Security Overview
Overview of the security measures adopted by Webmaster360 to protect infrastructure, data and editorial content.
Last updated: July 21, 2026
1. Purpose
This Security Overview describes, at a general level, the organizational and technical measures adopted by TAGMOOD S.R.L. to protect Webmaster360.
This document is for informational purposes only and does not replace contractual terms, the Data Processing Agreement, any Service Level Agreements, or other documentation signed with the customer.
For security reasons, operational details such as IP addresses, network configurations, firewall rules, component versions, credentials, internal procedures, or information that could facilitate unauthorized activities are not published.
2. Scope
This overview applies to the services offered through Webmaster360, with particular reference to:
- Editorial CMS;
- front-end of managed websites;
- back-end and admin panel;
- application infrastructure and databases;
- media management and distribution;
- automation and artificial intelligence features;
- technical support activities related to the service.
The public corporate website of Webmaster360 is excluded from the scope of this document.
3. Service Owner
Service Owner: TAGMOOD S.R.L.
Service: Webmaster360
Document approval authority: Fabio Salamone, Managing Director, Member & Co-Founder
Contacts:
- Security: webmaster360@tagmood.it
- Privacy: privacy@tagmood.it
- Support: webmaster360@tagmood.it
4. Infrastructure and Location
Webmaster360 uses external infrastructure providers selected based on the operational needs of the service:
- DigitalOcean for application infrastructure and managed MySQL databases;
- Laravel Forge for server management and deployment processes;
- Amazon Web Services S3 for media storage and related distribution services;
- SimpleBackups / SimpleStorage for external backup copies.
The primary application infrastructure and databases are hosted in Ireland. External backups are stored in the European eu-north-1 region.
Customers cannot currently choose a different region for data hosting.
The current configuration is not distributed across multiple zones or data centers, and the database is configured as a single node. Operational continuity therefore relies primarily on the provider’s recovery features and the separate backup copies described in this document.
5. Customer Separation
Each customer uses:
- a separate database;
- a dedicated application instance.
This architecture reduces the risk of accidental data commingling between customers and enables separate management of configurations and operational activities.
6. Data Protection
6.1 Data in Transit
Connections to Webmaster360 services are protected via HTTPS/TLS.
The managed MySQL database uses encrypted connections, and the provider declares encryption of data at rest.
6.2 Data at Rest
Media stored on Amazon S3 is protected by the server-side encryption provided by the service.
External backup copies are encrypted during streaming and stored in encrypted form using AES-256. The symmetric key used for each backup is protected through asymmetric RSA encryption. Decryption requires the corresponding private key, held by TAGMOOD.
6.3 Data Return and Deletion
Upon termination of the service, data extractable from the database can be returned in a structured format, typically JSON or XML. Media can be provided as an archive.
The methods, timing, and any limitations of data return or deletion are defined by the applicable agreements with the customer.
7. Identity and Access Control
Webmaster360 provides multi-factor authentication for:
- administrators;
- editors;
- authors.
MFA activation is currently optional.
Internal access is assigned according to the principle of least privilege. The creation, modification, or revocation of accounts and roles is managed through manual procedures by the authorized publisher or, upon request, by the Webmaster360 support team.
Administrative access and relevant activities are logged. Customers do not currently have direct access to their own audit logs.
8. Logging and Monitoring
Webmaster360 uses automatic monitoring systems and notifications to detect operational anomalies and potential incidents.
Relevant application and administrative logs are normally retained for 30 days, unless technical, security, or legal requirements demand a different period.
Access to logs is limited to authorized personnel.
9. Backup and Restore
The backup strategy includes:
- automatic daily backups of the managed MySQL database;
- point-in-time database recovery within the window made available by the provider;
- daily external backups, retained for 7 days;
- weekly external backups, retained for 4 weeks.
The ordinary retention of external copies does not exceed four weeks.
External backups:
- are separated from the production environment;
- are encrypted;
- undergo periodic restore tests.
