Security & EU

European by design. Built to be audited.

Your data stays in the EU, in a tenant of your own. Every action, by a person or an agent, is recorded against the rule that allowed it.

Built to an ISO 27001-aligned structure

Our controls follow the ISO 27001 structure, so what Constitor records fits straight into your own ISMS.

EU hosting

Your tenant, data and logs are hosted in the European Union.

Tenant isolation

Each customer gets its own tenant. Brands inside it stay separated too.

Single sign-on

Sign in with the accounts you already use, such as Microsoft or Google.

Secrets never in chat

Keys and passwords never appear in a conversation. Agents use them without seeing them.

Audit trail

Who did what, under which article, approved by whom.

Human approval gates

Agents propose; people with a mandate decide. Nothing goes live on its own.

For the board

Your ISMS, on record every day.

Your policies become articles in the handbook. The platform records how they were followed, by people and agents alike.

Working under a sector standard such as NEN 7510? Its controls become articles like any other rule. Constitor is already being set up within European R&D projects, together with research and industry partners.

  1. 1Policies become rules. Written once in the handbook, applied to every run.
  2. 2Gates have owners. Every approval is a named person, on record.
  3. 3Evidence is automatic. Tickets, runs, reviews and tests linked per release.
  4. 4Audits get easier. Ask for the evidence in plain words and export it.

Questions from your security officer?

We share our control overview and data processing terms on request.

Contact us