Security and Exit Addendum
This addendum attaches to the Terms of Service for customers on the Assurance and Custom plans. It is published rather than sent on request, because a commitment you can only read after signing is not much of a commitment.
Where this addendum and the Terms disagree, this addendum governs for the plans it applies to. Nothing here reduces a right you already have under the Terms or under law.
1. Definitions
1.1. "Business hours" means 08:00 to 17:00 Central European Time, Monday to Friday, excluding Swedish public holidays.
1.2. "First response" means a substantive human reply from a named person, not an automated acknowledgement.
1.3. "Urgent" means the Service is unavailable to you, your data is at risk, or a security incident is in progress. Everything else, including questions, requests and degraded but working functionality, is not urgent. If we disagree with your assessment we will treat it as urgent until we have discussed it with you.
1.4. "Security advisory" means a published vulnerability disclosure affecting Forgejo, or affecting a component in the Service's data path, that we assess as relevant to your use of the Service.
2. Support and response
2.1. Named contact. You are given one named individual at Hackerman AB and their direct email address. You may name up to two authorised contacts on your side.
2.2. First response. We will provide a first response within four business hours for an urgent issue, and within one business day for everything else.
2.3. Two levels, not four. Larger vendors publish four or five severity bands. We publish two, because two is what one person can staff honestly. A four-band table we could not hold would be worth less to you than a two-band one we can.
2.4. What 2.2 is and is not. It is a commitment to acknowledge and engage within the stated time. It is not a commitment to resolve an issue within any period. We do not promise fix times, because we cannot honestly promise them.
2.5. Outside business hours. We do not offer out-of-hours support on this plan. If you need it, it is scoped and priced per contract under the Custom plan.
2.6. Migration assistance. Within your first 90 days we will spend up to one working day helping you move onto the Service: importing repositories, adapting CI workflows, and whatever else the move needs. It is one-time and does not recur at renewal. Beyond it, the day rate in 3.3 applies, agreed in writing first.
3. Security questionnaires and assessments
3.1. We will complete up to 2 security questionnaires per contract year at your request, in the format you supply, whether that is a bespoke spreadsheet or a standard framework.
3.2. We will return a completed questionnaire within ten business days of receiving it, or agree a longer period with you in writing where the questionnaire is unusually long.
3.3. Questionnaires beyond the number in 3.1 are charged at €1,500 per day, agreed in advance and in writing before any work starts. We will not invoice you for work you did not approve.
3.4. We answer questionnaires truthfully, including where the truthful answer is unfavourable to us. We will not claim a certification we do not hold. See our security page for what we do and do not have.
4. Security advisories and patching
4.1. Notification. We will tell you about any security advisory relevant to your use of the Service within one business day of our becoming aware of it, whether or not we have finished responding to it.
4.2. Patching. We apply security fixes as quickly as we safely can, prioritised by severity. We deliberately do not commit to a fixed patching deadline, because a deadline we might miss during an incident is worth less to you than a notification we will always send.
4.3. Where we assess an advisory as not relevant to your use of the Service, we will say so and say why, on request.
5. Incident notification
5.1. We will notify you of a personal data breach affecting your data without undue delay and in any event within 48 hours of becoming aware of it.
5.2. We will notify you of a security incident affecting the confidentiality, integrity or availability of your data within the same period, whether or not personal data is involved.
5.3. Notification under 5.1 or 5.2 will include what we know, what we do not yet know, what we are doing, and when you will hear from us next. We will not wait for a complete picture before telling you.
5.4. Where you have your own regulatory notification deadline, tell us what it is and we will work to it.
6. Subcontractors
6.1. Our current sub-processors are published at codebahn.net/docs/subprocessors, with the location of each.
6.2. We will give you 30 days' written notice before adding or replacing a sub-processor that handles Customer Data.
6.3. You may object to a new sub-processor within those 30 days. If we cannot resolve your objection, you may terminate without penalty and section 8 applies.
6.4. On request we will identify our subcontractors and their rank in the chain in the form a financial entity needs for its register of information under DORA. The fields are published at codebahn.net/dora.
7. Continuity and audit
7.1. Backups. Customer Data is backed up daily to an EU region separate from the primary one, and held with a different provider. Repositories, the database and secrets are encrypted before they leave our infrastructure.
7.2. Restore testing. We restore from backup into a clean environment every week, automatically, and check that the database, the repositories and the secrets all come back. On request we will tell you the date and outcome of the most recent test.
7.3. Audit reports. On request we will provide the reports, assessments and evidence we hold. We do not offer on-site audit rights on this plan; where you require them, they are scoped per contract under the Custom plan.
7.4. Scheduled maintenance. We will give at least 72 hours' notice of planned maintenance that interrupts the Service, extending the 24 hours in section 7.1 of the Terms. We do not cap the quantity of planned maintenance, because we do not yet have enough operating history to commit to a number we would be confident of holding.
8. Exit
8.1. The switching, retrieval and no-charge commitments in sections 10.5 to 10.9 of the Terms apply to you, as they do to every customer.
8.2. Exit plan. We maintain a documented exit plan describing how your data leaves, in what formats, and what does not transfer. It is published at codebahn.net/leaving.
8.3. Deletion. On request after termination we will issue a written confirmation that Customer Data has been deleted, stating what was deleted and when.
8.4. Insolvency. If we cease trading, sections 10.5 to 10.9 of the Terms survive to the extent we are able to perform them, and we will make your data available for retrieval for as long as we are able to.
9. Changes to this addendum
9.1. We may update this addendum. Where a change reduces a commitment made to you, we will give you 30 days' notice and you may terminate without penalty within that period.
9.2. The version and date at the top of this page identify the version in force. Previous versions are available on request.
10. What this addendum does not do
10.1. It does not create an availability or uptime commitment. Availability terms are agreed per contract under the Custom plan.
10.2. It does not represent that Hackerman AB holds ISO 27001, SOC 2 or any other certification. We hold none, and say so plainly on our security page.
10.3. It does not grant on-site audit or inspection rights, or commit us to participate in threat-led penetration testing. A financial entity running a critical or important function on us under DORA should read section 7.3 before contracting.