Webmaster360 does not currently publish contractual Recovery Point Objective (RPO) or Recovery Time Objective (RTO) targets. Actual recovery times depend on the nature of the incident, the volume of data, and the procedures required by the infrastructure provider.
Any specific contractual commitments are valid only if expressly stated in the agreements signed with the customer.
10. Secure Development and Change Management
The development lifecycle includes:
- code review;
- separation between development, testing, and production environments;
- testing of changes before release;
- automatic checks on dependencies and known vulnerabilities;
- separation of application secrets from source code.
Available security updates are checked and applied on a daily basis, based on compatibility, criticality, and the operational needs of the service.
11. Vulnerability Management
Webmaster360 performs checks and vulnerability scans on service components.
As of the effective date of this document:
- no independent penetration test is declared;
- no security certifications are declared;
- no formal adoption of a specific security or compliance framework is declared.
Vulnerabilities or suspected security issues can be reported to:
The report should include, where possible:
- description of the issue;
- affected component or URL;
- steps required to reproduce it;
- potential impact;
- reporter’s contact details.
Please do not access, modify, copy, or delete data belonging to third parties, and do not perform activities that could compromise service availability.
12. Incident Management
Security events are handled by the Webmaster360 technical team.
When an incident may affect a customer’s services or data, TAGMOOD informs the affected parties via email, taking into account the nature of the event, contractual obligations, and applicable regulations.
As of the effective date of this document:
- no public service status page is available;
- no formalized and tested Incident Response Plan is declared.
This information does not limit any notification obligations that may be required by law or applicable agreements.
13. Personnel and Suppliers
Authorized personnel:
- are subject to confidentiality obligations;
- receive periodic security training;
- access systems only to the extent necessary to perform their activities.
Suppliers are evaluated before onboarding. Relationships with suppliers that process data are governed by contractual terms and, where applicable, by data processing agreements.
The public list of sub-processors will be made available on a dedicated Trust Center page. Until its publication, relevant information can be requested through the contacts listed in this document.
14. Artificial Intelligence Features
Some Webmaster360 features allow authorized editors and authors to send instructions to an external artificial intelligence provider.
The provider currently used is OpenAI.
Data sent may include:
- prompts entered by the authorized user;
- content or excerpts selected by the user;
- contextual instructions added by Webmaster360 to perform the requested function.
AI features can be disabled. Human review by the user or the responsible editorial party is required before publication.
Under the terms of the OpenAI API platform, data sent via API is not used to train or improve models, unless explicit opt-in to data sharing is given.
In the absence of specific Zero Data Retention controls approved by the provider, prompts, outputs, and related metadata may be retained by OpenAI for up to 30 days for abuse monitoring purposes, unless longer periods are required by law or necessary to protect the services and third parties.
Webmaster360 therefore does not declare a zero-retention guarantee with the AI provider, unless such configuration has been explicitly activated and documented.
15. Limitations and Shared Responsibility Model
Service security also depends on customer configurations and behaviors.
Customers are responsible for, among other things:
- protecting their own credentials;
- enabling MFA when available;
- assigning roles consistent with actual needs;
- promptly revoking accounts that are no longer needed;
- reviewing content before publication;
- not including in AI prompts unnecessary data or information that cannot be shared with the provider;
- promptly reporting suspicious activities.
No system can be considered completely immune to errors, vulnerabilities, or interruptions. TAGMOOD updates its measures based on technical evolution, identified risks, and service requirements.
16. Document Review
The Security Overview is reviewed at least every six months and may be updated before the deadline in the event of substantial changes to infrastructure, suppliers, or security measures.
Relevant changes will be reported by updating the version and the last review date.
17. Supplier References
Information about supplier features is subject to their respective terms and updated documentation:
- DigitalOcean Managed MySQL
- DigitalOcean: MySQL database restore
- Amazon S3: data protection with encryption
- SimpleBackups: backup encryption
- OpenAI API: data controls and retention
