Security by design

Processes you can prove.

Sensitive steps follow configured roles. The system records who submitted, changed and approved a case. It cannot remove every risk, but it can enforce defined rules and leave an audit trail.

Our certifications
Crayon illustration of identity, dual approval, secure storage and an audit trail

DERS management systems

Two certifications. An extended scope of cloud controls.

The certification body is CQS / IQNET. The management-system certificates are valid until 19 May 2029 and cover software development, consulting and related service delivery.

Certified management systems

ISO/IEC 20000-1

IT service management and delivery

ISO/IEC 27001

Information security management

Controls included within the ISMS scope

ISO/IEC 27017

Cloud security controls within the ISMS scope

ISO/IEC 27018

Cloud privacy controls within the ISMS scope

The certificates are issued to DERS for the stated management areas. Their exact scope is defined in each certificate; this does not automatically certify every product or customer deployment separately.

From sign-in to audit

Each layer protects a different part of the process.

  1. A user signs in securely with a verified identity01

    Identity

    We connect through OpenID Connect, SAML 2.0 or LDAP. Depending on the environment, this can involve Keycloak, Microsoft Entra ID, Shibboleth/CAS and Czech public-sector NIA or CAAIS identities, with SSO, MFA or passkeys.

  2. Separate roles receive separate tasks and time-bound delegation02

    Permissions

    Least privilege, role separation and time-bound delegation.

  3. Two authorised people independently approve a protected step03

    Decisions

    Mandatory controls, limits and four-eyes approval for protected operations.

  4. Decision, time and change remain connected in the audit record04

    Audit

    Traceable identity, time, change, decision and integration hand-off.

  5. A key, token and certificate are kept in a secure vault05

    Secrets

    In supported architectures, HashiCorp Vault manages tokens, certificates and credentials outside configuration files.

  6. A signed document moves into managed storage and records management06

    Documents

    Signatures, seals, trusted storage and certified records-management integration.

Two authorised people approve a sensitive step

Four eyes in practice

The rule is not only in a policy. The system stops the case.

The operation approver and budget controller have separate roles. Delegation is scoped by role and time. Decisions and evidence remain in the audit trail.

How internal control works
NIS2 · ISO/IEC 27001

The solution can support access control, approval workflows, segregation of duties, audit trails and evidence for selected controls. Deployment alone does not guarantee NIS2 compliance or customer certification; this depends on regulatory scope, configuration and organisation-wide processes.

I want to discuss solution security