Trust Center
How this platform protects privacy and security, and how its controls map to GDPR, SOC 2, ISO 27001, the EU Cyber Resilience Act and the NIS2 Directive.
Quick links
Controls
29 controls
Immutable audit logImplemented
Append-only audit trail of mutations and security events, retained for at least 12 months.
GDPR Art 5(2)GDPR Art 30GDPR Art 32SOC 2 CC7.2ISO A.12.4CRA Annex I.I(2)(l)NIS2 Art 21(2)(b)
Login audit + lockoutImplemented
Every credential sign-in is logged with outcome; lockout after repeated failures.
GDPR Art 32SOC 2 CC6.1SOC 2 CC6.8ISO A.9.4CRA Annex I.I(2)(d)NIS2 Art 21(2)(b)NIS2 Art 21(2)(i)
Password policyImplemented
Length, complexity, history, and optional breach-check enforced on every change.
GDPR Art 32SOC 2 CC6.1ISO A.9.4.3CRA Annex I.I(2)(d)NIS2 Art 21(2)(g)NIS2 Art 21(2)(i)
Role-based access controlImplemented
Fine-grained, feature-scoped permissions with workspace boundaries.
GDPR Art 32SOC 2 CC6.1SOC 2 CC6.3ISO A.9.2ISO A.9.4CRA Annex I.I(2)(d)NIS2 Art 21(2)(i)
Right to erasure + anonymisationImplemented
Self-service account deletion with a configurable grace period; anonymisation fallback for records on legal hold or referenced by business data.
GDPR Art 17ISO A.18CRA Annex I.I(2)(m)
Legal holdImplemented
Records can be placed under legal hold to override retention and deletion.
GDPR Art 18SOC 2 CC6.5ISO A.18
Public legal documentsImplemented
Versioned privacy policy, terms, DPA, cookie policy, and security overview.
GDPR Art 13GDPR Art 14SOC 2 CC2.2ISO A.5
Data Subject Access Requests (DSAR)Implemented
Self-service data export and admin DSAR queue with 30-day SLA tracking.
GDPR Art 15GDPR Art 20ISO A.18.1.4CRA Annex I.I(2)(m)
Consent + cookie managementImplemented
Granular consent purposes, append-only consent ledger, and a cookie banner.
GDPR Art 6GDPR Art 7ISO A.18
Sub-processor disclosureImplemented
Public list of sub-processors with notification mechanism for changes.
GDPR Art 28ISO A.15NIS2 Art 21(2)(d)
Two-factor authenticationImplemented
TOTP enrolment with single-use backup codes; can be required for super-admins, for all users, or per workspace.
GDPR Art 32SOC 2 CC6.1ISO A.9.4.2CRA Annex I.I(2)(d)NIS2 Art 21(2)(j)
Session managementImplemented
Active session listing, sign-out everywhere, configurable idle timeout.
GDPR Art 32SOC 2 CC6.1ISO A.9.4.2CRA Annex I.I(2)(d)NIS2 Art 21(2)(i)
Data retention policiesImplemented
Per-entity retention rules executed by scheduled sweeps and logged for evidence.
GDPR Art 5(1)(e)SOC 2 CC6.5ISO A.8.3ISO A.18
Encryption of sensitive fieldsImplemented
AES-256-GCM helper available for OAuth tokens and integration credentials.
GDPR Art 32SOC 2 CC6.7ISO A.10CRA Annex I.I(2)(e)NIS2 Art 21(2)(h)
Encryption in transitImplemented
TLS 1.2+ enforced on all public endpoints; HSTS enabled.
GDPR Art 32SOC 2 CC6.7ISO A.13ISO A.14.1.2CRA Annex I.I(2)(e)CRA Annex I.I(2)(f)NIS2 Art 21(2)(h)NIS2 Art 21(2)(j)
BackupsImplemented
Scheduled workspace backups with retention and restore tooling.
