Security & compliance

Audited, certified, traceable.

Vattenlarmet is operated by Partsnord Europe AB, a company continuously audited against international standards. Below is a summary of the frameworks and controls that govern our service.

Certifications & frameworks

International standards, independent audits

A summary of the primary certifications that apply to the platform.

SGS ISO/IEC 27001:2022

ISO/IEC 27001:2022

An information-security management system audited and certified by SGS, covering our entire platform and operations.

SGS ISO 9001:2015

ISO 9001:2015

A quality management system certified by SGS, ensuring predictable delivery and continuous improvement.

GDPR

GDPR

Personal data is processed under the EU General Data Protection Regulation with documented legal grounds and minimisation.

GLEIF LEI

LEI · GLEIF

Partsnord Europe AB is registered with the Global Legal Entity Identifier Foundation — verifiable at gleif.org.

Our security work

Four principles that guide every decision

Encryption

Transport encryption (TLS) on every channel. Data at rest encrypted with industry-standard ciphers.

Access control

Role-based access, principle of least privilege, and logging of every administrative action.

EU data centres

Hosted in Sweden and within the EU. No personal data leaves the Union without an approved legal basis.

Traceability

Every event is logged and can be followed — giving you and your insurer auditable evidence.

Additional frameworks

Standards we follow or are prepared for

EU data residency

All customer data is stored within the EU. No transfers to third countries without approved safeguards.

NIST SP 800-88

Secure erasure of data and equipment in line with NIST's global standard for media sanitisation.

NIST SP 800-53

Technical and organisational controls mapped to NIST's reference framework for information security.

ISO 22301

Business continuity and disaster-recovery plan so the service keeps running through disruption.

ISO 14001

Environmental management to an international standard. We measure and reduce impact across the supply chain.

Shared responsibility

We run the platform, you stay in control

Security is a partnership. We operate the platform under certified processes. You decide which data is recorded, who has access, and how the recipient lists are organised.

  • All communication is encrypted with TLS 1.2 or higher.
  • Administrative actions are logged, including who opened or closed the water.
  • Two-factor authentication available for administrator accounts.
  • Backup and continuity plan aligned with ISO 22301 principles.
  • Vulnerability monitoring of code and dependencies.
  • Strict vendor review before any integration.