Security at DataGrid
Last updated: April 29, 2026
Our commitment
Information security is a foundation of our service.
DataGrid B.V. develops and operates ONEX, a SaaS platform for data exchange in the Dutch healthcare sector. We process sensitive and special-category personal data. Our management recognizes that our customers, their clients and our employees rely on us to take information security seriously — not as a checklist, but as an ongoing discipline.
We have implemented an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022 and NEN 7510-1:2024. Regardless of the outcome of our external certification audit, we remain committed to:
- establishing, maintaining and continuously improving our ISMS;
- providing adequate resources to make information security effective;
- embedding risk-based thinking into our decisions and architecture;
- complying with applicable laws and regulations (GDPR, NEN 7510, sector-specific requirements);
- communicating transparently about our security posture toward customers, employees and supervisory authorities.
Certification status
DataGrid operates an ISMS aligned with ISO/IEC 27001:2022 and NEN 7510-1:2024. At the time this page was published, we are undergoing the external Stage 2 certification audit by Kiwa Nederland (28–30 April 2026). We are not yet certified; upon issuance of the certificate, we will update this page within one business week with certificate number and validity period.
How we protect personal data
- Encryption at rest and in transit (TLS 1.2+).
- Geo-redundant backups on Microsoft Azure (West / North Europe).
- MFA and Conditional Access on all employee access.
- Four-eyes review on all changes via Pull Request.
- Periodic vulnerability assessment and threat intelligence monitoring.
- 24/7 incident response with data-breach notification process (GDPR, < 72 hours).
Responsible disclosure
Have you discovered a vulnerability in our services? Please report it via security@datagrid.nl. We will confirm receipt within one business day and provide updates on progress. See also our security.txt per RFC 9116.
Compliance & processors
We rely on carefully selected sub-processors with demonstrated security:
- Microsoft Azure — ISO 27001 / NEN 7510 / SOC 2 (see Microsoft Trust Center).
- GitHub — SOC 2 / ISO 27001.
GDPR art. 28 data-processing agreements with customers are available on request via info@datagrid.nl.
Documentation on request
On request we provide customers with: an extract from our Statement of Applicability, a data-breach procedure summary, and an overview of our Business Continuity Plan. Send your request to info@datagrid.nl with subject "Security documentation".
Contact
- Security questions: security@datagrid.nl
- General inquiries: info@datagrid.nl