Security & compliance

Audit-ready security, baked in from day one

Our information security program is ISO 27001-aligned, GDPR-by-default, and NIS2-ready. Every engagement ships with documented controls and a clear incident-response playbook.

ISO 27001GDPRNIS2SOC 2 Type IIPCI-DSSHIPAA-aware
Controls

Six pillars of our security program

ISO 27001-aligned ISMS

Documented controls, annual internal audit, risk register reviewed quarterly.

GDPR by default

Lawful-basis mapping, DPIA templates, EU-only data residency on every project.

NIS2-ready

Tooling and runbooks aligned with NIS2 essential-entity obligations.

Zero-trust access

SSO + MFA on every system, hardware keys for admins, least-privilege by policy.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, customer-managed keys on request.

Continuous monitoring

SIEM, anomaly detection, and quarterly external pen-tests.

Report a vulnerability

Found something? We respond within 24 hours. Coordinated disclosure preferred.

security@euravetech.eu

Trust documents

Request our security questionnaire response, DPA, sub-processor list, and latest pen-test summary.

Request documents