Overview of cybersecurity in Easy8
Easy8 Group, demonstrates its commitment to the security of its products, processes, and overall ISMS in various ways. Read on to find resources relevant to your concerns.

Table of contents
Risks and regulatory pressure
Easy8 security at every level
Certified for ISO/IEC 27001:2022 and 27017
Full GDPR compliance
NIS2 readiness
Certified penetration testing
What makes Easy8 a secure choice for your business
Hosting options: On-premises or cloud
On-premises
Managed server
Private Cloud
Global Cloud
How secure is Easy AI
Azure AI
On-premises models
Business continuity
Staying ahead of threats
24/7 monitoring
Keeping the pace with security and AI
Easy8 keeps your data secure at every level
TL;DR
Easy8 embeds “security by design,” achieving ISO/IEC 27001:2022 and 27017 certifications, full GDPR compliance, and NIS2 readiness, while offering flexible hosting (on-premises, private, global, or EU Sovereign Cloud) with strong encryption, access control, monitoring, and continuity protocols.
Risks and regulatory pressure
Protecting sensitive data and ensuring business continuity is essential for any organisation managing complex projects or operating under strict regulations.
The challenges are compounded by growing regulatory demands such as GDPR and NIS 2. Organisations are expected to enforce secure data handling practices, implement technical and organisational safeguards, and offer clear transparency and user rights protections.
Easy8 security at every level
As we at Easy8 are highly aware of all the mentioned security threats, our software is developed with security by design—every line of code, deployment protocol, and update reflects our commitment to safeguarding your data and ensuring uninterrupted operations.
From initial architecture to deployment and maintenance, we implement industry-standard security practices, including role-based access control, data encryption, continuous vulnerability scanning, and secure coding principles.
Certified for ISO/IEC 27001:2022 and 27017
We at Easy8 are proud that our information security management system has been certified by DNV for the compliance with above mentioned standards.
Easy8 is ISO/IEC 27001:2022 and ISO/IEC 27017 certified by DNV. These international standards validate our robust Information Security Management System, ensuring secure handling of data across our organisation and product.
Additionally, we hold the ISO 9001 certificate, which confirms our commitment to quality management principles, including strong customer focus, process-based approach, and continuous improvement across all operations.

Full GDPR compliance
In the current climate of global digital uncertainty, we consider personal data protection as more than an obligatory phrase. Easy8 Group strictly follows the General Data Protection Regulation (EU) 2016/679 (GDPR) and upholds the highest standards of data protection and user privacy. Features include:
- Privacy by design and default
- Minimal data collection
- Transparent consent
- User permissions to view, edit or delete data
- Regular audits and strict access controls
- One-click anonymization and forgetting of PII
Easy8 operates with privacy by design and by default, ensuring that all personal data is collected, processed, and stored lawfully, transparently, and securely. We limit data collection to what is necessary, provide clear user consent mechanisms, and support users' rights to access, correct, or delete their personal data.
Easy8 incorporates technical and organizational safeguards to protect personal information against unauthorized access, alteration, or loss. We conduct regular audits, apply encryption where appropriate, and enforce strict access controls.
Additionally, we require all employees, contractors, and third-party service providers to adhere to GDPR-compliant data handling practices. Through continuous monitoring and improvement, we ensure that both our internal processes and our software remain in full compliance with GDPR requirements.

NIS2 ready
Easy8 product (including infrastructure, technologies and services) provides the components and mechanisms you need to achieve NIS2 compliance. These may include encrypted data at rest and in transit, granular access controls with 2FA, audit logs ready for SIEM integration, and regular vulnerability scanning and penetration testing.
In practice, with proper configuration and operational measures, the solution provides a solid basis to meet requirements within NIS2 regulation. This goes for cloud, on-premises and hybrid deployments.
Penetration testing
To validate the security of Easy8 in real-world conditions, we regularly undergo independent penetration testing performed by CREST accredited company Bulletproof against OWASP™ standards, among others. The most recent test was carried out in January 2026 (download letter of completion here).
