Skip to content
Nokumo AI Visibility is nu in early access — bekijk hoe AI uw hotel omschrijft.Aanmelden voor de wachtlijst →
nokumo
Beveiliging

De paspoorten van uw gasten verlaten de EU nooit. De rest ook niet.

Azure Frankfurt en Amsterdam. AES-256 in rust. TLS 1.3 in doorvoer. Jaarlijkse penetratietest door SEC-Consult. ePorezna en FURS via certificate-pinned overheids-API's. Dit is precies wat dat in de praktijk betekent.

Microsoft Azure Infrastructure

Nokumo is hosted exclusively on Microsoft Azure in EU data centers. Your guest data never leaves EU jurisdiction.

  • EU data residency (Frankfurt / Amsterdam)
  • 99.9% uptime SLA
  • Automatic failover and disaster recovery
  • Azure DDoS protection

AES-256 Encryption

All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Payment data is tokenised and never stored on Nokumo servers.

  • AES-256 encryption at rest
  • TLS 1.3 for all connections
  • Stripe tokenisation for payment data
  • No plaintext credentials stored

ISO 27001-Aligned

Our information security management follows ISO 27001 principles. We conduct annual security audits and penetration testing.

  • ISO 27001-aligned ISMS
  • Annual penetration testing
  • Vulnerability disclosure programme
  • Incident response under 4 hours

GDPR Compliance

Nokumo acts as a data processor under GDPR. A full Data Processing Agreement (DPA) is available for all customers.

  • Full DPA available on request
  • Data subject rights supported
  • Right to erasure implemented
  • Sub-processor list published

EU Regulatory Security

Croatian eVisitor, ePorezna, and FURS integrations use government-approved secure channels with certificate-pinned APIs.

  • ePorezna certificate-pinned API
  • FURS secure channel integration
  • eVisitor government API compliance
  • Fiscal log integrity guaranteed

Responsible Disclosure

Security researchers can report vulnerabilities via our responsible disclosure programme. We respond within 24 hours.

  • security@nokumo.net
  • PGP key available
  • Hall of fame for researchers
  • No legal action for good-faith disclosure

Certificeringen en nalevingsstatus

ISO 27001-conform
AVG (EU) 2016/679
SOC 2-controles
PCI DSS via Stripe
CAIQ (op verzoek)
Lijst van subverwerkers (gepubliceerd)

We hebben een ingevulde CAIQ nodig voor ons inkoopproces. Is dat beschikbaar?

EC
Enterprise customers
Contact sales to request the completed CAIQ under NDA

Lijst van sub-verwerkers

Microsoft Azure — cloudinfrastructuur, EU-West-regio's
Stripe — betalingsverwerking, PCI DSS-conform
SendGrid — transactionele e-mailbezorging
Volledige lijst beschikbaar op nokumo.com/security

Inkoopdocumentatie nodig?

Verwerkersovereenkomst (DPA) — beschikbaar op verzoek
Lijst van subverwerkers — gepubliceerd en driemaandelijks bijgewerkt
ISO 27001-bewijsbrief — beschikbaar onder NDA
Beveiligingsvragenlijst (CAIQ) — ingevuld op verzoek

Verkorte CAIQ-samenvatting

Versleutelt u gegevens in rust?

Ja — AES-256 voor alle productiedatabases. Sleutels beheerd door Azure Key Vault.

Ondersteunt u MFA?

Ja — MFA afgedwongen voor alle beheerdersaccounts. Beschikbaar voor alle personeelsaccounts.

Waar worden gegevens opgeslagen?

Microsoft Azure West Europe (Nederland) en North Europe (Ierland). Geen gegevens buiten de EU.

Jaarlijkse penetratietests?

Ja — onafhankelijke externe partij. Testrapporten beschikbaar voor enterprise-klanten onder NDA.

Beveiligingsvragen

Klaar om live te gaan in 1 week?

Sluit u aan bij honderden horeca-exploitanten in onze kernmarkten. 14 dagen gratis proefperiode. Geen creditcard vereist.

Geen creditcard · Live in 1 week · EU-naleving inbegrepen

50% off for early accessNo commitmentCancel anytime

Be first in line for Nokumo AI Visibility

Future-proof your digital presence directly within Nokumo AI Visibility and discover exactly how AI engines view and recommend your booking engine.