Trust

Security, privacy and continuity by design.

A reliable solution needs more than a secured login. We look at data, roles, integrations, logging, back-ups, recovery, suppliers and human responsibility.

Data minimisation

We collect and retain only the data a process actually needs.

Roles and authorisation

Access to data and functions is tied to roles, not open by default to every user.

Encryption in transit

Data is encrypted between user, application and database. Where the chosen hosting service supports it, data is also encrypted at rest.

Logging and audit trail

Critical actions and changes are recorded, so a case or process can be traced afterwards.

Back-ups and recovery agreements

Back-up frequency and recovery time are agreed per management package, from periodic to daily with recovery checks.

Dependency and patch policy

Software dependencies and security updates are checked and applied periodically.

Suppliers and processors

Hosting and AI suppliers are chosen deliberately and, where relevant, contractually recorded as a processor.

Incident response

In case of a security incident we follow a fixed sequence: detect, contain, remediate and inform.

Human oversight of AI

Critical or risky AI actions require explicit approval, logging or a fallback to a person.

The precise measures are determined per solution, based on the type of data, risk, sector, hosting and responsibilities. Contractual privacy and security agreements are part of the implementation scope where needed. Our environments run on a fixed chain from DEV to ACC to PRD (acceptance on NexusBase, production on Supabase), with EU hosting.

Want to know more about data handling or cookies? Read our privacy notice.

Questions about security or privacy?

Schedule a free 30-minute intake. We discuss the specific requirements for your sector and data.

Schedule intake