We operate in line with the international ISO/IEC 27001:2022 standard. We have established and run an information security management system (ISMS) covering the development, maintenance and delivery of all our SaaS services, including the supporting cloud infrastructure and development environment.
The security of our clients’ data is a condition of our business: a security policy, risk assessment, technical and organisational measures and independent audits form one system that is continuously measured and improved. Independent certification with an accredited certification body is in progress.
By topic of the standard
Management has adopted an information security policy committing to establish, operate, maintain and continually improve the ISMS, and to provide the resources it needs. The policy is reviewed at least once a year.
Security objectives are concrete and tracked through indicators reviewed at least annually.
Client data is stored and processed in data centres within the European Union. Personal data processing follows the Serbian Personal Data Protection Act (ZZPL): we keep records of processing activities, apply data minimisation and respond to data subject requests within legal deadlines.
In the event of a personal data breach posing risk to individuals, the supervisory authority is notified within 72 hours and affected clients without undue delay.
Access to systems and data follows the principle of least privilege: every account has only the rights it needs, and confidential data is accessed only when necessary.
All data in transit is protected with TLS (1.2 or newer, with HSTS). Data at rest is encrypted with AES-256, and particularly sensitive values are additionally encrypted at the application level.
Security is part of the development process from specification to delivery. Development, staging and production environments are fully separated, with separate databases and configuration.
Data is continuously protected through point-in-time recovery and backups at a secondary location independent of the primary environment.
Security events are reported through defined channels, triaged quickly and handled by a documented procedure: containment, scoping, root-cause removal, recovery and lessons learned.
Clients whose data or obligations are affected are informed honestly and without delay. Every incident is recorded, and root-cause analysis feeds further system improvement.
Our infrastructure is built on vetted cloud services with data processing agreements (DPA) in place. Client data may reside only with suppliers offering an adequate contractual framework and an EU region.
We do not audit the system only ourselves. We combine several independent layers of assurance and use the results for continual improvement.
This page publishes what the standard allows and expects to be public: our security policy and how we apply the controls. Detailed ISMS documentation (risk assessment, registers, internal procedures and records) is classified as internal, because publishing it would weaken the very security it protects.
We are happy to share relevant documentation with qualified clients and partners under a non-disclosure agreement.
Contact us