Controls

Infrastructure Security

Control Status
Infrastructure managed as code
All server, network and access configuration is defined as code and changed only through reviewed merge requests — no manual changes to production.
Privileged access controlled and logged
Access to production systems is least-privilege and requires multi-factor authentication; direct root login is prevented and all privileged activity is logged.
Environments and tenants isolated
Development, staging, demo and production run in separate, isolated networks, and each customer is isolated in its own tenant.
Production data backed up
Production data is backed up automatically — continuous incremental plus regular full backups — and stored encrypted, off-site and geo-redundant, separate from production.
Backups restore-tested
Backups are restore-tested automatically on a regular basis to confirm they actually recover.
Database redundancy maintained
A delayed standby database replica and real-time change streaming provide redundancy and fast recovery.
Physical security enforced
Offices and the server room use layered physical perimeters, escorted visitors, lockable storage, clear-desk/clear-screen, and regularly reviewed access registers.
Assets inventoried and owned
Information assets, devices and infrastructure are inventoried with assigned owners and lifecycle controls.

Organizational Security

Control Status
Security awareness training
All staff complete security-awareness training at onboarding and at least once a year, with completion tracked.
Roles and responsibilities defined
Information-security roles and responsibilities are formally defined, from the Board and CISO down to every employee.
Competence managed
Required security competencies per role are defined in a competency register, and gaps are closed through training, mentoring or hiring.
Personnel screening
Staff are background-screened before engagement, proportional to role sensitivity.
Confidentiality agreements
Confidentiality / non-disclosure terms are signed before access to information is granted.
Supplier security governed
Suppliers are risk-assessed before onboarding and bound by contractual security and privacy clauses, including breach notification and secure deletion on exit.

Internal Security Procedures

Control Status
Risk assessment performed
ioki runs a documented, ISO 27005-aligned risk-management process: risks are identified, scored, treated and reviewed on a defined cadence, including an annual risk workshop.
Incident response process
A documented incident-response process (detect, triage, contain, fix, notify, post-mortem) runs with 24/7 on-call escalation.
Incident communication
During incidents, internal and external stakeholders — and, where required, regulators within 72 hours — are notified through defined channels.
ISMS effectiveness monitored
The information security management system is monitored and measured against defined pass/fail criteria across all control areas.
Independent internal audit
The ISMS is independently internally audited on a program that mirrors the certification body, with findings tracked to closure.
Change management
Every change is ticketed, risk-classified and four-eyes reviewed; high-impact changes require committee approval, and emergency changes get post-incident review.

AI Security & Compliance

Control Status
AI acceptable-use policy
ioki maintains an AI policy: only approved enterprise AI tools are allowed, personal data and secrets must never be entered, and consumer AI accounts are prohibited.
EU AI Act classification assessed
ioki has assessed and documents its EU AI Act classification and re-confirms it at least annually.

Product Security

Control Status
Penetration testing
The platform is penetration-tested at least annually, and findings are fixed on severity-based timelines.
Encryption in transit and at rest
Data is encrypted in transit using TLS (1.3 internally; 1.2 or higher for public endpoints) and at rest using strong, industry-standard algorithms such as AES-256, with managed keys.
Vulnerability management
Vulnerabilities are continuously scanned, triaged daily, and patched on SLA (critical issues within 24 hours).
Security logging and monitoring
Systems emit centralized, tamper-resistant logs and metric-driven alerts that route to 24/7 on-call.
Secure software development
Software is built secure-by-default: version control with four-eyes review, automated security gates (SAST/SCA/secret scanning), and separated environments.

Data and Privacy

Control Status
Privacy and PII protection
ioki processes personal data under the GDPR, with a Data Protection Liaison, data processing agreements with processors, a records-of-processing register and a DPIA process.
Information classification
All information is classified into defined levels (Public, Internal, Confidential, Strictly Confidential) with handling rules per level.
Retention and secure deletion rules
Data is retained only as long as needed and disposed of securely under defined retention and deletion rules.
Data deletion on request
Personal data is deleted on request: business customers can trigger deletion through configurable automated platform functions, and employee data is handled through defined HR processes.
Business continuity and disaster recovery
ioki maintains a Business Continuity Policy and a tested Disaster Recovery Plan covering scenarios such as cloud-provider loss, database corruption and ransomware.
Disaster recovery tested annually
The Disaster Recovery Plan is tested at least annually, and on significant change, with results documented and remediated.