Policy · Information security

Information security policy.

This policy describes how Appfront secures information: our own, that of our clients and that of the end users of the systems we build and manage. It applies to all our employees, contractors and partners and forms the framework within which we implement technical and organisational measures.

Policy typeInformation security
Version2026.05
Effective dateMay 2026
Next reviewMay 2027
OwnerFabian van Dijk
Contactsecurity@appfront.nl

Introduction and scope.

Appfront B.V. designs, builds and manages custom software for clients in sectors including finance, healthcare, industry, mobility and the (semi-)public sector. Much of the information we process on behalf of clients is sensitive: personal data, trade secrets, source data from business processes and integrations with core systems. Information security is therefore not an optional layer, but a prerequisite for our services.

This information security policy describes the principles we apply, the normative framework within which we work, the technical and organisational measures we take, how we handle client data and incidents, and what you can expect from us as a client, partner or reporter. The policy applies to all employees, freelancers, interns and contractors working on behalf of Appfront, and to all systems in which we process data: our own infrastructure, development environments, and client environments we manage, to the extent contractually agreed.

The policy is a living document. We update it whenever legislation, standards or our operations require it, with a fixed annual review as a minimum. Changes are published on this page, stating the version date. For clients and auditors who wish to cite this policy in vendor onboarding or a risk assessment, the version on this page at the time of consultation applies. Questions about how this policy applies to a specific engagement or audit can be sent to security@appfront.nl.

CIA triad
Confidentiality, integrity, availability
EU-only
Data residency in EU data centres
MFA
Mandatory on all company accounts
ISO 27001
Certification process in preparation

Our security principles.

Principle 01

The CIA triad as our foundation

Confidentiality, integrity and availability are the three pillars against which we weigh measures. Every decision about architecture, access or storage is explicitly assessed against all three criteria, not just one of them.

Principle 02

Least privilege and defence in depth

Employees, systems and applications receive only the permissions strictly necessary for their task. Security is built in layers, so that the failure of one layer does not immediately lead to an incident and attackers face multiple hurdles.

Principle 03

Privacy and secure by design

Privacy and security are considered from the very first design, not added afterwards. Default settings are restrictive: data fields are hidden by default, endpoints are not public by default, accounts have no permissions by default, and these are only extended when a use case justifies it.

Legal and normative framework.

01
Privacy

GDPR and the Dutch UAVG

The General Data Protection Regulation (EU 2016/679) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG) form the primary framework for processing personal data. We apply its principles of lawfulness, purpose limitation, data minimisation and transparency.

02
Cybersecurity

NIS2 and the Cyber Resilience Act

The NIS2 Directive (EU 2022/2555) and the Cyber Resilience Act (EU 2024/2847) set requirements for appropriate security measures, incident reporting and the security of digital products throughout their lifecycle. We build our process around these wherever they apply to us or our clients.

03
Sector standards

NEN 7510, BIO and DORA

For healthcare clients, we follow NEN 7510 for information security in healthcare. For government projects, we apply the Baseline Informatiebeveiliging Overheid (BIO). For financial clients, we align with the requirements of DORA (EU 2022/2554) on digital operational resilience.

04
Standards families

ISO/IEC 27001 and 27701

We work according to the structure of ISO/IEC 27001 (information security management) and align with ISO/IEC 27701 (privacy information management). Formal certification is in preparation; until then, we carry out internal audits based on the relevant controls.

Technical measures.

The technical controls below form the baseline of our security. For clients with additional requirements (for example, with ISO 27001-compliant software or NEN 7510 projects), we extend this according to contractual agreements.

Encryption

AES-256 or stronger for data at rest, TLS 1.3 for data in transit. No unencrypted transport.

Access management

SSO via Microsoft Entra, mandatory MFA, role-based access control on all business systems.

Logging and monitoring

Centralised logging with alerting on anomalous patterns. Logs are stored separately from the production environment.

Patch management

Regular review of updates, with priority for critical CVEs. Auto-update where it is safe to do so.

Backup and DR

Encrypted, geographically separated backups. A regularly tested restore procedure as part of disaster recovery.

Endpoint security

MDM on all work devices, full-disk encryption, anti-malware and remote wipe in case of loss or theft.

Network security

Segmentation between environments, firewall policies, VPN for remote access and zero trust where possible.

Secrets management

Credentials are kept in a vault, never in version control. Rotation on a fixed schedule and whenever staff change.

Vulnerability scanning

Continuous scanning of dependencies and container images (SCA and SAST) as part of the build pipeline.

