Security

Security at DataGrid

Last updated: April 29, 2026

Our commitment

Information security is a foundation of our service.

DataGrid B.V. develops and operates ONEX, a SaaS platform for data exchange in the Dutch healthcare sector. We process sensitive and special-category personal data. Our management recognizes that our customers, their clients and our employees rely on us to take information security seriously — not as a checklist, but as an ongoing discipline.

We have implemented an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022 and NEN 7510-1:2024. Regardless of the outcome of our external certification audit, we remain committed to:

  • establishing, maintaining and continuously improving our ISMS;
  • providing adequate resources to make information security effective;
  • embedding risk-based thinking into our decisions and architecture;
  • complying with applicable laws and regulations (GDPR, NEN 7510, sector-specific requirements);
  • communicating transparently about our security posture toward customers, employees and supervisory authorities.

Certification status

DataGrid operates an ISMS aligned with ISO/IEC 27001:2022 and NEN 7510-1:2024. At the time this page was published, we are undergoing the external Stage 2 certification audit by Kiwa Nederland (28–30 April 2026). We are not yet certified; upon issuance of the certificate, we will update this page within one business week with certificate number and validity period.

How we protect personal data

  • Encryption at rest and in transit (TLS 1.2+).
  • Geo-redundant backups on Microsoft Azure (West / North Europe).
  • MFA and Conditional Access on all employee access.
  • Four-eyes review on all changes via Pull Request.
  • Periodic vulnerability assessment and threat intelligence monitoring.
  • 24/7 incident response with data-breach notification process (GDPR, < 72 hours).

Responsible disclosure

Have you discovered a vulnerability in our services? Please report it via security@datagrid.nl. We will confirm receipt within one business day and provide updates on progress. See also our security.txt per RFC 9116.

Compliance & processors

We rely on carefully selected sub-processors with demonstrated security:

  • Microsoft Azure — ISO 27001 / NEN 7510 / SOC 2 (see Microsoft Trust Center).
  • GitHub — SOC 2 / ISO 27001.

GDPR art. 28 data-processing agreements with customers are available on request via info@datagrid.nl.

Documentation on request

On request we provide customers with: an extract from our Statement of Applicability, a data-breach procedure summary, and an overview of our Business Continuity Plan. Send your request to info@datagrid.nl with subject "Security documentation".

Contact