Legal notices

Cyber security

Last updated 24 September 2026

We sell files online and we deliver them online, so security is not a feature we bolt on. This notice sets out our regulatory position, the measures in place, what happens if something goes wrong, and how to reach us if you find a hole.

Where we stand under the Cyberbeveiligingswet

The Cyberbeveiligingswet, or Cbw, is the Dutch implementation of the European NIS2 Directive. It places duties of care and duties to report on organisations that are designated as essential or important entities in the sectors the law lists.

We have not been designated as an essential or important entity by any Dutch ministry or supervisory authority, and no sectoral supervisor has been assigned to us. We are a small company outside the listed sectors, so the Cbw's mandatory regime does not currently apply to us.

We nevertheless registered voluntarily with the Nationaal Cyber Security Centrum, the national CSIRT, in July 2026 under KvK 95458859. The registration covers the company, and so every name it trades under, Digital Gemology included. Voluntary registration means we receive the NCSC's threat intelligence and advisories, and that the NCSC has a route to reach us directly if something that affects us is discovered. Our registration confirmation is on file and we will show it to a counterparty who asks.

We hold ourselves to the Cbw duty-of-care measures in proportion to our size, and we would follow its reporting rhythm in an incident, even though we are not obliged to. We would rather build to the standard now than discover we need it later.

How the site is built

Payments

Card details go straight to our payment provider, Stripe, which is certified to PCI DSS Level 1. We never see, transmit or store a card number.

Transport and headers

Every page and every download is served over TLS 1.2 or 1.3, with older and weaker protocols refused, and HSTS tells browsers never to try an insecure connection. Responses carry a Content Security Policy plus frame, referrer, permissions and content-type protections.

Edge

The site sits behind Cloudflare's network, which gives us DDoS protection, a web application firewall, and automated bot and threat filtering.

Files you download

The files we sell are geometry and data: STEP, STL, OBJ, GLB, FBX and 3DM models, GemCad cutting files, CSV tables and diagrams. They contain no macros, scripts or executable code, and we never ship an installer. If a file from us ever asks you to run something, it is not from us: tell us.

Supply chain

The site is plain HTML, CSS and vanilla JavaScript with no build step shipped to your browser, no bundler and no package tree. That is unusual, and it is deliberate: a dependency you never installed cannot be compromised. The typeface is served from our own domain rather than a third-party font service.

Risk management

If something goes wrong

A personal data breach is assessed as soon as we become aware of it. Where the law requires it we notify the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, within 72 hours under Article 33 of the GDPR, and we tell the people affected without undue delay where Article 34 applies. We keep a breach register, and it exists whether or not there has ever been a breach to put in it.

A significant cyber incident would be handled on the Cbw rhythm: an early warning within 24 hours, a fuller notification within 72 hours, and a final report once we understand what happened. We would tell affected customers directly rather than leaving them to read about it.

Reporting a vulnerability

We welcome coordinated disclosure and we will not take legal action against anyone acting in good faith. Write to security@brilliani.com, or see our security.txt.

What we ask of you:

What you get from us: an acknowledgement of every report, an honest answer about whether we consider it a vulnerability, and credit where you want it. We do not run a paid bug bounty at present, so please report because you want the hole closed rather than for a fee.

What we ask of our customers

The plain-language version of much of this is in the security and privacy FAQ. How we handle personal data specifically is in the privacy policy.