← Back to home

Security & Compliance

Last reviewed August 2026 · Plain English

HMI Library serves engineers who work on operational technology, and it is run by one automation technician (Pau Serrano García, sole trader) rather than a company with a security department. That is exactly why this page is written in plain language: below is where your data lives, who sees it, what becomes public when you publish a symbol, and how to reach me if something feels off.

What we store about you

What we do NOT store

What is public when you publish

HMI Library includes a community library and a forum. Anything you publish there is visible to anyone on the internet without an account, may be indexed by search engines, and — for symbols — is licensed under CC BY 4.0:

Your email, billing data, download history, private symbols and reports are never public. You can unpublish (make private) or delete your own symbols from the dashboard at any time; the Privacy Policy has the full list and the Community Guidelines cover what to publish and how takedowns work.

Where data lives

EU · Frankfurt
PostgreSQL database
Supabase EU region. Daily encrypted backups. Row-Level Security enforced for all tables: you only read your own private rows; published content is readable by everyone.
EU · Frankfurt
Symbol files & previews
Supabase Storage. Clean SVG/PNG in a private bucket (signed URLs, quota-gated). Watermarked previews and avatars in a public bucket.
EU · Ireland
Payments / Subscriptions
Stripe Ireland (Stripe Payments Europe Ltd). PCI-DSS Level 1. Customer Portal for self-service billing.
Global CDN
Static assets & web app
Cloudflare Workers (anycast). Renders public symbol, profile and forum pages from already-public data; edge caching of public assets only — no user data persisted on edge nodes.
EU
Email (transactional)
Supabase email service for auth confirmations + password reset. Marketing email opt-in only.

GDPR & your rights

Pau Serrano García (sole trader, trading as HMI Library) is the Data Controller. You have the right to:

See the Privacy Policy for the formal version with subprocessor list.

Authentication & access control

Subprocessors

We use a deliberately small set of well-vetted vendors:

We do not use third-party analytics on the marketing site (no Google Analytics, no tracking pixels).

Reporting a vulnerability

Found something? Email security@hmilibrary.com with details. I respond within 72 hours and credit reporters in the changelog (with permission). No bounty program currently — one-person operation — but I am respectful and grateful, and fixes ship fast because there is no committee.

What's NOT certified yet

Honest disclosure:

If your procurement requires any of these and we're a strong fit otherwise, email us — we're happy to commit to a timeline.

Changelog

August 2026: Community library, public profiles, comments and forum added; documented what is public when you publish, the storage buckets for symbol files and the server-side download quota. Download-log retention aligned with the Privacy Policy (12 months). Document version 1.1.

April 2026: Page published. Document version 1.0.