Security and trust

We sell security, so the way we run our own is part of the product. Here is how it works.

Where your data lives

Customer data is processed in Italian datacentres. Nothing is shipped to a third country for processing, and no customer data is shared with third parties for their own purposes.

The scanning engines run on infrastructure we operate ourselves. Findings, reports and telemetry stay inside that perimeter.

How we build the products

Data minimisation

We store the findings, not your content. Where a product processes reports from third parties, only the aggregated result is kept — never message bodies.

Retention limits

Every dataset has a retention window tied to your plan, and data past that window is deleted automatically rather than kept indefinitely.

Tenant separation

Every record is bound to a customer identifier, and every query is scoped by it. Access control fails closed: no entitlement means no data, not a disabled button.

Secrets handling

Credentials live outside the source code, in files readable only by the service that needs them, and are never passed on a command line.

Audit trail

Configuration changes and engine lifecycle events are written to an append-only log with the actor and a timestamp, so what happened stays reconstructable.

Nothing intrusive by default

Active tests only ever run against assets you own, and only where you have authorised them in writing. Until then, they run in simulation.

Certifications and standards

Fidem S.r.l. is ISO 27001 and ISO 9001 certified. Products are designed against the following frameworks, and each module ships with its own dated compliance mapping:

ISO 27001 Information Security
ISO 9001 Quality Management
GDPR EU Compliant
Made in EU Italian Data Residency

Products are additionally built against ISO/IEC 27017 and 27018 (cloud services and personal data in the cloud), the CSA Cloud Controls Matrix behind CSA STAR, the risk-management measures of NIS2 Article 21, and the NIST Cybersecurity Framework 2.0 with the Secure Software Development Framework for the development lifecycle.

Helping you meet NIS2

If NIS2 applies to you, or to a customer who is asking you to prove your posture, the reports our products generate are built to be handed over: severity, evidence and the remediation step for each finding, exportable as PDF for an auditor, an insurer or a client.

Continuous scanning covers the risk-analysis and vulnerability-handling side; the email identity products cover impersonation of your domain toward your own supply chain.

Questions about our security?

Security questionnaires, DPAs and audit requests are welcome — send them over and we will answer them properly.

Get in touch