Security Overview

A client-friendly summary of how Available protects information. For the formal commitment, see our Information Security Policy.

Organisational security

  • A management-owned ISMS aligned with ISO/IEC 27001:2022, with an explicit risk assessment reviewed quarterly and audited annually.
  • Every employee and contractor: confidentiality obligations in contract, security training at onboarding and annually, and a no-blame duty to report security events immediately.
  • Access follows least privilege, is protected by multi-factor authentication, and is reviewed quarterly. Departing team members lose access the same day.

Access to client systems

Much of our consulting work happens inside our clients' own systems — most often their Zendesk instance. We treat that access with the same discipline as our own production:

  • Named, individual accounts wherever the client can provide them, protected by MFA and limited to the consultants working on the engagement — so every action is attributable to a person in your own audit trail.
  • Where a client can only provide a shared login, it is a documented exception with mandatory compensating controls: the credential and its MFA seed live only in our company-managed vault, restricted to that engagement's consultants — never in chat, tickets, or documents.
  • When anyone with access to a shared client login changes role or leaves, the password is rotated and MFA re-seeded the same working day.
  • Engagement access is covered by our quarterly access reviews and revoked as part of same-day offboarding.
  • Your data stays in your systems and our approved company systems; we work with the minimum the task needs. The data processing agreement for each engagement governs what we access and why.

Product & infrastructure security

  • Our services run on AWS and Vercel in EU regions, behind Cloudflare (DNS/CDN/WAF), with PostgreSQL operated by Neon in the EU — see Subprocessors & Service Levels.
  • All data is encrypted in transit (TLS 1.2+) and at rest.
  • Every change to code and infrastructure is peer-reviewed and passes automated checks — including dependency vulnerability scanning — before release. Production is separated from development, and production data is not used in test environments.
  • Backups of production service data run hourly with 7-day retention (RPO 1 hour), stored separately from production and restore-tested at least twice a year.
  • Company devices are encrypted Macs with enforced screen lock; passwords live in a company-managed password manager and MFA is mandatory everywhere it is supported.
  • An independent penetration test of our production services is performed annually. A summary is available to clients on request.

Data protection

  • GDPR is part of our security program, not an afterthought: data processing agreements, documented processing activities, data minimisation, and defined retention.
  • Sub-processors: see Subprocessors & Service Levels.
  • Personal data breaches are assessed immediately and notified to authorities and affected clients within the timelines the law and our contracts require.

Incident response

We maintain a documented incident response procedure: rapid containment, honest and timely client communication, and structured post-incident reviews whose lessons change how we work.

Verify us

  • Our Information Security Policy is public.
  • Under NDA, clients can request our Statement of Applicability, audit results, and other assurance documentation via security@available.dk.
  • Once certified, our ISO/IEC 27001 certificate will be published on this site.

Version 0.2 · Last reviewed 2026-08-26