Trust centre

Security, compliance, and trust โ€” not a box to tick.

When you work with DevForces, your data, your clients' data, and the systems we build are held to the highest standard. This trust centre gives you full visibility into our security posture, certifications, and how we handle every piece of information we are given access to.

Compliance

Our current posture and roadmap.

We are transparent about where we are, what is complete, and what is in progress. If you need a certification that is not yet in place, we can discuss the timeline and evidence available today.

โœ… Compliant

GDPR

Full compliance. DPA template available. Data processed in EU by default. No third-country transfer without consent.

Target: Ongoing
๐ŸŸก In progress

ISO 27001

Information security management system. Covers access control, incident response, and data handling across all engagements.

Target: 2027
โœ… Assessed

EU AI Act

All AI components risk-assessed against the Act's tiered classification. No prohibited AI practices used in any engagement.

Target: Aug 2026
โœ… Complete

IWAY (IKEA)

IKEA supplier code of conduct. Ethical sourcing, employment practices, anti-bribery. Self-assessment complete.

Target: Jul 2026
๐Ÿ“‹ Planned

SOC 2 Type II

System and Organisation Controls. Trust service criteria covering security, availability, and confidentiality.

Target: 2028
โœ… Active

MDR / GDPR Health

Medical Device Regulation compliance for clinical data handling on healthcare client engagements.

Target: Ongoing

Compliance status on this page is updated manually. We are evaluating integration with a compliance automation tool (e.g., Vanta) to publish real-time certificate status in the future.

Security controls

How we protect what you trust us with.

Data residency

All client data processed and stored within the EU. No transfer to third countries without explicit DPA amendment.

Access control

Role-based access. Engineers access only the systems required for their engagement. Audit logs retained 12 months minimum.

Confidentiality

NDAs signed before discovery. Every engineer is bound by individual confidentiality obligations referenced in their employment contract.

Incident response

Data breach notification to client within 48 hours of identification. Dedicated security contact for active engagements.

FAQ

Questions procurement and legal teams ask.

Is DevForces GDPR compliant?

Yes. We are fully GDPR compliant. A Data Processing Agreement template is available, and client data is processed in the EU by default. No third-country transfer occurs without explicit consent and a DPA amendment.

Does DevForces hold ISO 27001?

ISO 27001 is currently in progress. Our information security management system covers access control, incident response, and data handling across all engagements, with certification targeted for 2027.

Where is client data stored?

All client data is processed and stored within the EU. No transfer to third countries occurs without an explicit DPA amendment.

What is DevForces' data breach notification process?

DevForces notifies clients of any identified data breach within 48 hours. A dedicated security contact is assigned to every active engagement.

How do you assess AI systems against the EU AI Act?

Every AI component is risk-assessed against the EU AI Act's tiered classification. We do not use prohibited AI practices, and we document risk levels for clients in regulated sectors.

Need a security questionnaire or DPA?

We respond to procurement and legal reviews within one business day.

Contact security