GDPR Art 32SOC 2 A1.2ISO A.12.3CRA Annex I.I(2)(h)NIS2 Art 21(2)(c)
Incident response + breach notificationImplemented
Incident workflow with the GDPR 72-hour notification deadline and, for significant incidents, the NIS2 early warning (24 h), incident notification (72 h) and final report (one month).
GDPR Art 33GDPR Art 34SOC 2 CC7.3SOC 2 CC7.4SOC 2 CC7.5ISO A.16CRA Art 14(3)CRA Art 14(4)NIS2 Art 21(2)(b)NIS2 Art 23
Evidence exports for auditsImplemented
CSV exports of audit log, DSAR log, consent ledger, login audit, retention sweep history and access review.
GDPR Art 30SOC 2 CC7.2ISO A.12.4NIS2 Art 21(2)(f)
Change managementImplemented
All entity changes logged via change log; release process documented.
GDPR Art 32SOC 2 CC8.1ISO A.12.1.2ISO A.14.2CRA Annex I.II(3)NIS2 Art 21(2)(e)
Logging and monitoringImplemented
Application logs, error events, and external log destinations.
GDPR Art 32SOC 2 CC7.1SOC 2 CC7.2ISO A.12.4CRA Annex I.I(2)(l)NIS2 Art 21(2)(b)
Vulnerability disclosureImplemented
A published coordinated disclosure policy (SECURITY.md) and a single contact, security@taion.fi, advertised by every installation at /.well-known/security.txt.
CRA Art 13(17)CRA Annex I.II(5)CRA Annex I.II(6)NIS2 Art 21(2)(e)
Security advisoriesImplemented
Fixed vulnerabilities are published as advisories with the affected and fixed versions, severity and mitigation, on a public page and a JSON feed, and shown to the installations they apply to.
CRA Annex I.II(4)CRA Annex I.II(8)NIS2 Art 21(2)(e)
Security updatesImplemented
Signed releases delivered through the hub; installations stage updates automatically and, by default, apply security-only releases on their own, with an opt-out and the option to postpone by pinning a release.
CRA Annex I.I(2)(c)CRA Annex I.II(2)CRA Annex I.II(7)CRA Art 13(9)NIS2 Art 21(2)(e)
Support periodImplemented
Security updates for the product until at least December 2032; each release is supported until 90 days after the next one. Installations show their support status.
CRA Art 13(8)CRA Art 13(19)CRA Annex II(7)
Software bill of materialsImplemented
Every release, and every marketplace plugin package, carries a CycloneDX SBOM of its components; the release SBOM is covered by the release signature.
CRA Annex I.II(1)NIS2 Art 21(2)(d)NIS2 Art 21(2)(e)
Reporting to authoritiesImplemented
Actively exploited vulnerabilities and severe incidents are tracked against the 24-hour, 72-hour and final-report deadlines, with alerts to the security team, and reported to CSIRT-FI.
CRA Art 14(1)CRA Art 14(2)CRA Art 14(8)
No known exploitable vulnerabilitiesImplemented
Each release is audited for known vulnerabilities in what it ships; it is not built while one has no analysis showing it is not exploitable here, and the analyses ship in its SBOM.
CRA Annex I.I(2)(a)NIS2 Art 21(2)(e)
Security alertsImplemented
Operators and workspace admins are notified of super-admin sign-ins from new addresses, impersonation and account lockouts.
GDPR Art 32SOC 2 CC7.2SOC 2 CC7.3ISO A.12.4ISO A.16.1.2NIS2 Art 21(2)(b)
Access reviewImplemented
CSV of every member's role, permissions, two-factor status and last sign-in, per workspace and installation-wide.
GDPR Art 32SOC 2 CC6.2SOC 2 CC6.3ISO A.9.2.5NIS2 Art 21(2)(i)
NIS2 references show which risk-management measures of NIS2 Article 21 a control helps a customer meet. They are not a statement that the operator of this installation is subject to, or certified under, NIS2.