Security at Daxap

At Daxap, security, privacy, and operational reliability are integrated into every stage of how we design, develop, and manage digital solutions. We believe security should be part of the foundation — not an afterthought added later in the process.

  • ISO 27001 Certified

    Daxap is ISO 27001 certified and operates with an active Information Security Management System (ISMS), continuous risk management processes, and a dedicated CISO ensuring ongoing compliance, governance, and improvement.

  • GDPR Compliant

    Our development practices follow the principles of Privacy by Design, ensuring that privacy, data protection, and regulatory considerations are built into solutions from the earliest stages of architecture and development.

  • Environmental Lighthouse Certified

    Operational responsibility is part of how we build technology. As a certified Environmental Lighthouse company, we work continuously to improve sustainability across both our internal operations and digital infrastructure.

  • Securely Designed

    Security architecture is considered from the first technical decisions. Threat modeling, access control, encryption, infrastructure security, and operational resilience are integrated directly into solution design and development workflows.

  • Encryption

    All data in transit and at rest is encrypted using strong industry-standard protocols, including TLS/SSL and AES.

  • Network Segregation and Security

    Daxap separates systems and environments to strengthen the protection of sensitive data, reduce operational risk, and support secure infrastructure management.

  • Access to Systems

    We apply the principle of least privilege across our systems and infrastructure, ensuring that access is limited to authorized personnel only. Multi Factor Authentication (MFA) is required across internal systems and operational environments.

  • Logging and Monitoring

    Systems, infrastructure, and operational activity are continuously logged and monitored to strengthen visibility, support auditing, and help identify potential misuse or security incidents.

  • Responding to Security Incidents

    Daxap maintains established incident management processes designed to identify, contain, investigate, and remediate security incidents in a structured and operationally reliable manner.

  • Continuous Security Work

    Security is an ongoing operational process. Through regular audits, reviews, monitoring, and continuous improvement initiatives, we work to ensure that our solutions remain secure, compliant, and resilient as technology and threat landscapes evolve.

  • AI Act Ready

    We continuously monitor emerging regulatory frameworks, including the EU AI Act, and design solutions with governance, transparency, and compliance readiness in mind.

FAQ

Yes. Daxap has established an Information Security Management System (ISMS) from the inception of the company and manages ISMS through policies, procedures and trusted service providers.

Daxap fulfills all the requirements of ISMS with the security team, led by our Chief Information Security Officer (CISO). The team implements and manages the security program.

Yes, Daxap holds ISO 27001 certification, necessitating regular external audits of our information security management system and security controls.

Daxap does not own its data centers. Instead, we make use of industry leading Cloud Services to store and discard your data. All data is fully encrypted and the systems are only accessible by people and services as defined in our ISMS.

Daxap has an Incident Management policy and procedures, as well as software to proactively detect incidents or threats of incidents. Our security team detects, defines, and responds to incidents as soon as it has been identified. In case of a security incident, or even the threat of one, our customers will receive information about the time, nature and cause of the incident, as well as a plan to ensure any future vulnerabilities are protected.