Koivu Solutions is part of the PubliX Group — the same team, strengthened for Nordic growth.

Trust, security and compliance

Trust should be inspectable.

Customers should not have to rely on vague promises. Koivu documents how information security, privacy, EU-region data operations, resilience and secure development are managed, and provides supporting evidence through the Sotender Trust Center and controlled document requests.

Assurance at a glance

Evidence for procurement and review.

  • ISO/IEC 27001:2022-certified ISMS
  • EU-region application data and backups
  • Independent security testing
  • Controlled evidence requests under NDA

A clear starting point for procurement, IT and security teams.

ISO/IEC 27001:2022 certified

Koivu operates a certified information security management system with documented policies, risk management, audits and management review.

EU-region cloud operations

Sotender runs on Google Cloud. Application data and backups remain in the EU region.

Identity and access

Sotender supports SSO through Microsoft and Google, with access controls managed as part of the service.

Independent testing

Application security is reviewed through external security testing and independent audit activity.

GDPR practices

Koivu maintains processor documentation, data processing agreements, records of processing, technical and organisational measures, privacy risk management and DPIA support.

Resilience

Documented incident response, backups, recovery testing, business-impact analysis and business continuity practices support service resilience.

Management system

Security is managed as an operating discipline.

Koivu’s ISO/IEC 27001:2022 information security management system covers organisational, people, physical and technological controls. Internal audits, corrective actions and management reviews are used to maintain and improve the system.

Risk management

Security and privacy risks are identified, assessed, treated and reviewed.

Secure development

Development policies, code review and independent penetration testing support the software lifecycle.

Incident response

Defined processes cover detection, containment, communication, recovery and post-incident review.

Business continuity

Backups, recovery testing, EU-region storage and business-impact analysis support continuity planning.

Data protection

Clear roles and practical GDPR support.

For tenant data, the customer organization normally acts as controller and Koivu acts as processor under written instructions and a data processing agreement. Koivu also maintains the documentation and workflows needed to support customer obligations.

Read Koivu’s approved Privacy Policy

Available privacy support

  • Data processing agreement available
  • Records of processing and technical/organisational measures
  • DPIA template support
  • Breach register, notification workflow and privacy risk management

Evidence

Public where useful. Controlled where necessary.

The Sotender Trust Center publishes an overview of controls, subprocessors, compliance practices, outcomes and evidence pathways. Sensitive supporting material is available to customers and auditors under NDA rather than being exposed publicly.

EU regulatory readiness

One control system, several regulatory conversations.

ISO/IEC 27001 gives Koivu a governed way to manage security risk and produce evidence. It supports — but does not by itself prove — compliance with sectoral or product-specific EU law.

GDPR

Koivu’s ISMS supports security of processing through risk treatment, access control, encryption, supplier governance, incident handling and continuity. Processor obligations, lawful basis, data-subject rights and DPIAs remain part of the separate privacy programme and customer controller responsibilities.

Official EU source

NIS2 Directive

Risk management, management review, supplier controls, incident response and business continuity provide useful evidence for NIS2-aligned customer assurance. Whether NIS2 applies, and to which entity, must still be assessed for the specific organization and service.

Official EU source

Cyber Resilience Act

Secure development, vulnerability management, component governance and lifecycle support help prepare for CRA requirements where a Koivu offering falls within the regulation’s scope. Scope, conformity assessment and reporting duties require product-specific review; ISO 27001 certification alone is not CRA conformity.

Official EU source

EU AI Act

Koivu’s AI policy, risk process, access controls, logging, supplier review and human oversight practices support responsible AI use. Each AI use case must still be classified and documented against the AI Act’s role- and risk-specific obligations.

Official EU source

Readiness support is assessed against each customer context. Legal scope and conformity decisions require case-specific review.

Start a conversation

Preparing a security review or public procurement?

Contact Koivu for certificates, audit evidence, data-processing documentation or product-specific answers.