All findings were manually verified, risk-rated, and documented, including clear remediation recommendations. Identified issues are addressed as part of our secure development lifecycle.
The penetration tests are performed by a CREST-accredited security provider, ensuring that:
- Testing follows recognized professional standards
- Methods are aligned with real-world attack techniques
- Results are independently validated and auditable
What makes Easy8 a secure choice for your business
Easy8 incorporates extensive technical measures:
- Data encryption: Encryption of data both at rest available. Data in transit uses industry-standard protocols TLS 1.2 and 1.3.
- Access control: Granular role-based access permissions; two-factor authentication (2FA) with password strenght definition; detection and prevention of suspicious login attempts; SSO, AD authentication integrated.
- Session management security: Secure handling of user sessions with automatic timeouts and protection against session hijacking or fixation.
- Rate limiting and brute force protection: Login attempts, and other critical endpoints are protected with rate limiting to prevent brute force attacks.
- Application security: Secure coding practices; code reviews with minimal two approvals; continuous scanning for vulnerabilities, SAST, DAST, IaC.
- Stringent OWASP Top 10 monitoring.
- Secure API access: All API endpoints require authenticated access, often using token-based systems like OAuth2 or API keys with scope restrictions.
- Logging and forensics: SIEM-friendly application logs of various types capture relevant security events (e.g., login attempts, privilege changes) for forensic and audit purposes.
- Regular security testing: Periodic penetration testing and external audits to identify and remediate vulnerabilities proactively. Consultations by our experts for your own VA findings.
- SBOM available on demand for verified customers
Hosting options: On-premises or cloud
Easy8 offers flexible hosting options to match your security, compliance, and operational needs:
- On-premises: Full data control, ideal for regulated industries.
- Managed server: Your infrastructure with cloud convenience—fully monitored and maintained by our team.
- Private cloud: Physically isolated infrastructure in over 20 global locations, including EU jurisdictions.
- Global cloud: Isolated containers with strict data separation in certified locations worldwide.
Let's take a closer look at the hosting options mentioned above.
On-premises
The mere fact that we continue to maintain and improve an on-premises solution underlines our commitment to the highest level of cybersecurity. We offer organisations full control over your data, infrastructure and access policies.
This setup ensures that sensitive information stays within your internal network, protected by your own security protocols and compliance standards. It’s the ideal choice for companies in highly regulated industries or those with strict data governance requirements, reinforcing our dedication to providing secure, reliable tools for work-, project-, IT service- and source code management.
Now powered by Docker, our on-premises deployment goes a step further—delighting server administrators with simplified updates and lower maintenance overhead. Docker delivers all required components in a guaranteed state, eliminating 90% of legacy manual update tasks, significantly reducing human error, and enabling more frequent security updates.

Managed server
For those seeking the security of on-premises with the comfort of cloud, we have this hybrid solution—your server in your environment, fully maintained and monitored by our expert team.
We take care of updates, backups, security patches and performance optimisation, so you can focus on managing your projects without the stress of technical upkeep. It’s a reliable and secure choice for companies that want the flexibility of a private environment, combined with the convenience of professional care.
Private Cloud
Choose any of the 20+ global locations, including 10+ in the sovereign EU territory with EU-based root ownership. Your data ownership is protected by the most strict regulations and never leaves the jurisdiction of EU. Other locations with analogic rules include Canada, Japan, Singapore, Australia and US.
Private Cloud offers full comfort of a cloud-based Easy8, but without sharing hardware and other resources with anyone else. You benefit from dedicated infrastructure, ensuring consistent performance, higher security and greater control over your environment.
It’s an ideal setup for teams that want cloud convenience but with the privacy and stability of a physically isolated system tailored to their needs.

