ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Trust Center

Security, compliance & privacy

At ON2IT, we understand the importance of security, compliance, and privacy in today’s digital world. It is not just a component of our services, it is at the heart of everything we do.

Independent audits. ISO and SOC 2 certifications. 100+ supported frameworks. The receipts, not the claims.

View certifications Responsible disclosure
Three pillars

By design, not by paperwork

Three commitments shape how we build and run every service we deliver: securing what we host, complying with what auditors require, and protecting the personal data that passes through us.

Security

Top priority, every day

As a global cybersecurity service provider, securing our clients’ data and environments has always been our top priority. Our own house first.

Compliance

Meets or exceeds the bar

We are committed to ensuring that our services consistently meet or exceed industry certifications and compliance requirements, in every country we operate in.

Privacy

European-grade by default

We safeguard personal data by adhering to stringent privacy standards and data protection regulations. We collect the minimum, keep it the shortest time, and tell you what we have.

Independent audits

Certifications & assurances

We regularly evaluate the quality of our services and the effectiveness of our controls through independent audits. Request the certificate or assurance you need below.

Certified

ISO 9001

Quality management system, externally audited and renewed annually.

Request certificate →

Certified

ISO 14001

Environmental management system, covering our offices and operations.

Request certificate →

Certified

ISO 27001

Information security management system, the global benchmark for managing security risk.

Request certificate →

Assurance

SOC 2 Type II

Independent attestation of our controls for security, availability and confidentiality over time.

Request assurance →

Supported

Cybersecurity Made in Europe

Recognised by Digital SME as a European cybersecurity provider with a verified European footprint.

View listing →

Compliance support

100+ frameworks, one platform

We serve global clients across many industries that encounter diverse industry frameworks, standards, and regulatory requirements. Our AUXO™ platform provides a curated repository of measures for Zero Trust architecture implementation and monitoring, aligned with the frameworks that matter to your auditor.

Global

CIS, ISO, SOC 2, NIST

CIS Controls, ISO 27001, SOC 2 Type II, NIST 800-171, NIST 800-53. The international baseline most auditors will start with.

Industry

PCI DSS, SWIFT CSCF, NEN 7510

Financial services, payments, and healthcare-specific frameworks, including SWIFT CSCF and NEN 7510 for the Dutch healthcare sector.

Regulatory

GDPR, FedRAMP, TISAX

EU privacy law, US federal cloud, German automotive supply-chain security, plus MITRE ATT&CK, COBIT, Cyber Essentials, BIO, Good Practice, and 100+ more.

Open by design

Responsible disclosure

We maintain a responsible disclosure program to encourage security researchers to disclose discovered vulnerabilities in a responsible manner.

View the program

Found a vulnerability in our systems? We’d like to hear from you. Our program defines the scope (*.on2it.net, *.on2it.nl), the rules, and the rewards.

Reports go to responsibledisclosure@on2it.net. We rate every disclosure and pay rewards via the Tremendous platform.

Specific framework?

Get in touch with our compliance team

If you need a certificate, an assurance letter, evidence for an audit, or a conversation about a framework we haven’t listed, reach out and we’ll connect you to the right person.

Contact us Responsible disclosure