Security Overview

A client-friendly summary of how Available protects information. For the formal commitment, see our Information Security Policy.

Organisational security

  • A management-owned ISMS aligned with ISO/IEC 27001:2022, with an explicit risk assessment reviewed quarterly and audited annually.
  • Every employee and contractor: confidentiality obligations in contract, security training at onboarding and annually, and a no-blame duty to report security events immediately.
  • Access follows least privilege, is protected by multi-factor authentication, and is reviewed quarterly. Departing team members lose access the same day.

Product & infrastructure security

  • Our services run on AWS and Vercel in EU regions, behind Cloudflare (DNS/CDN/WAF), with PostgreSQL operated by Neon in the EU — see Subprocessors & Service Levels.
  • All data is encrypted in transit (TLS 1.2+) and at rest.
  • Every change to code and infrastructure is peer-reviewed and passes automated checks — including dependency vulnerability scanning — before release. Production is separated from development, and production data is not used in test environments.
  • Backups of production service data run hourly with 7-day retention (RPO 1 hour), stored separately from production and restore-tested at least twice a year.
  • Company devices are encrypted Macs with enforced screen lock; passwords live in a company-managed password manager and MFA is mandatory everywhere it is supported.
  • TODO: penetration testing statement once decided (e.g. "An independent penetration test is performed annually; a summary is available to clients on request.")

Data protection

  • GDPR is part of our security program, not an afterthought: data processing agreements, documented processing activities, data minimisation, and defined retention.
  • Sub-processor list: TODO: link or state "available on request".
  • Personal data breaches are assessed immediately and notified to authorities and affected clients within the timelines the law and our contracts require.

Incident response

We maintain a documented incident response procedure: rapid containment, honest and timely client communication, and structured post-incident reviews whose lessons change how we work.

Verify us

  • Our Information Security Policy is public.
  • Under NDA, clients can request our Statement of Applicability, audit results, and other assurance documentation via security@available.dk (TODO: confirm).
  • Once certified, our ISO/IEC 27001 certificate will be published on this site.

Version 0.1 · Last reviewed 2026-08-26