Prijava Probaj Space ISO 27001

We operate by the ISO 27001 standard

We operate in line with the international ISO/IEC 27001:2022 standard. We have established and run an information security management system (ISMS) covering the development, maintenance and delivery of all our SaaS services, including the supporting cloud infrastructure and development environment.

The security of our clients’ data is a condition of our business: a security policy, risk assessment, technical and organisational measures and independent audits form one system that is continuously measured and improved. Independent certification with an accredited certification body is in progress.

By topic of the standard

How we apply ISO 27001, area by area

Information security policy Read more

Management has adopted an information security policy committing to establish, operate, maintain and continually improve the ISMS, and to provide the resources it needs. The policy is reviewed at least once a year.

  • Confidentiality: client data is available only to authorised persons, and one company’s data is never visible to another.
  • Integrity: fiscal, accounting and document data is protected from unauthorised change.
  • Availability: services and data are there when clients need them, with defined targets and measurement.
Measurable security objectives Read more

Security objectives are concrete and tracked through indicators reviewed at least annually.

  • Production service availability: targeted at 99.5% or better monthly, with continuous independent monitoring.
  • Recovery of key data from backup within 24 hours.
  • Remediation of critical security findings within defined deadlines.
Data in the EU and privacy protection Read more

Client data is stored and processed in data centres within the European Union. Personal data processing follows the Serbian Personal Data Protection Act (ZZPL): we keep records of processing activities, apply data minimisation and respond to data subject requests within legal deadlines.

In the event of a personal data breach posing risk to individuals, the supervisory authority is notified within 72 hours and affected clients without undue delay.

Access control Read more

Access to systems and data follows the principle of least privilege: every account has only the rights it needs, and confidential data is accessed only when necessary.

  • Two-factor authentication (2FA) is mandatory for administrative and privileged accounts.
  • No shared accounts: every access is tied to a specific person and leaves an audit trail.
  • Access rights are reviewed at least annually and revoked as soon as they are no longer needed.
Data encryption Read more

All data in transit is protected with TLS (1.2 or newer, with HSTS). Data at rest is encrypted with AES-256, and particularly sensitive values are additionally encrypted at the application level.

  • User passwords are stored only as one-way hashes (bcrypt or argon2), never in readable form.
  • Message integrity in integrations is protected with cryptographic signatures (HMAC-SHA256).
  • Outdated and weak algorithms are explicitly prohibited.
Secure software development Read more

Security is part of the development process from specification to delivery. Development, staging and production environments are fully separated, with separate databases and configuration.

  • All input is validated at system boundaries; database queries are parameterised.
  • Each client (company) is an isolated tenant; isolation is regularly tested, including independent penetration testing.
  • Releases go exclusively through a controlled process with instant rollback to the previous version.
  • Development and testing use synthetic data, never real client data.
Business continuity and backups Read more

Data is continuously protected through point-in-time recovery and backups at a secondary location independent of the primary environment.

  • Backup recovery is tested at least twice a year, with a written record of the outcome.
  • Service recovery priorities and targets are defined: recovery time and maximum acceptable data loss of up to 24 hours.
  • During incidents and recovery, security controls remain in force, with no temporary workarounds.
Security incident management Read more

Security events are reported through defined channels, triaged quickly and handled by a documented procedure: containment, scoping, root-cause removal, recovery and lessons learned.

Clients whose data or obligations are affected are informed honestly and without delay. Every incident is recorded, and root-cause analysis feeds further system improvement.

Suppliers and cloud services Read more

Our infrastructure is built on vetted cloud services with data processing agreements (DPA) in place. Client data may reside only with suppliers offering an adequate contractual framework and an EU region.

  • For every service we know what data it processes, in which region, and how access is protected.
  • Suppliers are reviewed at least annually: security practices, changes of terms and regions.
  • Every service has an exit strategy: a verified way to export the data.
Independent audits and continual improvement Read more

We do not audit the system only ourselves. We combine several independent layers of assurance and use the results for continual improvement.

  • Penetration testing at least once a year and after major architectural changes.
  • Monthly technical vulnerability review with remediation deadlines defined by severity.
  • Internal ISMS audit performed by an independent auditor, at least once a year.
  • Management review of the system with measurable indicators and improvement decisions.

Transparency, with responsibility

This page publishes what the standard allows and expects to be public: our security policy and how we apply the controls. Detailed ISMS documentation (risk assessment, registers, internal procedures and records) is classified as internal, because publishing it would weaken the very security it protects.

We are happy to share relevant documentation with qualified clients and partners under a non-disclosure agreement.

Contact us
Pogledaj cene Write to us