Compliance & certifications

Your regulator does not accept a vendor's word, and neither should you. Everything below is backed by a report, a certificate or an exportable record.

Independently assessed

Certifications we hold.

Certificates and full reports are released under NDA through the trust centre, normally within one business day.

ISO/IEC 27001:2022

Certified information security management system covering the full DocShare platform, corporate IT and our Dutch data centres. Annual surveillance, three-yearly recertification.

Certificate NL-27001-4471 · valid to March 2028

NEN 7510:2017

The Dutch standard for information security in healthcare. Required by hospitals, insurers handling medical acceptance files, and occupational health services.

Certificate NL-7510-0912 · valid to November 2027

SOC 2 Type II

Twelve-month observation period across the Security, Availability and Confidentiality trust services criteria. Issued by a registered public accounting firm.

Report period: 1 Jan – 31 Dec 2025

GDPR / AVG

Processing exclusively within the Netherlands. Standard DPA, records of processing, DPIA template and sub-processor register available. No transfers outside the EEA.

eIDAS

Audit records are sealed with qualified electronic timestamps from an EU Trust List provider, giving them evidential weight before Dutch and EU courts.

DORA readiness

Contractual provisions for the ICT third-party register, concentration-risk reporting, testing participation and a documented exit plan with data return in open formats.

Mapping

Which obligations DocShare actually helps with.

No tool makes an organisation compliant. These are the specific control requirements where a DocShare deployment contributes evidence.

Framework Requirement What DocShare provides
GDPR Art. 32 Encryption of personal data, ability to ensure confidentiality AES-256-GCM at rest, TLS 1.3 in transit, HSM key custody, documented algorithm suite per share
GDPR Art. 33–34 Breach notification and assessment of risk to data subjects Per-share release records make it possible to state precisely which documents were and were not accessed
GDPR Art. 5(1)(e) Storage limitation Key destruction on expiry renders ciphertext permanently unreadable; retention policy per template
DORA Art. 28–30 ICT third-party risk, register of information, exit strategy Pre-completed register entry, contractual DORA annex, tested exit plan with bulk export in open formats
NIS2 Art. 21 Cryptography policy, supply chain security, incident handling Published cryptographic policy, EEA-only sub-processors, 24-hour notification commitment
Wft / AFM Duty of care in client communication; demonstrable delivery Timestamped evidence of when a document was made available and when it was released
NEN 7510 Controlled exchange of medical information Certified processing environment, role-based sender controls, per-recipient release

Data residency

Everything stays in the Netherlands.

Encrypted documents, metadata, key material, audit records, backups and operational logs are all held in two facilities inside Dutch borders. There is no replication to another region, no cross-border support hand-off, and no sub-processor with access to ciphertext established outside the EEA.

Support is delivered by staff located in the Netherlands and Belgium. Where a support case requires access to tenant metadata, access is time-bound, four-eyes approved, and recorded in your own audit trail rather than only in ours.

Audit trail

What a release record contains

  • Share reference and document digest
  • Sender identity, department and template used
  • Recipient address the link was dispatched to
  • Every verification check, with result and duration
  • Source network, coarse geolocation and user agent class
  • Timestamp of key release, qualified under eIDAS
  • Outcome: released, refused, expired or revoked
  • Hash-chain position and the preceding record digest

Exportable as signed JSON or CSV, retained for seven years by default, and independently verifiable against our published chain roots.

Trust centre

Ask for the documents.

Certificates, SOC 2 report, penetration test summaries, sub-processor register, cryptographic policy, business continuity test results and our DORA annex. Most are released under a mutual NDA within one business day.