Security built by people who operate critical systems every day
We protect infrastructure, applications, data and identities with the experience of operating a trust platform audited under ISO 27001 and eIDAS. We do not sell fear: we design controls proportionate to the risk and keep them working.
- Management
- ISO/IEC 27001-certified information security management system
- Trust
- eIDAS Trust Service Provider, periodically audited
- Privacy
- GDPR-compliant processing, data hosted in Spain
- Infrastructure
- Own data centre with redundant physical and logical controls
- Operation
- 24/7 monitoring, incident management and tested continuity
listed in the EU Trusted List ISO/IEC 27001
information security, independently audited ISO 9001
quality management, independently audited Own infrastructure
high-performance data centres in Spain Since 1998
28 years of uninterrupted engineering
Security is a property of the system, not a product you bolt on
Our cybersecurity was born from an obligation: we operate services in which the integrity of a piece of data or of an evidence record has legal consequences. That demands a complete information security management system (risk analysis, controls, internal and external audits, continuous improvement) that we have kept certified under ISO/IEC 27001 for years and supervised as an eIDAS trust service provider.
We put that experience at our clients' service in two ways: security built into every system we design (access control, encryption, audit logging, segmentation, tested backups) and security services for existing systems: risk assessment, hardening, identity management, strong authentication, anti-fraud and monitoring.
We work with engineering judgement: every control must be justified by a real risk, be measurable and be maintainable. A control nobody operates is a false sense of security.
Principles
- Proportionality: controls sized to the risk and to the value of what they protect.
- Defence in depth: several independent layers, no single point of failure.
- Least privilege: role-based access, reviewed and logged.
- Verifiable: audit logs, evidence and qualified timestamping.
- Tested: backups, recovery and continuity rehearsed, not just documented.
- Audited: by independent third parties, every year.
Cybersecurity services
For the systems we build and for the ones you already run in production.
Risk analysis and compliance
Risk assessment, control map and roadmap towards ISO 27001, GDPR, the Spanish ENS or sector requirements, with a practical approach.
Infrastructure security
Server and network hardening, segmentation, firewalls, encryption in transit and at rest, patch management and secure configuration.
Application security
Architecture and code review, security testing, API protection and access control in bespoke applications.
Identity and strong authentication
Identity management, two-factor authentication via OTP (SMS, email, voice, app), identity verification with biometrics and trusted-device access.
Real-time anti-fraud
Risk scoring of phones, emails, IPs and documents, detection of impersonation and of compromised credentials before the fraud happens.
Monitoring and response
24/7 supervision of systems and services from our operations centre, multichannel alerts, incident management and post-incident analysis.
Continuity and recovery
Encrypted and verified backups, continuity and disaster recovery plans tested in our own data centre.
Evidence and integrity
Qualified timestamping, record custody and certified notifications to prove what happened, when and who did it.
Data sovereignty
Hosting and processing in our own data centres in Spain, under European jurisdiction and GDPR.
What gets audited every year in our own house
We apply to our clients the same controls an independent auditor verifies on our trust platform.
- Access management: Strong authentication, role-based privileges, periodic review and logging of every access to systems and data.
- Encryption: End-to-end encrypted communications, encrypted data at rest and key management with custody controls.
- Logging and evidence: Tamper-evident audit logs, with qualified timestamping when the evidence has legal value.
- Vulnerability management: Inventory, planned patching, security testing and continuous configuration review.
- Continuity: Redundancy in our own data centre, verified backups and recovery drills with measured target times.
- Suppliers and people: Third-party assessment, confidentiality agreements, team training and awareness.
How we approach the security of an existing system
No scaremongering and no hundred-page reports nobody applies: prioritised risks, concrete controls and follow-up.
Assessment
Asset inventory, risk analysis and technical review of infrastructure, applications and access.
Plan
Controls prioritised by risk and effort, with owners, deadlines and verification metrics.
Implementation
Hardening, strong authentication, anti-fraud, monitoring and backups, integrated into your operation.
Watch
24/7 monitoring, periodic control review and support during audits and certifications.
Common situations
Accounts being impersonated
Two-factor authentication via OTP and trusted device for access to panels and applications, with automatic escalation on suspicious attempts.
Fraud in contracting
Anti-fraud scoring of phone, email and IP plus identity verification with biometrics before accepting a sign-up or a transaction.
The road to ISO 27001 or ENS
Gap analysis, prioritised controls and evidence ready for the audit, with the experience of a company that maintains its own certification.
Backups that were never restored
Design of encrypted, verified backups with measured restore drills and our own data centre as fallback.
Proving what happened
Records with qualified timestamping and certified notifications for litigation, audits and claims.
Sovereignty and GDPR
Migration of systems and data to our own infrastructure in Spain, with audited access controls and encryption.
Questions we are usually asked
Are you ISO 27001 certified?
Yes. Our information security management system is ISO/IEC 27001 certified by an independent body and is audited periodically. As an eIDAS trust service provider we also pass specific conformity audits.
Can you protect systems you did not build?
Yes. We start with a technical and risk assessment of the existing system and propose concrete, prioritised and measurable controls, which we implement and integrate into your operation.
What is the anti-fraud service?
A service that scores in real time the risk of a phone number, an email, an IP or a document (virtual numbers, disposable emails, leaked credentials, impersonation) so that your system can decide before accepting a sign-up, a payment or a transaction.
Where is data hosted?
In data centres operated by ASETEC in Spain, under European jurisdiction and GDPR, with physical and logical controls included in the scope of our ISO 27001 certification.
How can I report a vulnerability?
Through the contact form or by phone, stating that it is a security communication. We handle it with priority, confidentially and with acknowledgement of receipt.
Do you know your real risk?
Tell us which systems you have and what worries you. We will propose an assessment with concrete controls, prioritised by risk, without reports nobody applies.