Certification
ISO2 HANDLE as an organization is ISO 27001 certified. This means that our information security complies with the ISO 27001 standard and its 114 controls.
We do this entirely through our own platform and have therefore set it up as a complete ISMS. In addition, we comply with the AVG legislation and many other security guidelines. This includes:
- Encryption policies
- Staff Policies
- Screening
- Access security
- Backup policy
- Asset Management and Security
- Incident Management
- Data classification
- Internal awareness training courses
- Stakeholder management
- and more
Environmental security
Environments are completely isolated from each other at both the database level and the file storage level to protect your data as well as possible. Among other things, we make use of:
- Secure SSL connection
- Minified encoded and chunked source code
- Firewall
- Two factor authentication
- Advanced rights structure
- Encrypted date in transit
- Encrypted data at rest
- Isolated databases
- Redundant infrastructure
- And more
Automatic backups
Environments are automatically backed up multiple times a day. These backups primarily go to hot storage. They are then backed up to a cold storage server every day.
- Multiple hot storage backups per day
- Daily cold storage backups
- All backups are encrypted with unique keys
- All hosting within the Netherlands and Germany inISO 27001certified data centers
PEN testing
The platform has now experienced several PEN tests from multiple parties and has passed them all brilliantly to date.
This is how we are:
- Tested by Qbit in 2020; Outcome: no critical or high points. Other points have been fixed.
- Tested by Hoffmann in 2020; Outcome: no critical or high points. Other points have been fixed.
- From 2021, automatically tested daily by PEN test testing software
- Tested by an independent party in 2021; Outcome: no critical or high points. Other points have been fixed.
- Tested in 2021 forISO 27001by Digitrust
- And more
Escrow
By taking out this insurance, the source code is added to ESCROW placed in custody. A guarantee for your (business) continuity.
Want to know more about our Escrow? Click here