COMPLIANCE · SECURITY · GOVERNANCE

Security and compliance, on the record.

Nexim Cloud runs on infrastructure operated by Nexim Italia S.r.l. under three certified management systems — with managed access, planned continuity and European operations behind them.

// ISO 9001:2015 // ISO/IEC 20000-1:2018 // ISO/IEC 27001:2022 // GDPR
CERTIFICATIONS · The three standards

Three certified management systems.

Certification is not a logo — it is an auditor returning periodically to check that the system still does what it says. These are the three that govern how this infrastructure is built, run and secured.

ISO

ISO 9001:2015

Quality management

Governs how services are planned, delivered and improved: defined processes, measurable objectives, and a route from a problem to a corrective action. In practice, it is why a request follows the same path whoever picks it up, and why a recurring fault becomes a fix rather than a habit.

What it covers
  • Documented processes and named process owners
  • Customer requirements captured and reviewed
  • Non-conformities handled through corrective action
  • Internal audits and management review
ISO

ISO/IEC 20000-1:2018

IT service management

Governs the service lifecycle: how a service is designed, changed, monitored and supported. It is the standard behind incident, problem and change management — the disciplines that decide whether an unplanned event stays an event or becomes an outage.

What it covers
  • Service level management and reporting
  • Incident and problem management
  • Change and release control
  • Configuration, capacity and availability management
  • Supplier management
ISO

ISO/IEC 27001:2022

Information security

Governs the information security management system: the risks are assessed, the controls that treat them are chosen deliberately, and the evidence that they work is kept. It is the standard that sits behind access, cryptography, physical entry, logging and incident response.

What it covers
  • Risk assessment and documented risk treatment
  • Access control, identity and authentication
  • Cryptography and key management
  • Physical and environmental security
  • Logging, monitoring and security incident management
  • Supplier and third-party security
ISO 9001:2015 ISO/IEC 20000-1:2018 ISO/IEC 27001:2022

Certificates are issued to Nexim Italia S.r.l., trading as Nexim Global. The scope and the validity of each certification are stated on the certificate itself — the published copies are the reference, not this page.

ACCESS · Identity & authorisation

Access is granted, reviewed and revoked.

Most incidents are access incidents wearing a different name. Under the certified information security management system, access is treated as something that has to be justified when granted and reconsidered afterwards — not as a permanent property of a person.

LEAST
Privilege

Rights are granted on the minimum scope the role actually requires, rather than on what would be convenient to hand out once.

NAMED
Identity

Personal, attributable accounts for the people who operate the infrastructure. A shared credential is not an access model.

REVIEW
Entitlements

Entitlements are reviewed periodically and revoked when a role changes or ends — the step most organisations skip.

LOGGED
Traceability

Administrative activity is logged so that what happened can be reconstructed and reviewed, rather than reconstructed from memory.

The same logic governs the building: entry to the facility is controlled and recorded, and physical access follows the same principle of justification as logical access.

CONTINUITY · Operational resilience

Continuity is planned, not improvised.

A continuity plan that has never been tested is a document, not a plan. This is the cycle the certified management systems require — and the one your workloads inherit when they run here.

  1. STEP 01

    Assess the impact

    Which services matter, what an interruption costs, and what the recovery objectives have to be. The answers come from your business, not from a template.

  2. STEP 02

    Engineer the redundancy

    Redundant power, cooling and network paths in the facility; replication and a recovery site for the workloads whose objectives demand one.

  3. STEP 03

    Document the plan

    Runbooks, roles, escalation and communication — written down while everyone is calm, so the decisions are already made when nobody is.

  4. STEP 04

    Test and review

    Periodic tests with the outcome in writing, and a plan updated on what the test actually found rather than on what it was supposed to prove.

RESIDENCY · Where your data lives

European infrastructure, European operations.

The group operates its own European infrastructure. Your environment is placed on it deliberately: where your data sits is a decision taken with you, not a side effect of somebody else’s capacity planning.

R-01

Known placement

You know which facility holds your environment. Placement is part of the agreement, so it does not change quietly underneath you.

R-02

European operations

The infrastructure and the teams that operate it sit within Europe, under one accountable operator and one European legal entity.

R-03

Purpose limitation

Your data is processed to deliver the service you contracted and on your documented instructions — the role of a processor, not that of a party with its own use for it.

PRIVACY · GDPR

Personal data, handled as a processor.

Where Nexim processes personal data on behalf of a customer, it acts as a data processor under Regulation (EU) 2016/679 (GDPR). Processing takes place on the customer’s documented instructions, under a data processing agreement, with confidentiality obligations on the people involved and with technical and organisational measures drawn from the controls of the certified ISO/IEC 27001:2022 management system.

Where Nexim processes personal data for its own purposes — a contact request, a contract, a supplier relationship — it acts as controller. What is collected, why, on which legal basis and for how long it is kept is set out in the privacy notice.

Sub-processors, where used, are engaged under the same obligations that bind Nexim, and changes are notified as the agreement and the Regulation require. Requests from data subjects that reach us in our role as processor are referred to the customer as controller; requests concerning data we hold as controller are handled under the privacy notice.

One caveat worth stating plainly: a certificate is not a substitute for your own assessment. Each certification states its scope, and the honest use of it is as evidence for your audit — which we will support with the documentation behind it — rather than as an answer to it.

Read the privacy notice

REQUEST · DOCUMENTATION

Ask for the evidence.

Certificates, controls, the data processing agreement, audit support — tell us what your compliance team needs to see and we will put it in front of them.

Request documentation View certificates