Trust is not a claim. It is evidence.
Find the measures, certification, agreements and evidence for Scope4mation and SAS. Public where possible; shared under controlled access where security requires it.

ISO/IEC 27001:2022/Amd 1:2024
Scope4mation is certified for the development, installation and support of SaaS and on-premise data integration software. The certificate is valid until 19 June 2029 and is evaluated annually.
For CISOs, DPOs, procurement and supplier reviews.
Not a marketing checklist, but the information needed to assess risk, continuity, privacy and control.
Security & certification
Certificate, audit context, penetration test information, measures and follow-up.
AVAILABLEPrivacy & processors
Processing agreements, sub-processors and appropriate sector models.
AVAILABLEContinuity & operations
Monitoring, incidents, backup, recovery, releases and service operations.
CONTROLLED ACCESSData, hosting & supply chain
Processing locations, hosting chain, supplier risk and relevant assurance.
CONTROLLED ACCESSCompliance & evidence
Relationship between the ISMS, controls and customer frameworks such as BIO2, GDPR and NEN 7510.
CONTEXT-SPECIFICExit & transfer
Agreements on data, configuration, logging, documentation and transferability.
PER AGREEMENTThe entire chain matters.
SAS is hosted from the Netherlands. Our ISMS also covers supplier and cloud risk, network and application security and continuity. Dutch does not automatically mean secure or autonomous; this is why we substantiate location, measures and the supplier chain separately.
A framework is the starting point. Demonstrable behaviour is the goal.
SAS can make measures part of daily processes: access, logging, exceptions, supplier steps, controlled data flows and evidence. We do not claim product certification for BIO2, NEN 7510, DORA or NIS2.
Request evidence or report a risk.
In an initial report, only share information needed to determine urgency and follow-up.
Need more evidence?
Request controlled access to the Assurance Pack.