Security & EU

European by design. Built to be audited.

Your data stays in the EU, in a tenant of your own. Every action, by a person or an agent, is recorded against the rule that allowed it.

Built to an ISO 27001-aligned structure

Our controls follow the structure of ISO 27001, so what Constitor records fits straight into your own ISMS. Constitor and Fabrica Agentis are not certified themselves.

What is an ISMS?

An ISMS (information security management system) is the set of rules, risks and evidence a company uses to protect its information. ISO 27001 is the international standard for it; NEN 7510 is the Dutch standard for healthcare.

In most companies it lives in documents that only open at audit time. In Constitor it is alive: every agent action adds evidence.

EU hosting

Your tenant, data and logs are hosted in the European Union.

Tenant isolation

Each customer gets its own tenant. Brands inside it stay separated too.

Single sign-on

Sign in with the accounts you already use, such as Microsoft or Google.

Secrets never in chat

Keys and passwords never appear in a conversation. Agents use them without seeing them.

Audit trail

Who did what, under which rule, approved by whom.

Human approval

Agents propose; people with a mandate decide. Nothing goes live on its own.

For your board and your regulator

What your board must show, and where Constitor helps.

DORA Art. 5
Final responsibility for ICT risk

Your management body holds it. Constitor gives it a readable rulebook, named approvals and a record of every change.

NIS2 Art. 20
Management approves cyber-risk measures

And oversees them. The handbook is where those measures are written, approved and followed.

EU AI Act
Human oversight, records, AI literacy

People approve what agents do, every action is logged, and the Academy trains your leaders.

ISO 27001
Fits your own ISMS

Built to an ISO 27001-aligned structure, so the record fits your own ISMS.

ISO 42001
A management system for AI

The standard for governing AI in an organisation. Constitor follows the same logic: rules, roles and evidence, with people in charge.

AI governance
Which agent does what, under which rule

Every agent, every rule and every approval in one place. That is the overview your board and auditor ask for.

Constitor does not make you compliant on its own. It gives you the evidence. Your ISMS, risk and audit functions stay responsible.

Certification follows

Run by the rules. Certification follows.

Standards are exactly what agents need. ISO 27001, NEN 7510 and ISO 42001 say precisely what must happen, who decides and which evidence you keep. For people that is paperwork. For agents it is the clearest frame there is: they work inside it on every task and collect the evidence as they go.

So certification is not a project you dread once a year. It is what your company does every day.

  1. 1
    The standard becomes your handbook

    Each control is written as a rule, with an owner your board approves.

  2. 2
    Agents work by it, every day

    Every task follows the rules and leaves its evidence behind. No chasing before the audit.

  3. 3
    Your auditor certifies you

    You show the handbook and the record. And you stay ready for the next audit.

The certificate is issued by an accredited certification body, not by Constitor. MEDrecord, HealthTalk and Coachi work under ISO 27001 and NEN 7510 certification.

Proven at home

Three companies. One handbook. Certified.

MEDrecordHealth data platform for hospitals and care providers.
ISO 27001NEN 7510
Its handbook, approvals and audit evidence run in Constitor.
HealthTalkAI scribe for mental healthcare.
ISO 27001NEN 7510
Its people and agents work under the same handbook, every day.
CoachiPersonal health companion app.
ISO 27001NEN 7510
Built and run under the same handbook and certification.

All three companies were founded by Jan-Marc Verlinden, who also founded Fabrica Agentis. The certificates belong to these companies, not to Constitor.

For the board

Your handbook and your ISMS are one document.

Your policies become rules in the handbook. The platform records how they were followed, by people and agents alike.

Working under a sector standard such as NEN 7510? Its controls become rules like any other.

  1. 1

    Policies become rules. Written once in the handbook, applied to all agent work.

  2. 2

    Approvals have owners. Every approval is a named person, on record.

  3. 3

    Evidence is automatic. Requests, agent work, checks and approvals, linked per delivery.

  4. 4

    Audits get easier. Ask for the evidence in plain words and export it.

Questions from security and risk.

Where is our data hosted?

In the European Union. Your tenant, data and logs are hosted in the EU. The sub-processor list is available on request.

Does Constitor help with DORA, NIS2 and the AI Act?

It gives your board the evidence those rules ask for: a readable rulebook, named approvals and a record of every change. It does not make you compliant on its own.

Can agents see our passwords?

No. Keys and passwords never appear in a conversation. Agents use them without seeing them.

Questions from your security officer?

We share our control overview, sub-processor list and data processing terms on request.

Contact us