Global Cloud
Again, you can choose any of the 20+ global locations, including 10+ in the sovereign EU territory with EU-based root ownership. Your data ownership is protected by the most strict regulations and never leaves the jurisdiction of EU in Global Cloud. Other locations include Canada, Japan, Singapore, Australia and US.
Each application including its database runs in an isolated container without any reach to its neighbours. This is as a safe Cloud architecture as you can get.
Security of Easy AI
Easy8 Group is certified for ISO 42001 - AI management system.
Easy8 application connects to LLMs to perform AI features. The most reliable in terms of quality are, based on our recent tests, GPT models. However, Easy AI can be connected as custom solution to on-premises variants, such as Mistral or Gemma.
Azure AI
Connecting to a GPT model via regular OpenAI API is the simplest option to configure, but not universally acceptable in terms of security. For EU-based (regulated) organizations, we offer connection to Azure AI hosted within EU Data Boundary.
- Data is stored and processed exclusively in the EU
- Operated by EU legal entities — separated from direct US control.
- GDPR, NIS2 & Schrems II + technical safeguards against CLOUD Act reach.
We use Azure AI as the default setup, due to high reliability of the models, and hardened EU-friendly regulatory compliance.
On-premises models
For the most stringent requirements, there remains the option to connect Easy AI to a self-hosted LLM. The advantage is obvious - all data fully under your control. It comes (currently) for the price of lower reliability of the model outputs, and high hardware and maintenance costs.
Business continuity
Staying ahead of threats
We take it most seriously—for us and for our clients. We know that uninterrupted deliveries are essential. That’s why we offer a robust disaster recovery SLA for resolution as low as 2 hours – so your work is never left on hold.
With 20 years of experience in the market, we’ve built reliability into everything we do. Unlike many providers, our cloud infrastructure is fully diversified, meaning you're never locked in with a single hyperscaler. And for those who prefer full control, our on-premises solution ensures perpetual use—granting you independence and long-term stability.
24/7 monitoring
Business continuity isn’t just about reacting—it’s about knowing before something happens. That’s why Easy8 Group has active monitoring across the full stack: Easy Cloud, hardware, critical systems, supporting services, internal processes, and even key suppliers.
We keep a constant eye on anomalies, performance shifts, and potential risks. This means we can respond early, often before our users even notice. Our approach allows you to rely on our platform, so you can focus on bringing value to your clients.
Keeping the pace with security and AI
Risks are evolving fast—with AI raising the complexity and quantum computing capacities on the horizon, the landscape has never been changing so rapidly.
Our own drive for innovation means we tackle new threats head-on, using the same advanced technologies to counter modern cyberattacks. We believe in fighting fire with fire—adapting our software, absorbing new knowledge, and anticipating the next moves. Every release of Easy8 contains some security enhancement.

Easy8 keeps your data secure at every level
Easy8 is fully secured at all levels, proven by ISO/IEC 27001:2022, ISO/IEC 27017, and GDPR compliance, along with advanced protection like data encryption, role-based access, and vulnerability monitoring.
From on-premises to global cloud hosting, every part of Easy8 is built and maintained to meet the highest standards of cybersecurity, business continuity, and regulatory readiness. The technological stack is continuously updated to address emerging threats, and we conduct regular audits and penetration tests to validate its resilience.
To learn more, scroll down to the FAQ for specific questions. Or download the comprehensive security summary (continuously updated) for a more complex overview.
Still missing something? Request a consultation!
Frequently asked questions
Can we use our Entra ID (formerly Azure Active Directory) for authentication? Do you have SSO?
Yes, Entra ID as the authentication method is a well-established solution. In addition, Easy8 provides general usability of SAML 2.0, OAuth 2.0, LDAP, covering practically the whole spectrum of modern secure authentication standards.
Is it possible to restrict access by IP address or network range?
Definitely, even with the Cloud solution, your application may be restricted only to whitelisted IP addresses and ranges.
In on-premises solution it goes without saying.
