Skip to content
The loopWorking togetherSecurityWorkSuiteJournal About Trust Center
Start a conversation NL

Home / Security and compliance at Mape

Security and compliance at Mape

Tenant isolation at the database layer, append-only logging, EU-only hosting, and an ISO 27001 programme underway. GDPR and EU AI Act conform.

Position

Compliance is an architecture decision, not a document.

If tenant isolation lives in application code, someone eventually forgets a WHERE clause. If it lives in the database, they cannot. Nearly everything below follows from choices like that one, made before any feature was written.

GDPR conform EU AI Act conform EU hosting only NEN 7513 logging

Evidence

Nothing is written until it has been checked.

Every change passes type checks, tests, a migration dry-run and a tenant-isolation pass before it can exist anywhere a client could see.

01 · Checked first

Nothing is written until it has been checked.

Type checks, tests, a migration dry-run and a tenant-isolation pass, before a client could ever see it.

02 · Recorded, not editable

Once it happens, it cannot be un-happened.

An append-only trail nobody can edit afterwards — including us.

03 · Evidenced against a standard

And it maps to a standard someone else wrote.

Controls implemented and evidenced as we go, against ISO 27001:2022 and NEN 7513.

How it is built

The parts an auditor reads first.

Isolation at the database

Row-level security on every table that touches customer data. Every query path is enforced by the database itself, and every file sits behind a tenant-scoped signed URL.

Append-only by construction

The audit trail cannot be edited after the fact — not by a customer, not by us. That property is the entire reason it is worth reading during an audit.

Access that expires

Multi-factor authentication by default, role-based access enforced at the data layer, and an offboarding procedure that actually removes access rather than disabling a login.

Encrypted throughout

TLS in transit, AES-256 at rest. Credentials live in a managed secret store with a rotation schedule — never in code, never in a repository, never in a message.

EU-only processing

Databases and application hosting inside the EU. Where a sub-processor sits outside it, Standard Contractual Clauses apply and the full list is available on request.

Recoverable

Daily database backups with point-in-time recovery, file versioning, and a restore procedure that is tested rather than assumed.

Certification

ISO 27001 certification, actively in progress.

We are working towards full ISO 27001:2022 certification with a target of Q3 2027. We are not certified today and we will not imply otherwise — a programme underway is worth more to you than a badge we do not hold.

STARTED

Started June 2026

Full certification path chosen over alignment-only, with an ISMS scope statement and a management structure rather than a folder of documents.

NOW

18 of 93 controls live now

Annex A controls implemented and evidenced as we go, with the Statement of Applicability as the single source of truth.

TARGET

Certificate targeted Q3 2027

Internal audit, external gap analysis, then Stage 1 and Stage 2. NEN 7510 coverage for healthcare partners follows on the same programme.

AI, specifically. Customer data is never used to train models. Prompts and outputs are not retained by our providers after processing. Every AI system we operate is listed in an AI System Register with a risk classification under the EU AI Act, and none of them fall into the high-risk or prohibited categories.

Tell us what your business runs on.

If it is the kind of system that cannot have a bad day, we should talk. One conversation, no deck, with the people who would build it.