Questionnaires answered within two days as a rule

Security as part of the architecture, not an afterthought

Access, data handling and logging are decided up front, before the first line of code exists. Systems secured after the fact stay patchwork.

FIG_05DATA COREENCRYPTIONAUDIT TRAILACCESSOPERATIONS

EU

processing in European data centres

SSO

sign-in through an existing identity provider

Audit

access and actions logged without gaps

GDPR

processing agreement and deletion periods settled

Structure

Four layers, each resting on the one below

Security is never a single measure. Every layer assumes the one beneath it holds — and every one of them can be examined on its own.

01

Operations

Where the software runs, and who runs it.

  • Processing in European data centres
  • Full operation inside a self-hosted environment on request
  • Data processing agreement with named subprocessors
  • Self-hosted models instead of third-party provider APIs
02

Data

How content is transmitted, separated and deleted again.

  • TLS 1.3 in transit, AES-256 at rest
  • Tenant separation at the data layer
  • Fixed retention periods instead of open-ended storage
  • Customer content is never used to train models
03

Access

Who gets to see something, and who gets to trigger it.

  • Sign-in through an existing identity provider via SAML 2.0 or OpenID Connect
  • Permissions configurable per team and role, not just admin and user
  • Access expires instead of lingering until the next clean-up
04

Evidence

What can be demonstrated after the fact.

  • Logs covering access and every action triggered
  • Tamper-evident storage, exportable at any time
  • Every step of a case traceable individually
  • Documentation for external review on request

Infrastructure

Sovereign operations

Nalune runs where the data is allowed to live: in a European data centre, in a private cloud, or entirely on-premise.

See operating models
Data centreEU
Modelsself-hosted

Self-hosted infrastructure

The full stack runs on local hardware. No connection leaves it that has not been opened deliberately.

Requirements

Open interfaces

Systems connect through documented APIs instead of closed connectors. Whatever is integrated stays auditable.

Integrations

Our own models

We run friday. and edith. on our own infrastructure. Content from connected systems is never handed on to third-party providers.

See the platform

Evidence

What we let ourselves be measured against

The status is stated openly. What is certified says certified; what is still outstanding says so too.

Frameworks
GDPRIn place

Data processing, deletion concept and data subject rights are covered contractually and technically.

ISO 27001:2022In preparation

Our measures follow the standard. The certification audit is still outstanding.

NIS2In preparation

Risk management and reporting paths are being aligned with the directive's requirements.

EU AI ActIn preparation

Classification of use cases and documentation duties are being followed as they take effect.

Technical implementation
Data residencyEU, on-prem available

Processing in European data centres, or entirely inside a self-hosted environment on request.

EncryptionIn place

TLS 1.3 in transit, AES-256 at rest.

Sign-inIn place

Connects to an existing identity provider via SAML 2.0 or OpenID Connect.

Roles and permissionsIn place

Permissions configurable per team and role, with expiring access.

Model trainingRuled out

Content from connected systems is not used for model training, neither by us nor by the providers we use.

Documentation
Records of processing activitiesOn request

Under Art. 30 GDPR, covering the processes in use.

Technical and organisational measuresOn request

Description of the measures under Art. 32 GDPR.

Data processing agreementOn request

Template agreement including the list of subprocessors in use.

Existing questionnaires are filled in and answered in writing.

Request documentation

Questions about security?

Questionnaires and requirement lists are answered in writing and without detours.