Are databases and file attachments encrypted at rest in Cloud environments?
The data centers storing your database and attachments are already physically protected to an extreme degree. Combined with the flexibility of our Cloud operations to ensure the highest uptime and user experience, data-at-rest encryption is disabled by default.
The solution is allowed as optional and we are happy to discuss the details with you.
Can we define custom roles and limit access to specific project objects or fields?
Easy8's role based access control (RBAC) is very granular. It separates read, edit, delete for every entity type containing potentially sensitive data. Roles are user defined and there is no limit to the possible combinations.
On a more detailed level, even specific fields are controled for visibility or editability based on user's role.
Is there a “read-only” user type or guest access mode for external collaborators?
Sure, thanks to the variability of permission controls, it is easy to configure a read-only role for your clients, partners, or other stakeholders. Naturally, the restricted projects and its data remain completely invisible unless you explicitly say otherwise.
Can we export logs to a SIEM or external log-management platform?
Absolutely, such solution is managed individually according to your processing software.
In on-premises solution it goes without saying.
How frequently are vulnerability scans conducted on cloud infrastructure? How quickly are critical security patches released and applied?
We scan our code, cloud and application multiple times per day. Patches of vulnerabilities with published exploits are applied within short days of public disclosure, if a vendor fix exists. If such a fix doesn't exist, we ensure substitutive measures to block the exploit vector.
Has Easy8 undergone any third-party security audits or code reviews?
Apart from official audits for ISO/IEC 27001, which also covers our application, we receive reports from our partners and clients. Any findings shared with us are analyzed, explained and remedied if necessary.
We use a number of external tools to conduct in-depth security assessments of our application and infrastructure.
Are Cloud customers hosted in multi-tenant or isolated environments?
Every production cloud application runs in an isolated environment based on Docker containers. Applications running on a common server have nothing except the hardware in common.
Private cloud solution separates your application physically, only your app and nothing else on a hardware server.
Is customer data ever accessed by support staff, and if so, how is access controlled and logged?
To provide fastest and most precise support, our (human) agents may choose to access some data necessary to solve your issue. Such access is allowed only to whitelisted personnel, and behind a MFA authentication (even if your application does not require it). Furthermore, any such access is reported by email to all of your application administrators. Any action performed by our agents is logged standardly as internal users, and the log is replicated to an independent storage to prevent any tampering.
This type of access for our support agents can be disabled on demand, while keeping in mind that it may significantly increase time to resolve certain support tickets.
Additionally, SIEM is used to detect any suspicious behaviour and an independent WAF and to automatically block it.
Are you NIS2 compliant?
Easy Software as an organization, including our its products follow the NIS2 Directive. We will not falsely promote any certificates, because, as you know, there is no authentic certification. There is only legislation which plainly must be respected.
We continuously develop our products, improve our services and adjust our processes to comply with all required regulations (including, but not limited to NIS2), as well as some voluntary ones (such as ISO 27001).
Our software has native built-in features to help you pass audits related to NIS2.
What is the NIS2?
NIS2 is the EU's Network and Information Security Directive 2, an updated cybersecurity regulation aimed at strengthening resilience across critical sectors. It expands on the original NIS Directive by broadening its scope and imposing stricter requirements on organizations.
How does Easy8 ensure the security of its cloud deployment?
Easy8 has undergone an independent penetration test performed on a standard production-like cloud deployment. The testing reflected a typical real-world configuration to ensure relevant and practical security coverage.
The assessment was conducted by Bulletproof, a CREST-accredited security company with extensive experience in application security testing. The engagement followed industry best practices and focused on identifying potential vulnerabilities affecting the application’s security posture.
As part of the assessment, the application was tested against OWASP™ standards, including common web application risks. Identified findings were reviewed and addressed to ensure an appropriate level of security for production use.
Does Easy8 undergo penetration testing?
Yes, we contract an independent CREST-accredited company test Easy8 against OWASP™ standards.




