GDPR compliance, NIS2 program underway, ISO 27001 and ISO 9001 certified. OVH hosting in Europe with selectable data residency. Full details on how we protect the platform and your data.
Full compliance with EU Regulation 2016/679. DPA available to clients.
ActiveEU Directive 2022/2555 on the security of network and information systems.
Program underwayInformation Security Management System and Quality Management System. Certifications achieved.
CertifiedAn option for organizations with maximum protection requirements: NIXIE runs locally only, on dedicated hardware.
In developmentData is encrypted both in transit and at rest, with keys managed via KMS.
Granular access control, enterprise SSO, and multi-factor authentication on all tiers.
All data stays in the EU. Automated daily backups with 30-day retention.
24/7 detection and a data breach procedure with notification within 72 hours.
blendX is built on enterprise-grade technologies with geographic redundancy and automatic failover.
A European provider with security certifications and client-selectable data centers. No data ever leaves the European perimeter.
Data residency EU SovereignSynchronous replication for high availability, point-in-time recovery up to 14 days.
HA PITR 14dDDoS protection, managed WAF, rate limiting, and bot mitigation.
DDoS L7 WAFVault for keys and credentials with automatic rotation and built-in audit logging.
KMS Audit logCI/CD with automated tests, isolated staging, fast rollback in case of regression.
Staging RollbackFull-stack monitoring with dedicated on-call alerting and contractual SLAs.
On-call APM| Framework | Scope | Status |
|---|---|---|
| GDPR EU Reg. 2016/679 |
Personal data protection, data subject rights, DPO, DPIA | Compliant |
| eIDAS EU Reg. 910/2014 |
Qualified digital signatures and electronic identity | Alignment in progress |
| NIS 2 EU Directive 2022/2555 |
Cybersecurity for critical infrastructure | Alignment in progress |
| AgID Italian public sector guidelines |
Document preservation and registration for the public sector | Alignment in progress |
| Codice Privacy Legislative Decree 196/2003 |
Italian national implementation of the GDPR | Compliant |
| EU AI Act EU Reg. 2024/1689 |
AI transparency and governance | Alignment in progress |
Agreement under Art. 28 GDPR for data processing as Processor.
Download PDFStatus of the NIS2 compliance program. Available on request for enterprise clients.
RequestPre-completed answers to the standardized SIG Lite questionnaire.
Request| Provider | Service | Location |
|---|---|---|
| OVH | Cloud hosting and storage | EU (selectable data center) |
| Cloudflare | CDN, WAF, DDoS protection | Global (EU cache) |
| Plausible | Privacy-first self-hosted analytics | EU |
We notify users at least 30 days in advance before adding new sub-processors.
Our security team is available for security reviews, vendor questionnaires, and technical deep dives.
Contact the Security team Book a demo