Information security

Comprehensive
information security management

We treat the security, privacy and integrity of our clients' data with the utmost seriousness. This is confirmed by the ISO/IEC 27001:2022 certificate, issued after an independent audit by TÜV Nord.

See the ISO certificate Contact the security team

Certification

ISO/IEC 27001:2022

We have implemented an Information Security Management System (ISMS) compliant with ISO/IEC 27001:2022. The ISMS has been independently audited and certified by TÜV Nord Polska.

Certificate scope: research and development, service delivery and advisory related to ebadu.pl products.

  • Compliance with the standard – we apply the requirements of the standard across the entire organisation.
  • Technical and organisational measures (TOMs) – we use them to protect key assets and information.
  • Continuous improvement – we regularly monitor, audit and improve our ISMS.
  • Incident management – every event is handled according to a standardised procedure.
Check the TÜV Nord reference list
TÜV NORD Polska certification mark – ISO 27001

How we protect your data

Technical and organisational safeguards

Encryption

All client data is encrypted both at rest and in transit.

Backups

RPO 24. Restore procedures tested regularly.

24/7 monitoring

Firewalls, intrusion detection systems (IDS) and real-time alerts.

Access control

Role-based access, IP allowlisting, SSO and MFA login.

Audit trails

Every login, change and export is recorded. Data access is easy to trace.

Data only in the EU

Data is stored and processed only within the European Union.

Dedicated instance

A dedicated environment for your organisation and full data separation.

Testing and response

Regular vulnerability scans and penetration tests, incident handling procedure.

GDPR compliance

Purpose-limited processing, data minimisation, full rights of access, rectification and erasure.

Contact

Talk to us about security