Background with verticals lines

Security isn't a layer we add on. It's the foundation we build on

Trust & security

Nostrion builds sovereign AI for Europe's most regulated sectors. That means security, privacy and sovereignty are built in from the first design decision — not bolted on afterwards.

ISO 27001
NEN 7510
ISO 42001
GDPR
EU AI ACT
GIN

Core principles

Six principles, one foundation

For every part of our platform, we ask the same questions: is it secure, is it privacy-resilient, does control stay with the customer — and can we prove it? Not a checklist applied afterwards, but the starting point for every architectural decision.

Security-by-design

Zero-trust architecture with strict separation between customer environments. Security-relevant events are logged, traceable and auditable. Encryption of data at rest and in transit is the norm, not the exception.

Privacy-by-design

Data minimisation and purpose limitation are built into our platform. Personal data is never used outside the agreed scope, and a human always retains final responsibility for sensitive decisions.

Sovereignty-by-design

Data and IP stay within a processing chain that is fully EU-hosted and EU-owned. Our architecture is resilient against extraterritorial claims such as the US CLOUD Act — your data, your AI, your control.

No model training

Your data is used exclusively within your own platform environment and never to train or improve underlying models — not for you, and not for other customers. Our model providers are contractually bound to this as well.

Zero-trust isolation

Every customer gets their own, isolated sovereign vault. Strict architectural separation keeps customer environments, IP and sensitive data from mixing.

Independently assessed

Our software is continuously tested through automated security testing (SAST) and continuous penetration testing — alongside the independent audits for our ISO 27001, NEN 7510 and ISO 42001 certifications.

In depth

Data sovereignty:
more than just "in Europe"

Sovereignty-by-design means more to us than a server location on a map. We look at the entire processing chain: where data is processed, who the supplier is, and which jurisdiction that supplier falls under.

For us, data sovereignty is a hard requirement, not a sliding scale. Everything that actually touches your data — hosting, AI infrastructure, model processing — is EU-hosted and EU-owned. No exceptions and no middle ground: if a supplier doesn't meet that requirement, it doesn't enter the chain that processes your data.

Fully EU-hosted and EU-owned

Across the entire primary processing chain — hosting, AI infrastructure and model processing — both the location and the ownership of the supplier lie within the EU; we do not work with US cloud providers or hyperscalers.

Fully governed by EU law

Our entire processing chain — hosting and AI infrastructure — consists of a small number of carefully selected suppliers, each of them EU-hosted and EU-owned. That means your data falls fully under European law and regulation.

Even with commercial AI models

When we deploy a commercial or proprietary model, it runs within our own European infrastructure — your data is never sent to the original model provider.

A continuously assessed chain

Every supplier undergoes an upfront assessment on security, privacy and jurisdiction, and is reassessed every six months after that — including on data sovereignty. That way, this stays a continuous safeguard, not a one-time snapshot.

You are, and remain, the owner of your data

Nostrion processes your data solely to deliver the agreed service — never for our own purposes. If you end our collaboration, we delete your data: it remains yours, not ours.

What it means for you

The people-process-technology triangle for your organisation

When your organisation works with the Nostrion platform, the people-process-technology triangle shows up in your day-to-day practice — not as an abstract principle, but very concretely across all three dimensions.

Chart

People

Your domain experts — the notary, accountant, administrative staff member or compliance officer — always retain final control. The platform supports and accelerates, but professional responsibility stays exactly where it belongs: with your people.

Process

Recurring work becomes faster, more consistent and fully traceable. AI takes on the volume, freeing up your people to focus on quality — on the work itself and on the end client. Your own quality and compliance processes remain leading; the platform fits around them rather than replacing them.

Technology

You benefit from a zero-trust processing chain that is fully EU-hosted and EU-owned, and secure by virtue of security-by-design, privacy-by-design and sovereignty-by-design. Your data and IP demonstrably remain within your own control.

How we organise it

The same triangle, applied to our own organisation

We apply that same triangle to ourselves. For Nostrion, security, privacy and sovereignty aren't product features — they're a way of organising.

People

Nostrion employees have no access to customer data within the platform. Access to our own systems is personal, secured with multi-factor authentication and set up on a least-privilege basis. Employees are screened and continuously trained in information security and the responsible use of AI.

Process

Our governance is ISO 27001, NEN 7510 and ISO 42001 certified, and for the notarial sector set up in line with the GIN. Incident response, change management and periodic risk assessments are standing parts of how we operate — and we're transparent about it.

Technology

Zero-trust architecture, encrypted sovereign vaults and continuous monitoring form the technical foundation of our own platform and internal systems. Software is structurally tested for vulnerabilities, both through automated testing during development and through external penetration testing. That keeps security part of the full lifecycle of our service, from design to production.

Chart

In practice

How we protect your data

Our principles and governance take concrete shape in the day-to-day protection of your data. These are the measures that make the difference.

Encryption, everywhere

Data is stored encrypted and transmitted encrypted. This applies to every environment within our platform, without exception.

Confidentiality by default

All customer data is treated as confidential, regardless of its nature or content. Confidentiality is the starting point, not a separate assessment per file.

Strict access security

Access is personal, secured with multi-factor authentication and set up on a least-privilege basis. We do not allow shared accounts.

Logging & monitoring

Logins, failed attempts and security-relevant changes are logged and monitored, so anomalies are flagged quickly.

Notify and recover

If an incident affects your data, we will, as a rule, inform you within 24 hours about its nature, impact and the measures taken. For larger disruptions, we maintain a continuity and disaster recovery plan, with periodic failover testing.

Fixed retention and deletion periods

Fixed retention periods apply to every data category. After the agreement ends, we delete your personal data, as a rule, within one month.

Frameworks & standards

Assessed against the frameworks that matter

We don't get assessed to display a badge. We do it because it enforces the discipline our customers need.

Abstract topographic line pattern

ISO 27001

Certified

The international standard for information security, externally certified. Governs how sensitive information is structurally protected, from access management to incident response.

NEN 7510

Certified

The Dutch standard for information security in healthcare, externally certified. Governs how sensitive patient data is protected within healthcare organisations.

ISO 42001

Certified

The international management system for responsible AI, externally certified. Governs how we manage AI risk, from design to monitoring in production.

GDPR

Compliant

Built into every pipeline: data minimisation, purpose limitation and a clear legal basis for every processing of personal data.

EU AI Act

Compliant

We proactively align our governance, risk management and transparency obligations with the European AI Act.

GIN

Compliant

The information security code of conduct for the Dutch notarial sector — the framework through which Fidacta aligns with the sector's specific requirements.

Our certifications cover our entire business operations, not just the product.

Full standard references: NEN-EN-ISO/IEC 27001:2023/A1:2024 nl, NEN 7510-1:2024 nl, NEN-EN-ISO/IEC 42001:2026.

Want to view certificates, policy documents and audit reports?

Bright cosmic explosion sphere with light rays above open hands

Have questions?

Schedule a conversation with our Chief Compliance Officer.