Audited, certified, traceable.
Vattenlarmet is operated by Partsnord Europe AB, a company continuously audited against international standards. Below is a summary of the frameworks and controls that govern our service.
Certifications & frameworks
International standards, independent audits
A summary of the primary certifications that apply to the platform.

ISO/IEC 27001:2022
An information-security management system audited and certified by SGS, covering our entire platform and operations.

ISO 9001:2015
A quality management system certified by SGS, ensuring predictable delivery and continuous improvement.

GDPR
Personal data is processed under the EU General Data Protection Regulation with documented legal grounds and minimisation.
LEI · GLEIF
Partsnord Europe AB is registered with the Global Legal Entity Identifier Foundation — verifiable at gleif.org.
Our security work
Four principles that guide every decision
Encryption
Transport encryption (TLS) on every channel. Data at rest encrypted with industry-standard ciphers.
Access control
Role-based access, principle of least privilege, and logging of every administrative action.
EU data centres
Hosted in Sweden and within the EU. No personal data leaves the Union without an approved legal basis.
Traceability
Every event is logged and can be followed — giving you and your insurer auditable evidence.
Additional frameworks
Standards we follow or are prepared for
EU data residency
All customer data is stored within the EU. No transfers to third countries without approved safeguards.
NIST SP 800-88
Secure erasure of data and equipment in line with NIST's global standard for media sanitisation.
NIST SP 800-53
Technical and organisational controls mapped to NIST's reference framework for information security.
ISO 22301
Business continuity and disaster-recovery plan so the service keeps running through disruption.
ISO 14001
Environmental management to an international standard. We measure and reduce impact across the supply chain.
Shared responsibility
We run the platform, you stay in control
Security is a partnership. We operate the platform under certified processes. You decide which data is recorded, who has access, and how the recipient lists are organised.
- All communication is encrypted with TLS 1.2 or higher.
- Administrative actions are logged, including who opened or closed the water.
- Two-factor authentication available for administrator accounts.
- Backup and continuity plan aligned with ISO 22301 principles.
- Vulnerability monitoring of code and dependencies.
- Strict vendor review before any integration.
