
Security is built into how we design, operate, and improve our services. We use a structured, risk-based approach to protect systems, data, and operations.
SECURITY BY DESIGN AND BY DEFAULT
We embed security and privacy into our products and processes from the start. We apply controls, monitoring, and regular reviews to maintain a strong security baseline.
A STRUCTURED CONTROL ENVIRONMENT
Our control environment is aligned with the ISO 27001 framework and mapped to the CIS Critical Security Controls (CIS18). This supports consistent governance, access control, asset protection, and ongoing monitoring.
KEY SECURITY MEASURES
To safeguard systems and customer data, we apply measures across among other things:
Access and identity
- Single Sign-On (SSO) and Multi-Factor Authentication (MFA)
- Role-based access control and least privilege
- Controlled administrative access
Protection and resilience
- Encryption in transit and at rest
- Regular, automated backups
- Resilience, recovery, and disaster response procedures
Monitoring and response
- Monitoring, alerting, and incident response
- Vulnerability management and penetration testing
- Patch management and endpoint protection
INDEPENDENT ASSURANCE
We maintain independent third-party assurance through:
- ISAE 3402 (IT Security)
- ISAE 3000 (GDPR)
- ISAE 3000 (NIS2 – Cybersecurity) in process
SECURITY GOVERNANCE
Our Information Security and Compliance Forum, reporting to executive management, supports alignment across compliance, IT security, operations, and legal. We monitor regulatory developments relevant to customers, including NIS2, DORA, the AI Act, and the Data Act.
Disclaimer: The content of this Trust Center is provided for informational purposes only and does not constitute legal advice. Security and compliance practices may change as our services evolve.


