Trust & Security
Security and compliance, by design.
Our clients operate in sectors where data is complex, regulation is real and systems cannot fail. Security and compliance are not features we add at the end — they are constraints we design around from the very first line of architecture.
Data protection
- GDPR-aligned handling of personal and sensitive data, with privacy considered from the first design decision.
- Data minimisation — we collect, process and retain only what a system genuinely needs.
- Encryption in transit and at rest across our platforms and pipelines.
- Data residency and sovereignty options so information stays within the jurisdictions you require.
Access & identity
- Role-based and attribute-based access control (RBAC/ABAC) scoped to real responsibilities.
- Single sign-on (SSO) integration with your existing identity provider.
- Least-privilege by default — access is granted narrowly and reviewed regularly.
- Full audit trails recording who accessed what, when and why.
Compliance & governance
- Audit-ready data provenance and lineage, so every figure can be traced to its source.
- Support for regulatory reporting against GDPR and sector-specific frameworks (for example EASA and ICAO in aviation).
- Policy-compliant architecture — controls expressed in the system, not bolted on afterwards.
- Governance tooling that helps your teams demonstrate compliance, not just claim it.
Operational security
- A secure software development lifecycle (SDLC) with security gates throughout.
- Mandatory peer code review and automated dependency management to catch issues early.
- Continuous monitoring, logging and alerting across deployed systems.
- Defined incident response processes so problems are contained, communicated and resolved.
Sub-processors & hosting
- Deployments can run on sovereign or EU-based infrastructure where data locality matters.
- On-premise and air-gapped options are available for the most sensitive environments.
- Sub-processors are kept to a minimum and disclosed, with hosting matched to each client's regulatory needs.
Responsible disclosure
If you believe you have found a security vulnerability in any of our systems, we want to hear from you. Please report it privately so we can investigate and remediate before any public disclosure.
Contact our security team at security@infimum.gr.
This page describes our security and compliance practices; it is not a formal attestation or certification. Specific certifications, attestations and supporting documentation are available on request as part of a due diligence process.
Running due diligence?
We are happy to complete security questionnaires, share documentation and walk your team through how we would secure your systems.