Snapshot 35887
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Because we care... PSOhub Security & Trust Center Built for peace of mind — powered by Mendix & AWS At PSOhub, data security, privacy, and compliance are core to how we design, build, and operate our platform. We deliver our software exclusively as a cloud-based SaaS solution, built on the Mendix low-code platform, hosted securely on Amazon Web Services (AWS). Our Security Foundation PSOhub’s architecture inherits the world-class security standards of our technology partners: Infrastructure Layer Provider Key Certifications & Controls - Multi-AZ redundancy - DDoS protection - Encrypted storage (RDS & S3) - Continuous monitoring Application Platform Layer Provider Key Certifications & Controls - Annual third-party audits - Continuous ISMS monitoring AI Layer (Optional) Key Certifications & Controls - GDPR-compliant data handling - No model training on PSOhub data - Customers must sign the OpenAI Data Use Agreement before activation. Application & Data Management Provider Key Certifications & Controls - Role-based access control - Data encryption - Incident response plan - GDPR/ Data Act-compliant data export & deletion procedures. Shared Responsibility Model Security is a shared effort between PSOhub and our technology providers. AWS AWS secures the physical data centers, networking, and storage infrastructure (“security of the cloud”). Mendix Mendix secures the application platform, including authentication, encryption, and runtime management PSOhub PSOhub secures how the software is built, configured, and operated (“security in the cloud”). This layered approach ensures enterprise-grade protection while allowing flexibility and transparency for our customers. Data Encryption & Protection Encryption in transit All data between users and PSOhub runs through HTTPS/TLS 1.2+ (end-to-end encrypted). Encryption at rest All application and file data stored in AWS RDS and S3 is AES-256 encrypted by default. Optional end-to-end encryption modules Mendix offers additional AES encryption modules for sensitive data sets. Access control Fine-grained role-based permissions down to entity and field level. Defense in depth Multi-layer security model combining infrastructure, application, and governance controls. Compliance & Privacy PSOhub adheres to European and international standards for privacy and cybersecurity: GDPR / AVG Full compliance as Data Controller. Mendix acts as Data Processor; DPA available. EU Data Act (2025) Data portability, transparent export, and cloud exit rights built into PSOhub. NIS2 Proactive alignment with security governance, incident response, and risk management principles. HIPAA / NEN 7510 (via Mendix) Ensures compatibility for healthcare-related use cases. ISO 27001 Readiness (PSOhub) – internal security roadmap towards certification in 2026. Continuous Auditing & Monitoring Annual third-party audits Mendix and AWS undergo yearly SOC 1/2, ISO, and PCI DSS assessments. 24/7 platform monitoring Automated detection of vulnerabilities and anomalies. Security incident management Documented process to notify affected customers within 24 hours. Penetration testing Regular external and internal tests to identify and resolve vulnerabilities. ISO 27001 readiness (PSOhub) Internal security roadmap towards certification in 2026. Data Residency & Sovereignty Data is hosted in EU-based AWS data centers. Mendix and AWS follow strict data-location guarantees — data is never moved outside the selected region without explicit consent. Sub-Processors & Transparency We maintain Data Processing Agreements (DPAs) with all our key partners: AWS Infrastructure & storage provider (Dublin/ Frankfurt). Mendix Application platform provider (Netherlands). A current list of sub-processors and their regions is available on request. Summary PSOhub delivers a secure, reliable, and transparent SaaS platform — leveraging the combined compliance of AWS, Mendix, and OpenAI, while maintaining strict control over data access, encryption, and privacy. With continuous auditing, ISO-aligned processes, and clear customer agreements, we ensure your business data remains protected — always.