
Trust and security
No certificate. The facts instead.
Softeria is not ISO 27001 certified. We would rather you heard that from us than found it out three meetings in — so here is exactly how the platform works instead.
What we can tell you is how the platform decides who reaches what, where your data sits, and what you can take with you when you go — and we answer, in writing, anything this page leaves open.
Access
Who can reach what
Permissions are checked where the data is stored, so a rule you set holds for every solution built on the platform — including the ones built next year by people who have not joined yet.
- Who signs in
- Your identity provider: Microsoft Entra ID, Google Cloud Identity, or any OpenID Connect provider such as Okta, Auth0 or Keycloak. We issue no new passwords, and when someone leaves your directory their access ends.
- Who may do what
- The groups you already maintain decide who can build, use live data, publish to the company and administer. There is no second directory to keep in step.
- Which records they see
- Row-level security is declared once and applied to every query on the server, by how the data is related — a person reaches a record through the links between records, not through a filter each solution has to remember.
- What was done
- An audit log of who built, changed and opened what.
- Checking it is right
- Access review answers "who can reach what" for any role or person, across every solution — the actual outcome of all the rules together, not the intention.
Your data
Where it lives, and how you leave
- Where it is stored
- On our own platform, in a region you choose in the EU or Norway. Encrypted, with automatic backups.
- Transfers out of the EEA
- Where a supplier processes data outside the EU/EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses with the safeguards those clauses require. Ask us and we will tell you about any transfer that affects you.
- What you can take with you
- The application code is yours. Data and database structure export in full at any time, including as plain SQL.
- Who runs it
- Hosting, deployment, backups and security updates are ours, for every solution your teams build.
If something goes wrong
What you can shut, limit and cap
- An off switch
- Take a misbehaving or compromised solution offline immediately, without deleting anything, and bring it back when it is resolved.
- IP allowlist
- Restrict which client network addresses may reach a solution at all. It runs before authentication, so a request from a disallowed address is turned away whatever token it carries.
- Changes that would break things
- Schema changes that would break existing data or existing callers are flagged before they run.
- Cost as a control
- Monthly cost per solution, with credit caps and spending thresholds set by you.
What this page does not say
Ask, and you get it in writing.
Some of what a security review needs belongs in a document with your name on it, not on a public page. Ask an engineer — not a sales team — and you will get:
- An architecture description for your security review
- Our data processing agreement, and the sub-processors involved
- Details of any transfer that affects your data
- How a specific rule of yours would be enforced, tried on your own setup
- hi@softeria.com
- Phone
- +47 46 77 40 00
- Also worth reading
- Privacy notice, terms of use and the questions and answers.