Penetration testing

Regular externally conducted penetration tests on production systems and core applications, with follow-up in a fix backlog.

Secure development

Peer review on every change, automated checks in CI/CD and security issues as blocking criteria for releases.

Hardening

Production environments follow documented baselines, with minimal attack surfaces and default accounts disabled.

Organisational measures.

Organisation 01

Responsibility

Appfront's CEO, Fabian van Dijk, is ultimately responsible for information security and acts as security officer. He directs policy, risk analysis and incident handling, and is the central point of contact for clients and regulators.

Organisation 02

Awareness and staff

Every employee and contractor signs a confidentiality agreement on joining and regularly completes security and privacy awareness training. For sensitive projects or at a client's request, we carry out appropriate screening in line with the legal framework.

Organisation 03

Change and vendor management

Production changes go through peer review and, where necessary, a formal change procedure. Sub-processors are assessed for a demonstrable level of security (for example ISO 27001, SOC 2 Type II or an equivalent standard) before they are given access to personal or client data.

Working with client data.

Our client is and remains the data owner of the data processed on their behalf. Appfront acts as processor within the meaning of Article 28 GDPR, unless agreed otherwise in the contract. With every client for whom we process personal data, we conclude a data processing agreement (DPA) based on our standard text or, if the client prefers, on their own template after review of its content.

Data residency: data is processed within the European Economic Area. For this we use EU regions of established cloud providers (AWS, Azure, Google Cloud) and European hosting providers (such as Hetzner). Data transfers to third countries take place only on the basis of a valid transfer mechanism such as Standard Contractual Clauses (SCCs) and an additional risk analysis (Transfer Impact Assessment).

Client data is not used to train general-purpose AI models or resold to third parties. For AI applications we build on commission, additional agreements apply: which models, on which data, with what logging and what retention. Retention periods follow the contract and applicable legislation; when an engagement is dissolved or terminated, client data is deleted within ninety days by default, unless statutory retention obligations require otherwise or the client explicitly requests longer retention.

Incidents and data breach notifications.

01
Detection

Central reports and monitoring

Incidents are detected through monitoring, external reports or our CVD process. All reports come together at a single central address and are triaged immediately by the responsible security team.

02
Client notification

Prompt contact when clients are affected

When an incident affects, or could reasonably affect, a client, we notify that client confidentially as soon as possible, in line with the agreements in the data processing agreement and no later than the period stated there.

03
Obligation to notify the Dutch DPA

72-hour notification of a data breach

When an incident qualifies as a data breach that a processor must report to the controller, we comply with the deadline set out in Article 33 GDPR. The client then assesses whether notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and data subjects is required.

04
Disclosure

Coordinated vulnerability disclosure

For external vulnerability reports, we apply a separate CVD policy. It sets out how researchers can responsibly report a vulnerability, what they can expect from us and what safe harbour we offer.

Audit and assurance.

Internal

Annual internal audit

At least once per calendar year, we carry out an internal audit of how this policy and the associated controls are working. Findings are prioritised and followed up in an action plan, with ultimate responsibility resting with the security officer.

Client audit

Audit right in the DPA

Clients with whom we have concluded a data processing agreement have an audit right within the framework described there. On reasonable request, we provide evidence of controls, such as logs, dashboard extracts and architecture documentation, under a confidentiality agreement.

Certification

ISO 27001 in preparation

We are working towards formal certification under ISO/IEC 27001 and aligning with the privacy extension ISO/IEC 27701. Until certification is complete, we apply the same controls and, on request, transparently make the scope and status available.

Special categories of data.

Certain categories of data require additional safeguards. For engagements in which such data plays a role, for example with a GDPR compliance platform, we lay down the specific measures contractually.

Health data

Processing in accordance with GDPR Art. 9 and NEN 7510, with stricter access control and logging.

Biometric data

Processed only on an explicit contractual basis, with a deliberate choice for hashing or vectorisation where possible.

Criminal data

Only processed with a lawful basis and strict role separation; never by default in a production environment.

Children (under 16)

Processing only with an appropriate lawful basis, with parental or guardian consent where the GDPR requires it.

Financial data

For clients subject to DORA or PSD2, we align security, monitoring and reporting lines with that client's regime.

Government data

BIO-compliant measures, classification in line with government standards and strictly EU-only hosting where the assignment requires it.

AI training data

Client data is never used for training without explicit consent. Anonymisation and aggregation are the default.

