Company & security

Security that asks twice

MFA, step-up and audit that meet municipal requirements — without slowing down the everyday.

Step-up flow
Step-up · delete pupil data
MFA verified (TOTP)
Reason logged
Leadership notified
Sent
Deletion reversible for 7 days
ℹ︎

TOTP MFA

Two-factor authentication with Google Authenticator, 1Password or Microsoft Authenticator — mandatory for leadership.

Step-up on sensitive actions

Deleting pupils, exporting identifiers and changing grades requires a fresh MFA — not just login.

Uni-Login and SSO

Integrates with municipal IdP and SSO — MFA is inherited automatically from there.

Suspicious activity

Login from a new country, bulk exports or out-of-hours access is flagged to leadership.

Audit trail

Every data access is logged with role, time and action — ready for DPIA and audit.

Pseudonymisation for AI

When AI analyses pupil text, names and identifiers are stripped first. The result is mapped back locally.

Built for municipalities

  • Architecture aligned to the ISO 27001 control framework (the certification belongs to our hosting provider), with encryption at rest and in transit
  • Continuous automated security and dependency scanning via Aikido Security
  • Data hosted in the EU — primary Falkenstein (DE), replica Nuremberg (DE), encrypted S3 backup in Hetzner Object Storage, Helsinki (FI) — 30-day retention
  • Separated identifier storage with its own encryption key
  • Pseudonymisation before AI analysis
  • DPIA template ready for municipal legal teams
  • Configurable retention periods per data type

Safe to show the municipality

Our DPIA, data map and contracts are ready — no extra work for the school.

Download DPIA