Security Overview
A client-friendly summary of how Available protects information. For the formal commitment, see our Information Security Policy.
Organisational security
- A management-owned ISMS aligned with ISO/IEC 27001:2022, with an explicit risk assessment reviewed quarterly and audited annually.
- Every employee and contractor: confidentiality obligations in contract, security training at onboarding and annually, and a no-blame duty to report security events immediately.
- Access follows least privilege, is protected by multi-factor authentication, and is reviewed quarterly. Departing team members lose access the same day.
Access to client systems
Much of our consulting work happens inside our clients' own systems — most often their Zendesk instance. We treat that access with the same discipline as our own production:
- Named, individual accounts wherever the client can provide them, protected by MFA and limited to the consultants working on the engagement — so every action is attributable to a person in your own audit trail.
- Where a client can only provide a shared login, it is a documented exception with mandatory compensating controls: the credential and its MFA seed live only in our company-managed vault, restricted to that engagement's consultants — never in chat, tickets, or documents.
- When anyone with access to a shared client login changes role or leaves, the password is rotated and MFA re-seeded the same working day.
- Engagement access is covered by our quarterly access reviews and revoked as part of same-day offboarding.
- Your data stays in your systems and our approved company systems; we work with the minimum the task needs. The data processing agreement for each engagement governs what we access and why.
Product & infrastructure security
- Our services run on AWS and Vercel in EU regions, behind Cloudflare (DNS/CDN/WAF), with PostgreSQL operated by Neon in the EU — see Subprocessors & Service Levels.
- All data is encrypted in transit (TLS 1.2+) and at rest.
- Every change to code and infrastructure is peer-reviewed and passes automated checks — including dependency vulnerability scanning — before release. Production is separated from development, and production data is not used in test environments.
- Backups of production service data run hourly with 7-day retention (RPO 1 hour), stored separately from production and restore-tested at least twice a year.
- Company devices are encrypted Macs with enforced screen lock; passwords live in a company-managed password manager and MFA is mandatory everywhere it is supported.
- An independent penetration test of our production services is performed annually. A summary is available to clients on request.
Data protection
- GDPR is part of our security program, not an afterthought: data processing agreements, documented processing activities, data minimisation, and defined retention.
- Sub-processors: see Subprocessors & Service Levels.
- Personal data breaches are assessed immediately and notified to authorities and affected clients within the timelines the law and our contracts require.
Incident response
We maintain a documented incident response procedure: rapid containment, honest and timely client communication, and structured post-incident reviews whose lessons change how we work.
Verify us
- Our Information Security Policy is public.
- Under NDA, clients can request our Statement of Applicability, audit results, and other assurance documentation via security@available.dk.
- Once certified, our ISO/IEC 27001 certificate will be published on this site.