Security, compliance & privacy
At ON2IT, we understand the importance of security, compliance, and privacy in today’s digital world. It is not just a component of our services, it is at the heart of everything we do.
Independent audits. ISO and SOC 2 certifications. 100+ supported frameworks. The receipts, not the claims.
By design, not by paperwork
Three commitments shape how we build and run every service we deliver: securing what we host, complying with what auditors require, and protecting the personal data that passes through us.
Top priority, every day
As a global cybersecurity service provider, securing our clients’ data and environments has always been our top priority. Our own house first.
Meets or exceeds the bar
We are committed to ensuring that our services consistently meet or exceed industry certifications and compliance requirements, in every country we operate in.
European-grade by default
We safeguard personal data by adhering to stringent privacy standards and data protection regulations. We collect the minimum, keep it the shortest time, and tell you what we have.
Certifications & assurances
We regularly evaluate the quality of our services and the effectiveness of our controls through independent audits. Request the certificate or assurance you need below.
ISO 9001
Quality management system, externally audited and renewed annually.
Request certificate →
ISO 14001
Environmental management system, covering our offices and operations.
Request certificate →
ISO 27001
Information security management system, the global benchmark for managing security risk.
Request certificate →
SOC 2 Type II
Independent attestation of our controls for security, availability and confidentiality over time.
Request assurance →
Cybersecurity Made in Europe
Recognised by Digital SME as a European cybersecurity provider with a verified European footprint.
View listing →
100+ frameworks, one platform
We serve global clients across many industries that encounter diverse industry frameworks, standards, and regulatory requirements. Our AUXO™ platform provides a curated repository of measures for Zero Trust architecture implementation and monitoring, aligned with the frameworks that matter to your auditor.
CIS, ISO, SOC 2, NIST
CIS Controls, ISO 27001, SOC 2 Type II, NIST 800-171, NIST 800-53. The international baseline most auditors will start with.
PCI DSS, SWIFT CSCF, NEN 7510
Financial services, payments, and healthcare-specific frameworks, including SWIFT CSCF and NEN 7510 for the Dutch healthcare sector.
GDPR, FedRAMP, TISAX
EU privacy law, US federal cloud, German automotive supply-chain security, plus MITRE ATT&CK, COBIT, Cyber Essentials, BIO, Good Practice, and 100+ more.
Responsible disclosure
We maintain a responsible disclosure program to encourage security researchers to disclose discovered vulnerabilities in a responsible manner.
View the programFound a vulnerability in our systems? We’d like to hear from you. Our program defines the scope (*.on2it.net, *.on2it.nl), the rules, and the rewards.
Reports go to responsibledisclosure@on2it.net. We rate every disclosure and pay rewards via the Tremendous platform.
Get in touch with our compliance team
If you need a certificate, an assurance letter, evidence for an audit, or a conversation about a framework we haven’t listed, reach out and we’ll connect you to the right person.