Access, data handling and logging are decided up front, before the first line of code exists. Systems secured after the fact stay patchwork.
EU
processing in European data centres
SSO
sign-in through an existing identity provider
Audit
access and actions logged without gaps
GDPR
processing agreement and deletion periods settled
Structure
Security is never a single measure. Every layer assumes the one beneath it holds — and every one of them can be examined on its own.
Where the software runs, and who runs it.
How content is transmitted, separated and deleted again.
Who gets to see something, and who gets to trigger it.
What can be demonstrated after the fact.
Infrastructure
Nalune runs where the data is allowed to live: in a European data centre, in a private cloud, or entirely on-premise.
The full stack runs on local hardware. No connection leaves it that has not been opened deliberately.
RequirementsSystems connect through documented APIs instead of closed connectors. Whatever is integrated stays auditable.
IntegrationsWe run friday. and edith. on our own infrastructure. Content from connected systems is never handed on to third-party providers.
See the platformEvidence
The status is stated openly. What is certified says certified; what is still outstanding says so too.
Data processing, deletion concept and data subject rights are covered contractually and technically.
Our measures follow the standard. The certification audit is still outstanding.
Risk management and reporting paths are being aligned with the directive's requirements.
Classification of use cases and documentation duties are being followed as they take effect.
Processing in European data centres, or entirely inside a self-hosted environment on request.
TLS 1.3 in transit, AES-256 at rest.
Connects to an existing identity provider via SAML 2.0 or OpenID Connect.
Permissions configurable per team and role, with expiring access.
Content from connected systems is not used for model training, neither by us nor by the providers we use.
Under Art. 30 GDPR, covering the processes in use.
Description of the measures under Art. 32 GDPR.
Template agreement including the list of subprocessors in use.
Existing questionnaires are filled in and answered in writing.
Request documentationQuestionnaires and requirement lists are answered in writing and without detours.