FAQ

Yes. ioki encrypts data in transit using TLS (TLS 1.3 internally and TLS 1.2 or higher for public endpoints) and encrypts data at rest using strong, industry-standard algorithms such as AES-256, including provider-managed encryption for production datastores and full-disk encryption for storage nodes. Approved algorithms and protocols are defined in our internal Cryptographic Controls Policy.

ioki's production infrastructure is hosted in EU data centers. We prioritise cloud and infrastructure providers that hold recognised security certifications (such as ISO/IEC 27001), and we assess and record each provider in our supplier register before use.

ioki provides a standard, EU-aligned Data Processing Agreement (DPA) as part of customer contracting. To request a copy, please reach out to your ioki contact.

Yes. ioki conducts penetration testing at least annually, and findings are tracked through a remediation plan and resolved according to severity-based timelines. A summary may be shared with customers under NDA on request.

Access to production systems is restricted to authorised personnel on a least-privilege, need-to-know basis. We enforce multi-factor authentication and unique individual accounts, and we review access rights regularly — at least annually, and quarterly for privileged access.

We maintain a formal incident response process covering detection, triage, containment, eradication, recovery and post-incident review, with 24/7 on-call escalation. Where a personal-data breach is involved, we carry out a GDPR assessment within 72 hours, and affected customers are notified in accordance with applicable regulations and our contractual obligations.

ioki maintains a current list of subprocessors and provides advance notice of changes as part of our Data Processing Agreement. We carefully assess all third-party providers against our security and privacy requirements before onboarding them. See our Subprocessors page for the current list.

Yes. All personnel complete security awareness training during onboarding and at least once a year thereafter, with completion recorded. Role-specific competencies are defined in our internal Competency Register, and additional targeted training is provided where gaps are identified.

During incidents affecting our services, ioki posts status and resolution updates to our incident status page. Internally, availability is monitored continuously and governed by recovery objectives (RTO/RPO) defined in our Business Continuity and Disaster Recovery plans.

To request deletion of personal data, contact ioki's Data Protection Liaison. We validate each request and process it in line with applicable data protection law (for example, the GDPR generally requires a response within one month).