Trust & compliance
Answers your procurement team will ask for.
Six-figure engagements are won in due diligence, not in demos. This page is written for your legal, security, and procurement colleagues. Anything missing, we answer in writing within two business days.
Jurisdiction & contracting
Legal entityBesharat Enterprises B.V., registered in Leeuwarden, the Netherlands. KvK 96294078, RSIN 867549828.
Contract structureMaster Services Agreement plus Statement of Work per engagement, under Dutch law. Fixed price per phase or time and materials with a cap.
NDASigned within 24 hours of first contact, yours or ours.
Intellectual propertyYou own all code, designs, and artifacts produced in the engagement, from the first commit. No license-back clauses.
ReferencesClient references available on request for qualified engagements.
Data protection
GDPRA Data Processing Agreement is standard with every engagement. Processing records are maintained per Article 30.
Data residencyEverything we host runs on EU infrastructure. Client data does not leave the EEA unless you direct it to.
AccessLeast-privilege access, MFA everywhere, access revoked the day an engagement ends.
RetentionClient data and credentials are deleted on engagement close, with written confirmation on request.
Security practice
Engineering controlsCode review on every change, branch protection, dependency scanning, secrets management. No production access from unmanaged devices.
TestingWe run penetration tests as a service and hold our own systems to the same standard. Our product UniDeck passed Google CASA Tier 2 assessment.
ISO 27001We build client systems to ISO 27001 controls and run our own operations against the same control set. Certification status and audit letters: ask us on the call.
Incident responseDefined incident process with client notification without undue delay. NIS2 and DORA reporting clocks built into the workflow for in-scope clients.
EU regulatory readiness
NIS2 & DORAWe accept audit rights, provide subcontractor transparency, and support the DORA Register of Information for financial-sector clients.
EU AI ActAI systems we build ship with logging, technical documentation, and monitoring evidence aligned to the Act's high-risk obligations.
AccessibilityInterfaces are built against WCAG 2.2 AA, which the European Accessibility Act expects of consumer-facing services.
Procurement pack
Due-diligence answers, pre-packaged
A capability statement with entity details, insurance, security practice, and references, ready for your vendor onboarding. Request it through the contact form.
Sub-processors
Disclosed, not discovered
The infrastructure vendors behind anything we host are disclosed in the DPA. No undisclosed subcontracting, which is what NIS2 and DORA now require of your suppliers anyway.
Continuity
No key-person cliff
Documentation and handover are part of every scope. Source-code escrow arrangements are available for long-running managed systems.