Personal fields are encrypted with XChaCha20-Poly1305 before they reach the database; lookups use keyed blind indexes. The servers accept no inbound connections; all traffic goes through Cloudflare. Staff see masked data by default and every unmasking is written to an append-only audit log. Report vulnerabilities to security@peidik.ee (see /.well-known/security.txt).