Your data is secure, redundant and stored within Europe.

Providing a platform where many organizations register their processes and information involves responsibility. A responsibility that we take very seriously

Certification

ISO2 HANDLE as an organization is ISO 27001 certified. This means that our information security complies with the ISO 27001 standard and its 114 controls.

We do this entirely through our own platform and have therefore set it up as a complete ISMS. In addition, we comply with the AVG legislation and many other security guidelines. This includes:

  • Encryption policies
  • Staff Policies
  • Screening
  • Access security
  • Backup policy
  • Asset Management and Security
  • Incident Management
  • Data classification
  • Internal awareness training courses
  • Stakeholder management
  • and more

Environmental security

Environments are completely isolated from each other at both the database level and the file storage level to protect your data as well as possible. Among other things, we make use of:

  • Secure SSL connection
  • Minified encoded and chunked source code
  • Firewall
  • Two factor authentication
  • Advanced rights structure
  • Encrypted date in transit
  • Encrypted data at rest
  • Isolated databases
  • Redundant infrastructure
  • And more

Automatic backups

Environments are automatically backed up multiple times a day. These backups primarily go to hot storage. They are then backed up to a cold storage server every day.

  • Multiple hot storage backups per day
  • Daily cold storage backups
  • All backups are encrypted with unique keys
  • All hosting within the Netherlands and Germany inISO 27001certified data centers

PEN testing

The platform has now experienced several PEN tests from multiple parties and has passed them all brilliantly to date.

This is how we are:

  • Tested by Qbit in 2020; Outcome: no critical or high points. Other points have been fixed.
  • Tested by Hoffmann in 2020; Outcome: no critical or high points. Other points have been fixed.
  • From 2021, automatically tested daily by PEN test testing software
  • Tested by an independent party in 2021; Outcome: no critical or high points. Other points have been fixed.
  • Tested in 2021 forISO 27001by Digitrust
  • And more

Escrow

By taking out this insurance, the source code is added to ESCROW placed in custody. A guarantee for your (business) continuity.

Want to know more about our Escrow? Click here

How do we deal with your data?

When is your service desk open?

It can be reached by phone on weekdays from 09:00 to 17:00. In addition, an online ticket desk is available where you can report questions or problems 24/7. There is also a academia available with more than 50 articles, an online video training and various instructional videos.

How does ISO2HANDLE handle backups?

Every environment is fully backed up every 12 hours (hot storage). In addition, a cold storage backup is also made of your environment every day, which is stored in a secure data center in the Netherlands. You can also extract data from the application yourself via an Excel and/or PDF dump.

What uptimes do you aim for?

We aim for an uptime of 99.5% during weekdays from 09:00 to 17:00.

Where is the data?

Data is stored in the hosting center (ISO 27001 certified) by Digital Ocean. This one is in Amsterdam. Hot storage backups are stored encrypted (with unique keys) in Frankfurt. The cold backups are stored encrypted (with unique keys) in the Netherlands.

Questions & Answers

When do you make backups?
Every day, 2 hot storage backups are made of each environment. In addition, a cold storage backup is made every day.
Where are your backups stored?
Hot storage backups are stored within Europe in Germany. Cold storage backups are stored in the Netherlands in a secure data center on managed hardware.
Do you check backups for corruption?
We randomly check backups for corruption.
Do you have a backup test process?
Yes, we test backups daily and work on an automated test process that detects corruption.
What do you do if one of these things is not in order?
If one of these things is not in order, notifications will be sent immediately.
Is there monitoring?
Yes. We monitor all our servers and backup 24/7. In turn, our monitoring systems are also monitored so that any problems are detected immediately.
How do the different environments run side by side in backup?
All environments are separate, so databases never touch each other.
How is traffic to your platform doing?
All traffic to and from our platform is encrypted.
Do you use a firewall?
Each environment has its own firewall.
Are you ISO 27001 certified?
We ourselves and our hosting centers are ISO 27001 certified.
How do you monitor the different environments?
We monitor each environment live on around 50 parameters including uptime, presence of hot storage backups and the presence of cold storage backups.
Has a PEN test been performed yet?
Yes, we regularly carry out a PEN test.