ISO/IEC 27001:2022 certified
Koivu operates a certified information security management system with documented policies, risk management, audits and management review.
Trust, security and compliance
Customers should not have to rely on vague promises. Koivu documents how information security, privacy, EU-region data operations, resilience and secure development are managed, and provides supporting evidence through the Sotender Trust Center and controlled document requests.
Assurance at a glance
Koivu operates a certified information security management system with documented policies, risk management, audits and management review.
Sotender runs on Google Cloud. Application data and backups remain in the EU region.
Sotender supports SSO through Microsoft and Google, with access controls managed as part of the service.
Application security is reviewed through external security testing and independent audit activity.
Koivu maintains processor documentation, data processing agreements, records of processing, technical and organisational measures, privacy risk management and DPIA support.
Documented incident response, backups, recovery testing, business-impact analysis and business continuity practices support service resilience.
Management system
Koivu’s ISO/IEC 27001:2022 information security management system covers organisational, people, physical and technological controls. Internal audits, corrective actions and management reviews are used to maintain and improve the system.
Security and privacy risks are identified, assessed, treated and reviewed.
Development policies, code review and independent penetration testing support the software lifecycle.
Defined processes cover detection, containment, communication, recovery and post-incident review.
Backups, recovery testing, EU-region storage and business-impact analysis support continuity planning.
Data protection
For tenant data, the customer organization normally acts as controller and Koivu acts as processor under written instructions and a data processing agreement. Koivu also maintains the documentation and workflows needed to support customer obligations.
Read Koivu’s approved Privacy PolicyEvidence
The Sotender Trust Center publishes an overview of controls, subprocessors, compliance practices, outcomes and evidence pathways. Sensitive supporting material is available to customers and auditors under NDA rather than being exposed publicly.
EU regulatory readiness
ISO/IEC 27001 gives Koivu a governed way to manage security risk and produce evidence. It supports — but does not by itself prove — compliance with sectoral or product-specific EU law.
Koivu’s ISMS supports security of processing through risk treatment, access control, encryption, supplier governance, incident handling and continuity. Processor obligations, lawful basis, data-subject rights and DPIAs remain part of the separate privacy programme and customer controller responsibilities.
Official EU sourceRisk management, management review, supplier controls, incident response and business continuity provide useful evidence for NIS2-aligned customer assurance. Whether NIS2 applies, and to which entity, must still be assessed for the specific organization and service.
Official EU sourceSecure development, vulnerability management, component governance and lifecycle support help prepare for CRA requirements where a Koivu offering falls within the regulation’s scope. Scope, conformity assessment and reporting duties require product-specific review; ISO 27001 certification alone is not CRA conformity.
Official EU sourceKoivu’s AI policy, risk process, access controls, logging, supplier review and human oversight practices support responsible AI use. Each AI use case must still be classified and documented against the AI Act’s role- and risk-specific obligations.
Official EU sourceReadiness support is assessed against each customer context. Legal scope and conformity decisions require case-specific review.
Start a conversation
Contact Koivu for certificates, audit evidence, data-processing documentation or product-specific answers.