Compliance & certifications
Your regulator does not accept a vendor's word, and neither should you. Everything below is backed by a report, a certificate or an exportable record.
Independently assessed
Certifications we hold.
Certificates and full reports are released under NDA through the trust centre, normally within one business day.
ISO/IEC 27001:2022
Certified information security management system covering the full DocShare platform, corporate IT and our Dutch data centres. Annual surveillance, three-yearly recertification.
Certificate NL-27001-4471 · valid to March 2028
NEN 7510:2017
The Dutch standard for information security in healthcare. Required by hospitals, insurers handling medical acceptance files, and occupational health services.
Certificate NL-7510-0912 · valid to November 2027
SOC 2 Type II
Twelve-month observation period across the Security, Availability and Confidentiality trust services criteria. Issued by a registered public accounting firm.
Report period: 1 Jan – 31 Dec 2025
GDPR / AVG
Processing exclusively within the Netherlands. Standard DPA, records of processing, DPIA template and sub-processor register available. No transfers outside the EEA.
eIDAS
Audit records are sealed with qualified electronic timestamps from an EU Trust List provider, giving them evidential weight before Dutch and EU courts.
DORA readiness
Contractual provisions for the ICT third-party register, concentration-risk reporting, testing participation and a documented exit plan with data return in open formats.
Mapping
Which obligations DocShare actually helps with.
No tool makes an organisation compliant. These are the specific control requirements where a DocShare deployment contributes evidence.
| Framework | Requirement | What DocShare provides |
|---|---|---|
| GDPR Art. 32 | Encryption of personal data, ability to ensure confidentiality | AES-256-GCM at rest, TLS 1.3 in transit, HSM key custody, documented algorithm suite per share |
| GDPR Art. 33–34 | Breach notification and assessment of risk to data subjects | Per-share release records make it possible to state precisely which documents were and were not accessed |
| GDPR Art. 5(1)(e) | Storage limitation | Key destruction on expiry renders ciphertext permanently unreadable; retention policy per template |
| DORA Art. 28–30 | ICT third-party risk, register of information, exit strategy | Pre-completed register entry, contractual DORA annex, tested exit plan with bulk export in open formats |
| NIS2 Art. 21 | Cryptography policy, supply chain security, incident handling | Published cryptographic policy, EEA-only sub-processors, 24-hour notification commitment |
| Wft / AFM | Duty of care in client communication; demonstrable delivery | Timestamped evidence of when a document was made available and when it was released |
| NEN 7510 | Controlled exchange of medical information | Certified processing environment, role-based sender controls, per-recipient release |
Data residency
Everything stays in the Netherlands.
Encrypted documents, metadata, key material, audit records, backups and operational logs are all held in two facilities inside Dutch borders. There is no replication to another region, no cross-border support hand-off, and no sub-processor with access to ciphertext established outside the EEA.
Support is delivered by staff located in the Netherlands and Belgium. Where a support case requires access to tenant metadata, access is time-bound, four-eyes approved, and recorded in your own audit trail rather than only in ours.
What a release record contains
- Share reference and document digest
- Sender identity, department and template used
- Recipient address the link was dispatched to
- Every verification check, with result and duration
- Source network, coarse geolocation and user agent class
- Timestamp of key release, qualified under eIDAS
- Outcome: released, refused, expired or revoked
- Hash-chain position and the preceding record digest
Exportable as signed JSON or CSV, retained for seven years by default, and independently verifiable against our published chain roots.
Trust centre
Ask for the documents.
Certificates, SOC 2 report, penetration test summaries, sub-processor register, cryptographic policy, business continuity test results and our DORA annex. Most are released under a mutual NDA within one business day.