The security of your data is the foundation of blendX.

GDPR compliance, NIS2 program underway, ISO 27001 and ISO 9001 certified. OVH hosting in Europe with selectable data residency. Full details on how we protect the platform and your data.

GDPR compliant
NIS2 in progress
ISO 27001 and ISO 9001 certified
OVH hosting in Europe

Platform monitored

Continuous detection, 24/7

EU
Data residency
24h
Automated daily backups
72h
Data breach notification (GDPR)
Go to status page

Recognized standards, independent audits.

GDPR

Full compliance with EU Regulation 2016/679. DPA available to clients.

Active

NIS2

EU Directive 2022/2555 on the security of network and information systems.

Program underway

ISO 27001 · ISO 9001

Information Security Management System and Quality Management System. Certifications achieved.

Certified

Private AI · On-premise

An option for organizations with maximum protection requirements: NIXIE runs locally only, on dedicated hardware.

In development

How we protect your data.

Encryption

Data is encrypted both in transit and at rest, with keys managed via KMS.

  • TLS 1.3 for every inbound and outbound connection
  • AES-256 for data at rest on databases and storage
  • Keys rotated every 90 days via dedicated KMS
  • Encrypted backups with keys separate from the prod environment

Authentication & access

Granular access control, enterprise SSO, and multi-factor authentication on all tiers.

  • SSO SAML 2.0 and OIDC (Azure AD, Okta, Google)
  • 2FA mandatory for admins, optional for users
  • Granular RBAC with custom roles
  • Configurable session timeout, immediate revocation

Data residency & backup

All data stays in the EU. Automated daily backups with 30-day retention.

  • Hosting exclusively in EU data centers
  • Daily backups in a separate geographic zone
  • RPO < 1h, RTO < 4h for disaster recovery scenarios
  • Full data export on request within 48h

Monitoring & incidents

24/7 detection and a data breach procedure with notification within 72 hours.

  • SIEM with automated alerting on anomalies
  • Annual external penetration tests
  • Continuous vulnerability scanning on dependencies
  • Data breach procedure aligned with the GDPR (72h)

A reliable, verifiable technology stack.

blendX is built on enterprise-grade technologies with geographic redundancy and automatic failover.

Cloud

OVH Europe

A European provider with security certifications and client-selectable data centers. No data ever leaves the European perimeter.

Data residency EU Sovereign
Database

PostgreSQL 16 managed

Synchronous replication for high availability, point-in-time recovery up to 14 days.

HA PITR 14d
Network

Cloudflare + WAF

DDoS protection, managed WAF, rate limiting, and bot mitigation.

DDoS L7 WAF
Secrets

Centralized secrets management

Vault for keys and credentials with automatic rotation and built-in audit logging.

KMS Audit log
Deploy

Zero downtime deployment

CI/CD with automated tests, isolated staging, fast rollback in case of regression.

Staging Rollback
Monitoring

Observability and on-call

Full-stack monitoring with dedicated on-call alerting and contractual SLAs.

On-call APM

Applicable regulations and frameworks.

FrameworkScopeStatus
GDPR
EU Reg. 2016/679
Personal data protection, data subject rights, DPO, DPIA Compliant
eIDAS
EU Reg. 910/2014
Qualified digital signatures and electronic identity Alignment in progress
NIS 2
EU Directive 2022/2555
Cybersecurity for critical infrastructure Alignment in progress
AgID
Italian public sector guidelines
Document preservation and registration for the public sector Alignment in progress
Codice Privacy
Legislative Decree 196/2003
Italian national implementation of the GDPR Compliant
EU AI Act
EU Reg. 2024/1689
AI transparency and governance Alignment in progress

Everything your compliance team needs.

DPA (Data Processing Agreement)

Agreement under Art. 28 GDPR for data processing as Processor.

Download PDF

Security Whitepaper

Complete technical document on security architecture and controls.

Download PDF

NIS2: compliance roadmap

Status of the NIS2 compliance program. Available on request for enterprise clients.

Request

Penetration Test Summary

Executive summary of the latest annual pentest. NDA required.

Request

Business Continuity Plan

BCP/DR with documented RPO, RTO, and recovery procedures.

Request

Vendor questionnaire (SIG Lite)

Pre-completed answers to the standardized SIG Lite questionnaire.

Request

Third-party providers appointed as data Processors.

ProviderServiceLocation
OVHCloud hosting and storageEU (selectable data center)
CloudflareCDN, WAF, DDoS protectionGlobal (EU cache)
PlausiblePrivacy-first self-hosted analyticsEU

We notify users at least 30 days in advance before adding new sub-processors.

Need a call with the Security team?

Our security team is available for security reviews, vendor questionnaires, and technical deep dives.

Contact the Security team Book a demo