Compliance Infrastructure You Can Rely On
format, with the right legal standing, the platform underneath it cannot be an
afterthought. At Semansys, security and operational integrity are not features we added.

The foundation we built on
Our customers include enterprises, regulators, and software providers operating in some of the most demanding compliance environments in Europe. They trust us because we have spent twenty-five years earning that trust, quietly, methodically, and without shortcuts.
Our Compliance and Certifications
XBRL International Certified
GDPR ready
Peppol Access Point Certified Provider
SOC2 Type II
ISO 9001:2015
ISO 27001:2022
ISO 20000-1:2018
ISO 22301:2019
ISO 42001:2026
ISO 27701:2025
NIS2 compliant
How we protect your data
Data residency
Encryption in transit and at rest
Non-repudiation
Access control
Incident management

Our commitment
We understand that trust is not granted on the basis of a certificate. It is built through consistent delivery, transparent communication, and the willingness to be held accountable.
We publish our certifications. We answer security questionnaires directly and thoroughly. We engage openly with procurement and infosec teams, because we know that the organisations that ask the hardest questions are usually the ones that become the most durable partners.
If you have specific security or compliance requirements you would like to discuss, our team is ready to engage.
Frequently asked questions
Semansys applies security, access-control, monitoring, incident-management, continuity, and data-protection controls appropriate for compliance-critical infrastructure.
The platform operates within an ISO 27001-certified information-security framework and is supported by independently audited controls.
Semansys platform infrastructure and customer data are hosted within the European Union.
EU hosting supports European data-residency requirements and helps organisations maintain clear control over where their regulated business information is processed.
Yes. The Semansys platform is designed and operated in alignment with the EU General Data Protection Regulation.
Data-processing roles, retention, access controls, deletion, and subprocessors are governed through the applicable service and data-processing agreements.
SOC2 Type II is an independent attestation concerning the design and operating effectiveness of controls over a defined review period.
It provides customers with assurance that relevant controls are not only appropriately designed but also operate effectively over time.
A SOC 3 report is a general-use assurance report based on the applicable Trust Services Criteria. It can be shared publicly and contains less detail about the service auditor’s testing than a restricted-use SOC 2 report.
Yes. For supported platform processes, Semansys records relevant processing and audit events, which may include document identifiers, timestamps, validation outcomes, transmission events, statuses and external system responses. Availability and retention depend on the selected service, configuration and contractual retention period.
This supports operational investigation, reconciliation, customer service and compliance review.
Yes. Business continuity and operational resilience are integral to the Semansys control framework.
Semansys is certified to ISO 22301, the international standard for business continuity management systems.