Security at Protium
Protium.digital B.V. develops and operates managed trust-infrastructure services for data spaces, including iSHARE-compliant components delivered as fully managed SaaS. Security is embedded in how we build and run: everything is code, every change goes through a reviewed and scanned pipeline, and evidence is generated automatically.
Certification status
| Framework | Status |
|---|---|
| ISO/IEC 27001:2022 | Certification in progress — ISMS operational; certification audit planned |
| iSHARE Trust Framework | Compliant components — technical certification of Onboarding Portal / Participant Register |
We publish our real posture. The ISO 27001 certificate will be listed here, with scope, the day it is issued.
How we secure our services
Access. All access is personal, SSO-based and MFA-protected. Production access is limited to named accounts and fully logged. Authorisations are re-attested every six months.
Change. Every change reaches production only through a merge-request pipeline with four-eyes review, SCA/SAST scanning (build fails on high/critical findings), signed container images and automated rollback. Development, acceptance and production are fully segregated — separate secrets, data and integrations.
Operations. Continuous monitoring of availability, error rates, latency, certificates and capacity, with automated alerting. Runtime vulnerability scanning on all workloads. Daily encrypted backups with restore testing against defined RTO/RPO.
Continuity. Documented runbooks, tested recovery paths, and business-continuity plans exercised periodically.
People. Screening on engagement, confidentiality undertakings, annual security-awareness training, and strict rules for endpoints and AI-assisted development.
Suppliers. A reviewed supplier register; no subcontractor touches customer data or systems without the customer's prior written consent.
Security testing
Security test tooling runs continuously in our delivery pipelines, and penetration testing is performed on the acceptance environment. Reports are available to customers under NDA on request.
Responsible disclosure
Found a vulnerability? Please report it to [email protected]. We respond within 2 business days, we will not take legal action against good-faith research, and we ask you not to disclose until we have remediated.
Documents
Customers and auditors can sign in to access ISMS documentation (policies, Statement of Applicability). No account? Request access via [email protected].