ISO/IEC 27001:2022
Information security management covering our cloud and on-premises document management systems.
Certificate scope & detailsSECURITY, PRIVACY & ASSURANCE
Your documents deserve a provider you can trust. Review our certifications, security controls and privacy commitments, with supporting documentation for your due diligence.
Information security management covering our cloud and on-premises document management systems.
Certificate scope & detailsWhole-organisation certification under the UK Cyber Essentials scheme.
Verify certificate in public registryCertification is subject to ongoing maintenance of the management system and periodic audits. Request a copy of the certificate.
Cyber Essentials uses an assessed self-assessment of the organisation’s cybersecurity controls. View the active certificate and inspection copy in the public registry.
Document controls and clear processing responsibilities for the requirements that matter to your organisation.
GDPR-compliant service with documented data processing commitments, a published Privacy Notice and transparency about subprocessors.
Read the DPA (PDF)Access controls, encrypted storage and audit trails support healthcare document workflows. Business Associate Agreements are available to discuss for your intended use.
HIPAA safeguards & BAA informationControlled access, document activity records and configurable retention help your organisation put its personal information protection policies into practice.
Discuss your POPIA requirementsPermissions, audit trails, searchable records and retention automation support DPDP readiness. Assess configuration, log retention, contracts and hosting for your use case.
How Folderit supports DPDP readinessRegulatory support is distinct from independent certification. Your organisation’s compliance also depends on its configuration, policies, processing activities and applicable agreements.
Product safeguards and documented governance, organised around the questions your security team asks.
Two-factor authentication, configurable password policies and IP restrictions. Single sign-on with Microsoft Entra ID, Okta and Google. Granular permissions for files and folders.
Encrypted connections protect data in transit, with 256-bit encrypted storage for data at rest.
Audit trails record document activities such as uploads, previews, downloads and sharing, giving authorised administrators evidence for reviews and investigations.
Geographically separated backups support recovery. Our Emergency Management Policy defines response responsibilities, service restoration priorities and requirements for testing backup and recovery procedures.
Regular penetration testing by third-party specialists helps identify vulnerabilities. Our Information Security Policy sets requirements for access management, secure development and supplier security.
Our Incident Management Policy covers identification, severity assessment, containment, recovery, communication and post-incident review, with defined ownership.
Our policy sets requirements for security in the software development lifecycle, code reviews, security testing and addressing vulnerabilities.
Our policy addresses supplier due diligence, security requirements in agreements and ongoing oversight. The published provider list identifies the roles of application, business and website services.
Our policy defines security responsibilities, staff awareness and training requirements, asset management and periodic policy review.
Policy summaries describe documented requirements, not live monitoring results. Product capabilities are described in our security overview. Request deployment-specific evidence for your assessment.
Choose a service arrangement that fits your requirements, then confirm the operational responsibilities in your agreement.
| Area | Folderit cloud | On premises |
|---|---|---|
| Hosting & recovery | Review the service’s hosting location, backup arrangements and agreed recovery requirements. | Define who operates the infrastructure, backups and recovery procedures. |
| Maintenance | Confirm service maintenance and support arrangements. | Agree responsibility for application updates, infrastructure patching and monitoring. |
| Users & access | Your organisation approves users, permissions, sharing and authentication settings for its workspace. | |
| Information lifecycle | Your organisation decides what to store, applicable retention rules and authorised deletion, subject to agreed service capabilities and obligations. | |
Deployment and plan affect available features and responsibilities. For on-premises installations, confirm the division of operational responsibilities during your assessment.
Verify our Cyber Essentials certificate and review our public legal and privacy documents. Contact us for our ISO certificate and policy documentation relevant to your review.
Whole-organisation scope. Public verification and an inspection copy.
Processing responsibilities and data protection commitments.
How personal information is handled.
Provider roles, including application services and public website tools.
The terms governing use of the Folderit service.
Certificate EST-I-270571, including the certified management system scope.
Security governance and organisational safeguards.
Incident response, ownership and communication.
Business continuity and service restoration procedures.
Requests are reviewed before supporting documents are shared. Confidential materials are not publicly downloadable here.
Folderit OÜ’s information security management system is certified to ISO/IEC 27001:2022. Its scope covers the design, development, installation, maintenance and management of cloud-based and on-premises document management systems. Certificate EST-I-270571 was issued on 28 October 2024 and states an expiry of 27 October 2027, subject to ongoing maintenance and audits.
Our Privacy Notice identifies Amazon hosting in Ireland, or another location selected where that option is provided. On-premises deployment is also available. Confirm the hosting location and service arrangement for your deployment during procurement.
Some service providers may involve processing outside the EEA. Review the Privacy Notice (PDF) and provider list for the relevant roles and safeguards.
Our standard DPA (PDF) is available for review. Contact our team about your contracting requirements or a BAA for a healthcare use case. Agree the applicable arrangements before processing protected health information.
Compliance is a shared effort. Folderit provides security controls, document management capabilities and contractual commitments that support your programme. Your organisation remains responsible for its processing decisions, user access, configuration and operating procedures.
For example, retention automation must be configured to your approved schedule, and required log retention should be confirmed for your deployment.
Google Analytics and Microsoft Advertising are used on the public Folderit website, not inside the Folderit application. Our subprocessor and service provider page distinguishes application services from tools used only on the public website.
Set a retention schedule that reflects your organisation’s requirements and confirm the retention automation available for your plan. Moving a document to the recycle bin is not the same as permanent erasure. Include document versions, audit records and backup retention in your review.
Our DPDP readiness guide explains these configuration considerations. Ask our team to confirm export and deletion arrangements, including account closure, before contracting.
Include your required recovery time, acceptable data loss and audit log retention period in your security review. Backup arrangements alone do not establish a contractual recovery time objective (RTO) or recovery point objective (RPO). Confirm availability and commitments for your intended deployment in the applicable agreement.
Yes. Send your questionnaire, required documents and review timeline to info@folderit.com. Identify any specific requirements for hosting, recovery, authentication, log retention or contract terms so our team can address your intended deployment.
MOVE YOUR REVIEW FORWARD
Tell us which documents you need, the deployment you are considering and your review timeline. We can help your IT, privacy and procurement teams assess Folderit together.
Please send requirements rather than live customer records, credentials or other sensitive data. Our team can agree a suitable channel for confidential review materials.
Procurement & security reviews: info@folderit.com
Privacy enquiries: privacy@folderit.com
Page updated 30 September 2026. This overview summarises Folderit’s security and privacy information; the applicable agreements define service commitments. Security overview.