DECOS TRUST CENTER
“Trust but verify” a famous statement by former US President Ronald Reagan that has taught us that is important to verify that all the agreements made also have been implemented.
Certifications and Standards
Decos undergoes an annual audit by an independent certification body. Below are the standards for which we are certified.
| Standard | Scope | Certificate |
| ISO/IEC 27001:2022 | Information Security (ISMS) | View certificate |
| ISO/IEC 27017 | Cloud Services Security | View certificate |
| ISO/IEC 27018 | Protection of personal data in the cloud | View certificate |
| ISO 9001:2015 | Quality management | View certificate |
| ISO/IEC 20000-1:2018 | IT service management | View certificate |
ISO 27017 and ISO 27018 build upon ISO 27001 and are specifically focused on our SaaS services. The controls required by both standards are included in our Statement of Applicability, which is available upon request.
Assurance Reports
-
ISAE 3000 / SOC 2 Type 2: A SOC 2 audit assesses a cloud service provider's controls against the AICPA Trust Services Criteria. A Type I report evaluates the design and implementation of controls, while a Type II report also assesses their operating effectiveness over an agreed period. Decos holds a SOC 2 Type II report covering the period from 1 October 2024 through 30 September 2025. A customized report can be requested through your Business Consultant. Additional charges apply.
-
DigiD: For products that offer a DigiD integration, we comply with the standards set by Logius. The audit is performed by a certified auditor affiliated with NOREA. The current assurance report is available to our existing and prospective DigiD customers.
Other Frameworks
-
BIO (Baseline Information Security for Government Organizations): Not a certifiable standard, but a Dutch government-specific implementation of ISO 27001 and ISO 27002. Our controls align with BIO requirements, enabling our customers to support their own BIO compliance obligations.
-
Forum Standardization: We comply with the “comply or explain” obligation for open standards. Not every standard on this list is applicable to all our services.
-
ISO 16175-1:2020: Applicable to JOIN Case & Document. See the Declaration of Compliance.
-
NEN 2082:2008: JOIN Case & Document was previously certified against this standard. The standard has since been withdrawn and replaced by ISO 16175.
Security
Decos manages data and systems for various local and regional government authorities and businesses. Our principles and practices are based on the need of our customers that they want their data and systems protected using the most up-to-date techniques and standards.
Due to the various requirements of the General Data Protection Regulation (GDPR), Decos has chosen to host its servers and infrastructure within the European Economic Area (EEA). For this we make use of the data centers of Microsoft, Amazon and Oracle within the EEA.
Microsoft itself is certified according to many standards that are required or needed in different industries. You can find them for Microsoft here, for Amazon here and for Oracle here.
Decos' management objectives and measures are based, among other things, on the aforementioned industry standard ISO27001:2017 and the OWASP Top10.
Backup & disaster recovery
We take data availability in our cloud solutions very seriously. We use different methods to back-up your data for restore purposes, for example point-in-time-restore (PITR), snapshots and differential backups. For every resource we have configured a retention policy. If you want more information on the retention policy contact Decos Security.
To secure your data, we can store the data either redundant within a zone in a datacenter (LRS), or at multiple zones within a datacenter within the EEA (ZRS), or in multiple datacenters (sometimes in multiple countries) within the EEA (GRS). Contact your account manager for more information about this or check the website of Microsoft: Data redundancy - Azure Storage.
Organizational security
In order to be able to offer safe and secure products, our own organization needs to be the same. This means that all our employees:
- Are made aware of information security from the moment they start at Decos.
- Are continuously educated on information security.
- Will have to provide a “Verklaring omtrent gedrag” (VOG) besides the regular screening.
- Will have to use 2FA to access our systems.
- Have an NDA clause in their contract.
All our employees are forced to adopt Multi-Factor Authentication (MFA/2FA) to access our systems. We are even further migrating to a Zero-Trust policy for system access. We apply strict Role-Based Access (RBAC) and assign privileges only based on need. Events and logs related to failed or successful authentication are aggregated for monitoring and triage.
Furthermore, Decos adopts a "cloud-first" policy. This means that the infrastructure in our offices is minimal. We do, of course, use personal access capabilities, CCTV and alarm systems. Employees are also only granted access to regular areas such as the shop floor by default.
Secure software development
Applications developed by Decos are designed with the OWASP Top 10 Framework, among others, in mind.All code goes through a quality assurance process before it is released to the production environment.This includes testing for performance, functionality and security. In addition, our applications are periodically tested internally and externally.
As regards the encryption of data, Decos has an encryption policy.Decos encrypts the data in "transit" and "at rest":
- All traffic is encrypted using TLS 1.2 (or higher).
- Data "at rest" is encrypted using AES-256 or better.
- A modern hash function that "hashed" and "salted" the data is used to store login data.
Responsible disclosure
Decos uses a Responsible disclosure policy. This ensures that security experts from around the world can report to us if a problem is found.
.png?width=4654&height=987&name=logo-full-duotone%20(3).png)