How we protect your data.
A practical security programme aligned to recognised control families. This page states what is implemented, what is agreed per engagement, and our current assurance status: Grilli is not externally ISO/IEC 27001 certified.
Defense-in-depth
Layered controls across identity, network, application, and data.
Encryption
TLS 1.2+ in transit, industry-standard encryption at rest.
Change control
Peer review, CI/CD checks, and staged rollouts for production changes.
Governance, identity, data.
Governance & Standards
- Aligned to ISO/IEC 27001:2022 control families and secure R+D practices
- Risk management with regular reviews and management oversight
- Policies for access, acceptable use, secure coding, change, and incident response
Identity & Access
- Least-privilege, role-based access and JIT elevation where applicable
- Phishing-resistant MFA (FIDO2/WebAuthn) enforced on administrative and production systems
- Segregated environments and logging of privileged actions
Data Protection
- Encryption in transit (TLS 1.2+); website form records use KMS-managed encryption at rest in AWS eu-central-1
- Data minimisation, documented access locations, and time-bound retention by default
- Engagement-specific residency, access, backup, and deletion requirements are recorded in the SoW and DPA where applicable
App security, IR, supply chain.
Application Security
- Secure R+D with threat modelling, SAST/DAST/SCA, and peer review
- Secrets management, hardening baselines, and dependency control
- Monitoring of error rates, security events, and anomaly signals
Incident Response
- Defined severity levels and time-bound SLAs for triage and communication
- Forensics-ready logging and evidence preservation procedures
- Post-incident reviews and corrective actions
Supply Chain & Platform
- Vendor risk assessments and least-privilege integrations
- Dependency and container scanning; provenance and signing where applicable
- Infrastructure as code, immutable builds, and monitored changes
Documents for procurement review.
Request the current review set during diligence. Data roles, transfer mechanisms, audit rights, liability, insurance requirements, and other buyer terms are confirmed against the proposed scope rather than implied by this page.
- ✓Master Services Agreement (MSA)Commercial frame: payment terms, IP ownership, liability, term & termination.
- ✓Data Processing Agreement (DPA)Used where Grilli acts as a processor. Records the parties’ roles, security measures, subprocessor terms, breach notification, assistance, return, and deletion.
- ✓Transfer termsThe applicable EU Standard Contractual Clause module and supplementary measures are selected for the actual data flow when a restricted transfer is in scope.
- ✓Statement of Work (SoW) templatePer-engagement scope, deliverables, timeline, and rules of engagement.
MSA-DPA REQUEST — [your organisation]. We will confirm the available documents, review path, and timing for your diligence request. The public Website Data Processing Notice is not the engagement DPA.Personnel screening is risk- and role-based and conducted only where permitted by applicable law. Estonia-based checks may use Karistusregister; other locations use appropriate lawful local processes. Least-privilege access is enforced throughout the engagement and revoked at close. The screening process and credential evidence can be reviewed during diligence where disclosure is lawful and appropriate; private personnel records are not published.
We welcome responsible disclosure. Email security@grillisecurity.com. We target acknowledgement within three business days.
Website assets and form records are stored in AWS's Frankfurt region. CloudFront may process request metadata at global edge locations, and authorised personnel may work from Estonia or Argentina. EU-only access, alternative regions, and engagement-specific residency are available only when expressly agreed before data is shared. See Subprocessors for the full flow.
Our security programme is aligned to ISO/IEC 27001:2022 control families; Grilli is not externally certified. During diligence we provide a dated evidence index that distinguishes implemented controls, planned work, client-specific controls, and third-party certifications. Request it at privacy@grillisecurity.com.
Before signature we identify the proposed engagement lead and delivery roster, including role, seniority, responsibility, work location, credential evidence, conflicts, and any subcontractors. Agreed staffing and substitution controls are recorded in the SoW. References or anonymised work examples are shared only with client permission and, where necessary, under NDA. hello@grillisecurity.com.
For DORA-scoped buyers, we map the proposed service and data flow to the applicable oversight, subcontracting, exit, audit, and incident requirements during diligence. Commitments apply only where agreed in the MSA and SoW. This page does not claim authorisation, registration, or external certification as a TIBER-EU or TLPT provider.
