Trust & security
Last updated: 24 September 2026
Security and data protection are core to what Entit does — we design them into our clients' systems, and we run our own the same way. This page describes the principles we work to. We aim for the spirit of recognised frameworks; where we are not formally certified, we say so plainly.
European data sovereignty
This website and its data stay within the EU/EEA. It is hosted on Cleura, a European, EU-owned cloud, and we do not send data to third countries. Fonts and analytics are self-hosted, so no visitor data leaks to third-party CDNs. See our privacy policy for the full data-handling detail.
How we secure this service
- Encryption in transit. HTTPS everywhere, HSTS, and modern TLS.
- Hardened application. A strict Content-Security-Policy, anti-CSRF protection, secure cookies, and standard security response headers.
- Least privilege. Access to systems and data is limited to what each role needs.
- Secure delivery. Changes go through review and automated build checks; we keep dependencies current and watch for known vulnerabilities.
- Resilience. Infrastructure runs with redundancy and controlled, zero-downtime rollouts.
- Supplier diligence. We keep the number of sub-processors small and choose EU-based providers with data-protection agreements in place.
Standards we align to
We design and operate to the principles behind ISO/IEC 27001 (information-security management), the NIST Cybersecurity Framework, and NIS2, and we build client solutions to be GDPR-compliant by design.
To be clear about what that means: Entit is not currently certified to ISO 27001, nor do we hold a SOC 2 report. These are organisation-wide certifications awarded by independent auditors; we align our practices to their controls but do not claim the certifications until we hold them. GDPR is a legal obligation we do meet, and it governs how this site handles personal data.
Reporting a security issue
Found a vulnerability? Please tell us at info@entit.se. Our machine-readable contact details are published at /.well-known/security.txt (RFC 9116). We appreciate responsible disclosure and will work with you on any valid finding.