Home / Trust Center: security, compliance and policies
Trust Center: security, compliance and policies
How Mape protects your data. GDPR and EU AI Act conform, EU hosting, and the full policy set available on request.
Position
How we protect your data.
Mape builds and operates systems that hold other people's data. That means security is not a department here. It is a property of how the software is put together. Everything on this page is either true today or labelled as in progress.
Compliance
Where we actually stand.
Two frameworks we conform to today, and one certification we are working towards and have not yet achieved.
- GDPR / AVG: conform. Processing register maintained, processor agreements with partners, 72-hour breach notification, data-subject rights honoured.
- EU AI Act: conform. AI System Register with a risk classification per system. None are high-risk or prohibited.
- ISO 27001:2022, in progress. Certification programme started June 2026, target Q3 2027. We are not certified today.
Measures
How your data is protected.
Encryption
TLS in transit and AES-256 at rest. Credentials in a managed secret store with rotation, never in code.
Access control
MFA required on every platform. Every person and every agent gets only the access they need, enforced at the data layer.
Vulnerability management
Periodic scanning for vulnerabilities and leaked credentials. Findings are fixed and then verified.
Incident response
A documented plan with named responsibilities. Breaches reported to the Autoriteit Persoonsgegevens within 72 hours.
Responsible AI
Human oversight on every critical action. Customer data is never used for model training and prompts are not retained.
Continuity
Daily backups with versioning and a tested restore path. Each partner project runs in its own isolated environment.
Documents
Open policies, and the rest on request.
Three policies are published in full. The remainder are shared after a short review. Email security@mapemedia.com with your name, organisation and which document you need. We respond within two working days.
Tick what you need. We reply within two working days.
Request selected documentsCommon questions
What buyers ask us most.
Is our data used to train AI models?
No. Customer data is never used for model training, and our providers do not retain prompts or outputs after processing.
Where is our data stored?
In EU data centres. Where a sub-processor operates outside the EU, Standard Contractual Clauses apply. The full list is available on request.
Do you hold certifications?
We conform to GDPR and the EU AI Act. ISO 27001 and ISO 42001 are on the roadmap; we do not hold either yet and will not imply that we do.
Tell us what your business runs on.
If it is the kind of system that cannot have a bad day, we should talk. One conversation, no deck, with the people who would build it.