ISO 27001:2022 certified. In an era where AI and data form the core of business processes, information security is not a side issue, but a foundation.

security as a
foundation

The atrium of Plus Ultra Groningen, home base of Researchable

What ISO 27001 means

The globally recognised standard for information security, from policy to technology.

The standard specifies the requirements for setting up, running and maintaining an Information Security Management System (ISMS). All projects at Researchable, from data architecture to AI product development, fall within the scope of our certification.

Certification is not a one-off exercise. Annual surveillance audits and three-yearly recertification by an independent party ensure the level stays current and effective.

Where getting it wrong is not an option

We build business-critical AI and data infrastructure for sectors where the wrong decision has immediate consequences.

Medical & Healthcare

Processing and storing patient data within a NEN 7510-compliant environment.

Government

Secure management of sensitive government data and public services.

Science

Reliable and reproducible processing of sensitive research data.

Legal

Analysing and processing legally sensitive documents with strict access control.

Critical infrastructure

Continuous availability and integrity of systems that must not fail.

Swipe for all sectors →

How we safeguard security in practice

Guidelines and policy are only the beginning. Execution is what counts. We safeguard information security on three levels.

01Security by Design

Security and privacy are in the system from the first design choice, not bolted on afterwards. Every component is built to least privilege and data minimisation.

02Sovereign & European Cloud

We run on European infrastructure, so data always falls under European law. No ambiguity about where your data sits or who has access to it.

03Processes & Access management

Clear processes around access, incidents and handover, with role-based authorisation and a full audit trail. That keeps security safeguarded in daily practice.

Guarantees for your organisation

By working with Researchable you choose a technology partner with demonstrable control over data security.

Data protection

Least privilege, encryption in transit and at rest, and strict key management.

Legal compliance

Demonstrably in line with GDPR and, for healthcare, with NEN 7510.

Proactive risk mitigation

Continuous monitoring, periodic risk analyses and a rehearsed incident process.

Business continuity

Tested backups, failover and recovery procedures, so systems stay available.

Researchable engineer at work

Security you see reflected in every choice.

From the architecture of a system to the management of access: security is not a layer we add on top, but a starting point in everything we build.

Frequently asked questions

Everything you want to know about our certification, compliance and how we handle your data.

An independent, accredited auditor has established that we operate a full ISMS to the standard. That covers policy, access management and risk management, through to our data architecture and AI product development, including hosting and management.

Yes. The full lifecycle, from training data and model development to production and management, falls within the scope. The same requirements for access, encryption and data minimisation apply to AI workloads as to the rest of our infrastructure.

They reinforce each other. The standard provides the management system and the technical measures with which we demonstrably meet the GDPR's requirements around security and accountability. ISO 27001 is a means, GDPR compliance an obligation.

NEN 7510 is the Dutch standard for information security in healthcare and builds on ISO 27001. Our ISO foundation connects to it directly, so we offer medical partners a demonstrably suitable level.

Certainly. We are happy to share our current certificate and the accompanying scope statement on request. Get in touch and we will send the documentation.

We follow a fixed incident process with predefined roles: detection, containment and communication. Affected parties and, where applicable, the Dutch Data Protection Authority are informed within the statutory deadlines.

By default we keep data within the EU on European infrastructure, under European law. Where a situation deviates from this, we set out transparently in advance where data sits and which safeguards apply.

Question about security?Certification?Get a call back
Eduard van Pagée

Ask your question about security, certification or compliance. We give you an honest answer.