Security and compliance

Technical control by design

Isolation, European Union data residency and reversibility designed for institutional requirements.

Compliance

Requirements with clear status

We distinguish commitments, alignment and completed certification. Applicable evidence must be validated for each procurement.

  • ISO/IEC 27001

    Information security management certification included in the roadmap.

    Roadmap
  • RGPD / DPIA

    Data protection by design and impact assessments where applicable.

    Commitment
  • NIS2

    Incident management and reporting processes aligned with applicable duties.

    Alignment
  • WCAG 2.2 AA / EN 301 549

    Interfaces designed to WCAG 2.2 Level AA, including WCAG 2.1 Level AA requirements.

    Conformance
  • eIDAS

    Planned support for European electronic identity scenarios.

    Where applicable
  • Autenticação.Gov.pt / CMD

    Identity integration planned for Portuguese public services that require it.

    Where applicable

Isolation and sovereignty

Data remains within the chosen perimeter

Organisation-level separation

Collections, metadata and indexes belong exclusively to the institution’s environment.

EU residency

Cloud services are selected for processing and storage in European Union data centres.

Topology choice

Shared, Dedicated or Sovereign adapts isolation to institutional risk and duties.

Reversibility

Your data is not locked into the platform

Across all deployment models, data and configuration can be exported in open formats at contract end. The abstraction layer also enables a change of LLM provider or model without rebuilding the experience.

Request security and subprocessor documentation

Evaluate Acervo in your institution’s context

Start with a Shared environment or request a demonstration focused on your requirements.