Security Overview
A client-friendly summary of how Available protects information. For the formal commitment, see our Information Security Policy.
Organisational security
- A management-owned ISMS aligned with ISO/IEC 27001:2022, with an explicit risk assessment reviewed quarterly and audited annually.
- Every employee and contractor: confidentiality obligations in contract, security training at onboarding and annually, and a no-blame duty to report security events immediately.
- Access follows least privilege, is protected by multi-factor authentication, and is reviewed quarterly. Departing team members lose access the same day.
Product & infrastructure security
- Our services run on AWS and Vercel in EU regions, behind Cloudflare (DNS/CDN/WAF), with PostgreSQL operated by Neon in the EU — see Subprocessors & Service Levels.
- All data is encrypted in transit (TLS 1.2+) and at rest.
- Every change to code and infrastructure is peer-reviewed and passes automated checks — including dependency vulnerability scanning — before release. Production is separated from development, and production data is not used in test environments.
- Backups of production service data run hourly with 7-day retention (RPO 1 hour), stored separately from production and restore-tested at least twice a year.
- Company devices are encrypted Macs with enforced screen lock; passwords live in a company-managed password manager and MFA is mandatory everywhere it is supported.
- TODO: penetration testing statement once decided (e.g. "An independent penetration test is performed annually; a summary is available to clients on request.")
Data protection
- GDPR is part of our security program, not an afterthought: data processing agreements, documented processing activities, data minimisation, and defined retention.
- Sub-processor list: TODO: link or state "available on request".
- Personal data breaches are assessed immediately and notified to authorities and affected clients within the timelines the law and our contracts require.
Incident response
We maintain a documented incident response procedure: rapid containment, honest and timely client communication, and structured post-incident reviews whose lessons change how we work.
Verify us
- Our Information Security Policy is public.
- Under NDA, clients can request our Statement of Applicability, audit results, and other assurance documentation via security@available.dk (TODO: confirm).
- Once certified, our ISO/IEC 27001 certificate will be published on this site.