Certifications & assurance
Across security, data quality, and sustainability reporting. Certificates are available upon request.
SOC 2 Type II
ReportDeepki has successfully obtained the SOC 2 Type II report. This demonstrates that our systems, infrastructure and processes consistently meet the highest criteria for data security, confidentiality, availability and operational integrity.
ISO 27001
CertificationThe Deepki platform is certified ISO/IEC 27001:2022 which represents a guarantee of trust, responsibility and security to all stakeholders.
ISAE 3000 Type 2
ReportDeepki has obtained the ISAE 3000 Type 2 attestation for the design, existence and operational effectiveness of its data collection process and quality controls. It makes it fully auditable and provides the same high-quality standards as financial reporting.
ISO 14064-1
CertificationDeepki's CO₂ matcher module is ISO 14064-1 certified by Bureau Veritas, ensuring our methodology complies with the highest standards of carbon accounting to provide complete, consistent and accurate carbon data.
GDPR
RegulationFull compliance with European data privacy regulations. Data processing agreements are available for all clients.
EU AI Act
RegulationDeepki is aligned with EU AI Act pinciples and complies with its respective risk category (level two).
CISSP
Team CredentialDeepki’s security strategy is led by a CISSP-certified Chief Security Officer. This confirms that our governance framework is overseen by executive leadership with proven mastery of the entire information security landscape.
Platform security controls
Access, authentication, and data governance controls built into the Deepki platform.
Single sign-on (SSO)
Supports industry-standard SAMLv2 (including Microsoft ADFS) for the Deepki platform and OpenID Connect for the Nooco SaaS platform, enabling seamless corporate identity integration.
Role-based access control
Enforces strict need-to-know data segregation at fund, portfolio, asset, and data type levels with pre-defined user roles.
Multi-factor authentication
Enforced 2FA across all tools and applications where technically possible. For credential log-ins, a strict password policy of 14 characters minimum with mixed complexity is enforced.
Full audit trail
All system and application events are logged and securely retained read-only for one year. Deepki commits to sharing relevant log extracts directly upon request during security investigations.
Penetration testing
Conducted annually by renowned, independent external cyber security firms across public-facing interfaces. Technical pentest summary reports are available to clients upon request.
AI privacy & governance
Governed in alignment with the NIST AI Risk Management Framework and the EU AI Act. By default, customer data is anonymized before model training, and clients retain full opt-out rights.
Secure uploads & malware defense
All document and bill uploads are automatically scanned for malware to prevent platform contamination. All internal employee endpoints are monitored by enterprise-grade EDR solutions.
Service continuity & disaster recovery
Ensured by a 99.99% infrastructure uptime SLA and real-time multi-site data replication. Standard disaster recovery protocols commit to a 24-hour RPO and a 48-hour RTO, tested annually.
Public policies
Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, storage, compute | EU (Ireland, Sweden) |
| AWS Bedrock | GenAI model inference (zero data retention) | EU |