Skip to content
The loopWorking togetherSecurityWorkSuiteJournal About Trust Center
Start a conversation NL

Home / Trust Center: security, compliance and policies

Trust Center: security, compliance and policies

How Mape protects your data. GDPR and EU AI Act conform, EU hosting, and the full policy set available on request.

Position

How we protect your data.

Mape builds and operates systems that hold other people's data. That means security is not a department here. It is a property of how the software is put together. Everything on this page is either true today or labelled as in progress.

GDPR / AVG conform EU AI Act conform Data stored in the EU ISO 27001 in progress

Compliance

Where we actually stand.

Two frameworks we conform to today, and one certification we are working towards and have not yet achieved.

  • GDPR / AVG: conform. Processing register maintained, processor agreements with partners, 72-hour breach notification, data-subject rights honoured.
  • EU AI Act: conform. AI System Register with a risk classification per system. None are high-risk or prohibited.
  • ISO 27001:2022, in progress. Certification programme started June 2026, target Q3 2027. We are not certified today.

Measures

How your data is protected.

Encryption

TLS in transit and AES-256 at rest. Credentials in a managed secret store with rotation, never in code.

Access control

MFA required on every platform. Every person and every agent gets only the access they need, enforced at the data layer.

Vulnerability management

Periodic scanning for vulnerabilities and leaked credentials. Findings are fixed and then verified.

Incident response

A documented plan with named responsibilities. Breaches reported to the Autoriteit Persoonsgegevens within 72 hours.

Responsible AI

Human oversight on every critical action. Customer data is never used for model training and prompts are not retained.

Continuity

Daily backups with versioning and a tested restore path. Each partner project runs in its own isolated environment.

Documents

Open policies, and the rest on request.

Three policies are published in full. The remainder are shared after a short review. Email security@mapemedia.com with your name, organisation and which document you need. We respond within two working days.

Data Security Policyon request
Processing Register (ROPA)on request
AI System Registeron request
Incident Response Planon request
Sub-processor Liston request
Data Processing Agreement (template)on request
Business Continuity & Backup Policyon request
Secure Development Processon request
Cryptography & Access Control Policyon request

Tick what you need. We reply within two working days.

Request selected documents

Common questions

What buyers ask us most.

Is our data used to train AI models?

No. Customer data is never used for model training, and our providers do not retain prompts or outputs after processing.

Where is our data stored?

In EU data centres. Where a sub-processor operates outside the EU, Standard Contractual Clauses apply. The full list is available on request.

Do you hold certifications?

We conform to GDPR and the EU AI Act. ISO 27001 and ISO 42001 are on the roadmap; we do not hold either yet and will not imply that we do.

Tell us what your business runs on.

If it is the kind of system that cannot have a bad day, we should talk. One conversation, no deck, with the people who would build it.