Trust & compliance

Answers your procurement team will ask for.

Six-figure engagements are won in due diligence. This page is written for your legal, security, and procurement colleagues. Anything missing, we answer in writing within two business days.

Jurisdiction & contracting

Legal entityBesharat Enterprises B.V., registered in Leeuwarden, the Netherlands. KvK 96294078, RSIN 867549828.
Contract structureMaster Services Agreement plus Statement of Work per engagement, under Dutch law. Fixed price per phase or time and materials with a cap.
NDASigned within 24 hours of first contact, yours or ours.
Intellectual propertyYou own all code, designs, and artifacts produced in the engagement, from the first commit. No license-back clauses.
ReferencesClient references available on request for qualified engagements.

Data protection

GDPRA Data Processing Agreement is standard with every engagement. Processing records are maintained per Article 30.
Data residencyEverything we host runs on EU infrastructure. Client data does not leave the EEA unless you direct it to.
AccessLeast-privilege access, MFA everywhere, access revoked the day an engagement ends.
RetentionClient data and credentials are deleted on engagement close, with written confirmation on request.

Security practice

Engineering controlsCode review on every change, branch protection, dependency scanning, secrets management. No production access from unmanaged devices.
TestingWe run penetration tests as a service and hold our own systems to the same standard. Our product UniDeck passed Google CASA Tier 2 assessment.
ISO 27001Ainur does not hold ISO 27001 certification. We work the other side of it: we have taken clients through ISMS scoping, control implementation, internal audit, and the penetration testing their certification required. Our own operations run against the same control set.
Incident responseDefined incident process with client notification without undue delay. NIS2 and DORA reporting clocks built into the workflow for in-scope clients.

EU regulatory readiness

NIS2 & DORAWe accept audit rights, provide subcontractor transparency, and support the DORA Register of Information for financial-sector clients.
EU AI ActAI systems we build ship with logging, technical documentation, and monitoring evidence aligned to the Act's high-risk obligations.
AccessibilityInterfaces are built against WCAG 2.2 AA, which the European Accessibility Act expects of consumer-facing services.

Procurement pack

Due-diligence answers, pre-packaged

A capability statement with entity details, insurance, security practice, and references, ready for your vendor onboarding. Request it through the contact form.

Sub-processors

Named in the DPA

The infrastructure vendors behind anything we host are listed in the DPA before you sign it. NIS2 and DORA require that visibility of your suppliers in any case.

Continuity

No key-person cliff

Documentation and handover are part of every scope. Source-code escrow arrangements are available for long-running managed systems.

Request the procurement pack