Audited guarantees, not self-proclaimed
Everything we promise about security, quality and trust is certified or recognised by independent third parties, audited periodically and verifiable in public registers. This page gathers the certifications, the policies and the documents.
listed in the EU Trusted List ISO/IEC 27001
information security, independently audited ISO 9001
quality management, independently audited Own infrastructure
high-performance data centres in Spain Since 1998
28 years of uninterrupted engineering
Three guarantees, three independent auditors
Each covers a different dimension: the legal validity of our trust services, the security with which we process information and the quality of our processes.
eIDAS Trust Service Provider, with qualified timestamping
ASETEC Ingeniería de Sistemas (Mensatek brand) is recognised and audited as a provider of electronic trust services under the supervision of the competent ministry in Spain, and is listed in the Trusted List published by the European Commission. We issue qualified electronic timestamps with a legal presumption of accuracy and integrity across the European Union, and on them we provide certification of communications, electronic signature and custody of evidence.
Certified information security
ISO/IEC 27001 is the most relevant international recognition in information security. It is obtained after an external, independent audit that tests risk analysis, technical and organisational controls, incident management and continuous improvement. In a company whose product is, very often, the evidence, data security is not an extra: it is the product. The scope includes our data centres and the communication and trust platforms.
Certified process quality
The UNE-EN ISO 9001 certification recognises internationally the overall quality of our services: how we analyse, design, develop, operate and support. The certification audit assessed the qualification of our staff and the proper management of every process, and it has been reviewed periodically ever since.
In addition, the communication certificates we issue are sealed by two qualified trust service providers (Mensatek and the FNMT), so that the evidence never depends on a single party.
The regulatory framework we operate in
eIDAS (EU 910/2014)
Supervised trust service provider; qualified timestamps with legal effect across the Union.
GDPR and Spanish LOPDGDD
Personal data processed under the European Regulation and Spanish law, with data hosted in Spain.
Law 6/2020 and Civil Procedure Act
Electronic trust services and admissibility of electronic documents as evidence (Arts. 299 and 326).
Telecommunications
Operation of communication services with direct carrier connections and our own numbering, in line with sector regulation.
Information security
ISO/IEC 27001 management system with internal and external audits; published security policy.
Quality
ISO 9001 management system applied to engineering, service and support; published quality policy.
Public, verifiable documents
What an auditor, a client or a court needs to check, without asking.
About our certifications
Who audits the ISO certifications?
An independent, accredited certification body, which performs the initial audit and the periodic surveillance and renewal audits. The current certificates are published as PDFs on this page.
How do I check that you are a trust service provider?
In the European Commission's trusted list browser, selecting Spain: the provider and the qualified services it delivers are listed there. The direct link is on this page.
What does the ISO 27001 certification cover?
The information security management system with which we operate our data centres and the communication and trust platforms: risk analysis, physical, technical and organisational controls, incident management, continuity and continuous improvement.
Can you help us with our own certification?
Yes. Within our cybersecurity services we carry out gap analyses, control plans and evidence preparation for ISO 27001, the Spanish ENS and sector requirements, with the experience of a company that maintains its own certification.
Need the documentation for a supplier approval?
If your procurement or compliance department needs certificates, policies or completed security questionnaires, write to us: we prepare them quickly.