Special category personal data

For all categories under GDPR Art. 9, the following applies: an enhanced lawfulness assessment, minimal access and strict logging.

Governance and review.

Governance 01

Policy owner

This policy has a single owner: Appfront's security officer. He is responsible for establishing, maintaining, communicating and enforcing the policy. Changes are recorded in a change log and are available to clients and auditors on request.

Governance 02

Review cycle

The policy is reviewed at least once a year, and additionally in the event of relevant changes in legislation and regulations, in our infrastructure, or after a significant incident. The next regular review is scheduled for May 2027. Earlier reviews are listed in the change log.

Governance 03

Risk management

Risks are recorded in a risk register and periodically reassessed based on changes in our portfolio, the threat landscape and the sub-processors involved. High-risk areas receive additional measures; residual risks are explicitly accepted by the security officer.

Frequently asked questions.

What exactly does this information security policy cover?
The policy covers how Appfront secures the information we manage ourselves (internal email traffic, source code, business administration) and the information we process on behalf of clients. It describes principles, normative frameworks, technical and organisational measures, the handling of client data, incident reporting and governance. It is a framework; specific agreements for each assignment are set out in the data processing agreement and the relevant service documents.
How often is the policy reviewed?
At least once a year. It is also reviewed in between in the event of relevant changes in legislation and regulations, in our technical infrastructure, in our client portfolio, or after a significant incident. The current version is 2026.05, effective May 2026; the next regular review is scheduled for May 2027. Versions remain visible to clients and auditors via this policy document.
Is Appfront ISO 27001 certified?
We are currently working towards formal certification under ISO/IEC 27001 and aligning with the ISO/IEC 27701 privacy extension. We apply the corresponding control structure and carry out internal audits, but at the time this policy was published we are not yet externally certified. For clients where certification is a precondition, we discuss the status of the process, the scope and the timeline in advance, and we connect to a certified sub-processor where that is a suitable solution.
Who is the security officer and how can they be reached?
Fabian van Dijk, CEO and ultimately responsible for information security, acts as security officer. For questions about the content of this policy, for incident reports or for a request for audit information, he can be reached at security@appfront.nl or directly at fabian.vandijk@appfront.nl. For urgent reports, you can write to both addresses at the same time.
How do I report a security incident or a vulnerability?
For vulnerabilities in our systems or in software we publish ourselves, please use our coordinated vulnerability disclosure policy. Send your report to security@appfront.nl. For incidents you identify as a customer in an environment we manage, use the reporting channel agreed in your data processing agreement; if in doubt, email the same inbox. We confirm receipt within five working days and escalate immediately where severity warrants it.
How does this policy relate to Article 28 of the GDPR?
In most client engagements, Appfront acts as a processor within the meaning of Article 28 of the GDPR. This policy describes the appropriate technical and organisational measures that a processor is required to ensure under that article. We record the specific arrangements for each client, including instructions, sub-processors, retention, audit rights and assistance with data subject rights, in a data processing agreement. This policy serves as an explanation and supporting evidence for that agreement, not a replacement for it.
What happens to our data after the contract ends?
By default, we delete client data within ninety days of the engagement being dissolved or ending, unless statutory retention obligations require otherwise or you explicitly request longer retention. On request, we will provide a verified export beforehand. Backups containing your organisation's data are deleted automatically within the retention period of those backups. A written confirmation of deletion is available on request for your own records.
Where is the data stored, and does it leave the EU?
By default, we process clients' personal and business data within the European Economic Area. We use EU regions of established cloud providers (such as AWS Frankfurt, Azure West Europe and Google Cloud Belgium/Netherlands) and European hosting providers where this suits the engagement. Where a transfer to a third country is necessary, for example for specific SaaS tools, we base it on a valid transfer mechanism and a Transfer Impact Assessment, and we inform you in advance.
Can I get a copy of this policy and the associated controls for our vendor onboarding?
Yes. On request, we provide a PDF version of this policy with a version stamp and, if desired, a completed supplier questionnaire and an overview of the key controls. For clients who want to base an independent audit on this documentation, we use a non-disclosure agreement to set out which additional documents we will share, such as architecture overviews, logs or pen test reports. Send your request, along with the context of the onboarding, to security@appfront.nl.

Questions about this policy?

For substantive questions, vendor onboarding, an audit request or an incident report, you can contact our security officer. We treat serious requests confidentially and confirm receipt within five working days.

Confirmation within 5 working days
Confidential handling
Westerdoksdijk 599, Amsterdam

Edit content