
Security isn't a layer we add on. It's the foundation we build on
Trust & security
Nostrion builds sovereign AI for Europe's most regulated sectors. That means security, privacy and sovereignty are built in from the first design decision — not bolted on afterwards.






Core principles
Six principles, one foundation
For every part of our platform, we ask the same questions: is it secure, is it privacy-resilient, does control stay with the customer — and can we prove it? Not a checklist applied afterwards, but the starting point for every architectural decision.
Security-by-design
Zero-trust architecture with strict separation between customer environments. Security-relevant events are logged, traceable and auditable. Encryption of data at rest and in transit is the norm, not the exception.
Privacy-by-design
Data minimisation and purpose limitation are built into our platform. Personal data is never used outside the agreed scope, and a human always retains final responsibility for sensitive decisions.
Sovereignty-by-design
Data and IP stay within a processing chain that is fully EU-hosted and EU-owned. Our architecture is resilient against extraterritorial claims such as the US CLOUD Act — your data, your AI, your control.
No model training
Your data is used exclusively within your own platform environment and never to train or improve underlying models — not for you, and not for other customers. Our model providers are contractually bound to this as well.
Zero-trust isolation
Every customer gets their own, isolated sovereign vault. Strict architectural separation keeps customer environments, IP and sensitive data from mixing.
Independently assessed
Our software is continuously tested through automated security testing (SAST) and continuous penetration testing — alongside the independent audits for our ISO 27001, NEN 7510 and ISO 42001 certifications.
In depth
Data sovereignty:
more than just "in Europe"
Sovereignty-by-design means more to us than a server location on a map. We look at the entire processing chain: where data is processed, who the supplier is, and which jurisdiction that supplier falls under.
For us, data sovereignty is a hard requirement, not a sliding scale. Everything that actually touches your data — hosting, AI infrastructure, model processing — is EU-hosted and EU-owned. No exceptions and no middle ground: if a supplier doesn't meet that requirement, it doesn't enter the chain that processes your data.
Fully EU-hosted and EU-owned
Across the entire primary processing chain — hosting, AI infrastructure and model processing — both the location and the ownership of the supplier lie within the EU; we do not work with US cloud providers or hyperscalers.
Fully governed by EU law
Our entire processing chain — hosting and AI infrastructure — consists of a small number of carefully selected suppliers, each of them EU-hosted and EU-owned. That means your data falls fully under European law and regulation.
Even with commercial AI models
When we deploy a commercial or proprietary model, it runs within our own European infrastructure — your data is never sent to the original model provider.
A continuously assessed chain
Every supplier undergoes an upfront assessment on security, privacy and jurisdiction, and is reassessed every six months after that — including on data sovereignty. That way, this stays a continuous safeguard, not a one-time snapshot.
You are, and remain, the owner of your data
Nostrion processes your data solely to deliver the agreed service — never for our own purposes. If you end our collaboration, we delete your data: it remains yours, not ours.
What it means for you
The people-process-technology triangle for your organisation
When your organisation works with the Nostrion platform, the people-process-technology triangle shows up in your day-to-day practice — not as an abstract principle, but very concretely across all three dimensions.

People
Your domain experts — the notary, accountant, administrative staff member or compliance officer — always retain final control. The platform supports and accelerates, but professional responsibility stays exactly where it belongs: with your people.
Process
Recurring work becomes faster, more consistent and fully traceable. AI takes on the volume, freeing up your people to focus on quality — on the work itself and on the end client. Your own quality and compliance processes remain leading; the platform fits around them rather than replacing them.
Technology
You benefit from a zero-trust processing chain that is fully EU-hosted and EU-owned, and secure by virtue of security-by-design, privacy-by-design and sovereignty-by-design. Your data and IP demonstrably remain within your own control.
How we organise it
The same triangle, applied to our own organisation
We apply that same triangle to ourselves. For Nostrion, security, privacy and sovereignty aren't product features — they're a way of organising.
People
Nostrion employees have no access to customer data within the platform. Access to our own systems is personal, secured with multi-factor authentication and set up on a least-privilege basis. Employees are screened and continuously trained in information security and the responsible use of AI.
Process
Our governance is ISO 27001, NEN 7510 and ISO 42001 certified, and for the notarial sector set up in line with the GIN. Incident response, change management and periodic risk assessments are standing parts of how we operate — and we're transparent about it.
Technology
Zero-trust architecture, encrypted sovereign vaults and continuous monitoring form the technical foundation of our own platform and internal systems. Software is structurally tested for vulnerabilities, both through automated testing during development and through external penetration testing. That keeps security part of the full lifecycle of our service, from design to production.

In practice
How we protect your data
Our principles and governance take concrete shape in the day-to-day protection of your data. These are the measures that make the difference.
Encryption, everywhere
Data is stored encrypted and transmitted encrypted. This applies to every environment within our platform, without exception.
Confidentiality by default
All customer data is treated as confidential, regardless of its nature or content. Confidentiality is the starting point, not a separate assessment per file.
Strict access security
Access is personal, secured with multi-factor authentication and set up on a least-privilege basis. We do not allow shared accounts.
Logging & monitoring
Logins, failed attempts and security-relevant changes are logged and monitored, so anomalies are flagged quickly.
Notify and recover
If an incident affects your data, we will, as a rule, inform you within 24 hours about its nature, impact and the measures taken. For larger disruptions, we maintain a continuity and disaster recovery plan, with periodic failover testing.
Fixed retention and deletion periods
Fixed retention periods apply to every data category. After the agreement ends, we delete your personal data, as a rule, within one month.
Frameworks & standards
Assessed against the frameworks that matter
We don't get assessed to display a badge. We do it because it enforces the discipline our customers need.

ISO 27001
Certified
The international standard for information security, externally certified. Governs how sensitive information is structurally protected, from access management to incident response.
NEN 7510
Certified
The Dutch standard for information security in healthcare, externally certified. Governs how sensitive patient data is protected within healthcare organisations.
ISO 42001
Certified
The international management system for responsible AI, externally certified. Governs how we manage AI risk, from design to monitoring in production.
GDPR
Compliant
Built into every pipeline: data minimisation, purpose limitation and a clear legal basis for every processing of personal data.
EU AI Act
Compliant
We proactively align our governance, risk management and transparency obligations with the European AI Act.
GIN
Compliant
The information security code of conduct for the Dutch notarial sector — the framework through which Fidacta aligns with the sector's specific requirements.
Our certifications cover our entire business operations, not just the product.
Full standard references: NEN-EN-ISO/IEC 27001:2023/A1:2024 nl, NEN 7510-1:2024 nl, NEN-EN-ISO/IEC 42001:2026.
Want to view certificates, policy documents and audit reports?

Have questions?
Schedule a conversation with our Chief Compliance Officer.