GDPR · EU AI Act · DORA · ISO/IEC 27001
Security & Trust

Security isn’t a feature we added. It’s where we started.

Emblema was forged in defense, where keeping data inside the building was the only option. That origin shaped every layer of the platform: sovereign by deployment, encrypted by default, auditable by design.

Your data never leaves your network — not even to us.

Standards that matter

Aligned with the frameworks that count.

Emblema’s security and privacy program is engineered to align with the European and international standards of the field.

  • ISO/IEC 27001:2022
  • ISO/IEC 27701:2019
  • ISO/IEC 27002:2022
  • NIST SP 800-63B
  • NIST SP 800-61
  • AgID Minimum Measures
  • EU AI Act
  • GDPR
  • DORA
  • NIS2

Alignment, not certification: framework references indicate engineered conformance until the relevant certificate is issued by an accredited body.

How we protect you

Eight layers, one logic: provable.

The same architecture that makes Emblema private makes it provable. Every control below is part of the product — not bolted on after.

01

Data sovereignty & residency

Your data stays inside your walls — by architecture, not by promise.

  • Fully on-premise and air-gap-capable: runs completely disconnected from the public internet.
  • No data and no inference ever leave your network, even to Emblema.
  • Single-node or multi-node deployment, entirely on hardware you control.
  • A sovereign deployment option for Public Administration and data-residency-bound sectors.
02

Encryption everywhere

Modern, authenticated cryptography at rest and in transit, with no weak legacy algorithms.

  • At rest: AES-256-GCM across all data stores and backups.
  • In transit: TLS 1.2+ (1.3 preferred) with forward-secret cipher suites; HSTS enabled.
  • Centrally managed TLS certificates at the edge gateway.
  • No MD5/SHA-1; no plaintext storage of secrets or credentials.
03

Identity & access control

Least privilege, enforced and recorded.

  • Keycloak central identity provider with Single Sign-On.
  • Multi-factor authentication for privileged and remote access.
  • Role- and attribute-based access control (RBAC + ABAC) down to entity and record level.
  • Periodic access recertification and automatic disabling of dormant accounts.
04

Auditability & monitoring

Every action is recorded — searchable now, immutable for the long term.

  • Dual-sink audit trail: searchable structured logs plus per-event WORM-ready records (S3 Object Lock).
  • Privacy-by-design logging: the immutable store keeps only a salted hash of the user ID and a truncated IP.
  • Security logs retained 6 months online, up to 24 months in archive.
  • Centralized monitoring with detection and alerting on anomalous events.
05

AI & ML security

The model layer gets its own threat model.

  • Prompt-injection and jailbreak mitigations via input/output guardrails.
  • Data lineage across training, fine-tuning, and RAG sources.
  • Embeddings derived from personal content are treated as personal data.
  • Human oversight for automated decisions (GDPR Art. 22); AI-generated content is labeled.
06

Incident response

A 24/7 plan, severity-based SLAs, and a clear way to report.

  • Standing Incident Response Team activated 24/7, with severity-based containment SLAs.
  • GDPR breach notification within 72 hours of becoming aware.
  • Responsible disclosure via security.txt and a dedicated security contact.
  • NIS2 notification readiness; blameless post-mortems; protected whistleblowing channel.
07

Resilience & continuity

Built to recover, and tested on the assumption it will have to.

  • Business Continuity and Disaster Recovery plans with defined objectives (RTO/RPO targets).
  • 3-2-1 backup strategy (3 copies, 2 media, 1 off-site), encrypted.
  • Restore tests at least quarterly; DR drills annually.
  • Authenticated time sync and redundancy for critical services.
08

Privacy by design

GDPR is the default setting, not a configuration.

  • Privacy by design & by default: data minimization, restrictive defaults, pseudonymization.
  • DPIA for high-risk processing; documented retention limits.
  • Data-subject rights honored within 30 days (extendable per GDPR).
  • DPAs (Art. 28) with every sub-processor; TIA + SCC for any extra-EU transfer.
In short

The guarantees, in numbers.

0
data or inference leaving your network
AES-256
GCM encryption at rest, on data and backups
TLS 1.3
in transit, with forward-secret ciphers
72h
breach notification under GDPR
Responsible disclosure

Found a security issue?

We welcome responsible disclosure. We acknowledge reports promptly and will keep you informed through remediation.

The principle

The same architecture that makes us private makes us provable.

A self-hosted, deterministic, inspectable platform emits the encryption boundary, the audit trail, the access records, and the oversight controls regulators ask for — as a byproduct of using it.

Security and compliance are an output of the deterministic graph — not extra work bolted on after.

This content describes Emblema’s security and data-protection program for informational purposes; it is not a contractual warranty and not legal advice. Some items reflect policy commitments and roadmap targets; figures are objectives unless independently verified.