Trust

SECURITY, PRIVACY & ASSURANCE

Folderit Trust Center

Your documents deserve a provider you can trust. Review our certifications, security controls and privacy commitments, with supporting documentation for your due diligence.

Independent certifications

01 / ASSURANCE
Certified

ISO/IEC 27001:2022

Information security management covering our cloud and on-premises document management systems.

Certificate EST-I-270571
Issued 28 Oct 2024 · Expires 27 Oct 2027

Certificate scope & details
Certified

Cyber Essentials

Whole-organisation certification under the UK Cyber Essentials scheme.

Certified 14 Sep 2026
Recertification due 14 Sep 2027

Verify certificate in public registry
ISO 27001 certificate details
Certified entity
Folderit OÜ
Standard
ISO/IEC 27001:2022
Scope
Design, Development, Installation, Maintenance and Management of Cloud-Based and On-Premises Document Management Systems.
Certification body
Certification Assurance International
Certificate number
EST-I-270571
Issued / expiry
28 October 2024 / 27 October 2027

Certification is subject to ongoing maintenance of the management system and periodic audits. Request a copy of the certificate.

Cyber Essentials certificate details
Certified entity
Folderit OÜ
Scheme
Cyber Essentials
Scope
Whole organisation
Certification body
Southern IT Networks
Scheme partner
The IASME Consortium Ltd
Certificate number
f7193a69-85ea-4745-88b2-a1eea6b5ede4
Certified
14 September 2026
Recertification due
14 September 2027
Profile version
3.3 (Danzell)

Cyber Essentials uses an assessed self-assessment of the organisation’s cybersecurity controls. View the active certificate and inspection copy in the public registry.

Privacy & regulatory support

02 / COMPLIANCE

Document controls and clear processing responsibilities for the requirements that matter to your organisation.

EUROPEAN UNION · COMPLIANCE

GDPR

GDPR-compliant service with documented data processing commitments, a published Privacy Notice and transparency about subprocessors.

Read the DPA (PDF)
UNITED STATES · COMPLIANCE SUPPORT

HIPAA

Access controls, encrypted storage and audit trails support healthcare document workflows. Business Associate Agreements are available to discuss for your intended use.

HIPAA safeguards & BAA information
SOUTH AFRICA · READINESS SUPPORT

POPIA

Controlled access, document activity records and configurable retention help your organisation put its personal information protection policies into practice.

Discuss your POPIA requirements
INDIA · READINESS SUPPORT

DPDP Act

Permissions, audit trails, searchable records and retention automation support DPDP readiness. Assess configuration, log retention, contracts and hosting for your use case.

How Folderit supports DPDP readiness

Regulatory support is distinct from independent certification. Your organisation’s compliance also depends on its configuration, policies, processing activities and applicable agreements.

Security, built into the work

03 / CONTROLS

Product safeguards and documented governance, organised around the questions your security team asks.

Identity & access

Control who can do what

Two-factor authentication, configurable password policies and IP restrictions. Single sign-on with Microsoft Entra ID, Okta and Google. Granular permissions for files and folders.

Encryption

In transit and at rest

Encrypted connections protect data in transit, with 256-bit encrypted storage for data at rest.

Auditability

Accountability across document activity

Audit trails record document activities such as uploads, previews, downloads and sharing, giving authorised administrators evidence for reviews and investigations.

Backup & continuity

Preparation for disruption

Geographically separated backups support recovery. Our Emergency Management Policy defines response responsibilities, service restoration priorities and requirements for testing backup and recovery procedures.

Security testing

Independent assessment

Regular penetration testing by third-party specialists helps identify vulnerabilities. Our Information Security Policy sets requirements for access management, secure development and supplier security.

Incident management

A documented response process

Our Incident Management Policy covers identification, severity assessment, containment, recovery, communication and post-incident review, with defined ownership.

Secure development

Information Security Policy

Our policy sets requirements for security in the software development lifecycle, code reviews, security testing and addressing vulnerabilities.

Supplier security

Information Security Policy

Our policy addresses supplier due diligence, security requirements in agreements and ongoing oversight. The published provider list identifies the roles of application, business and website services.

People & governance

Information Security Policy

Our policy defines security responsibilities, staff awareness and training requirements, asset management and periodic policy review.

Policy summaries describe documented requirements, not live monitoring results. Product capabilities are described in our security overview. Request deployment-specific evidence for your assessment.

Security for your deployment

04 / RESPONSIBILITIES

Choose a service arrangement that fits your requirements, then confirm the operational responsibilities in your agreement.

Responsibilities to confirm during procurement
AreaFolderit cloudOn premises
Hosting & recoveryReview the service’s hosting location, backup arrangements and agreed recovery requirements.Define who operates the infrastructure, backups and recovery procedures.
MaintenanceConfirm service maintenance and support arrangements.Agree responsibility for application updates, infrastructure patching and monitoring.
Users & accessYour organisation approves users, permissions, sharing and authentication settings for its workspace.
Information lifecycleYour organisation decides what to store, applicable retention rules and authorised deletion, subject to agreed service capabilities and obligations.

Deployment and plan affect available features and responsibilities. For on-premises installations, confirm the division of operational responsibilities during your assessment.

Documentation for due diligence

05 / EVIDENCE

Verify our Cyber Essentials certificate and review our public legal and privacy documents. Contact us for our ISO certificate and policy documentation relevant to your review.

PUBLIC DOCUMENTS

Cyber Essentials certificate

Whole-organisation scope. Public verification and an inspection copy.

Verify certificate

Data Processing Agreement

Processing responsibilities and data protection commitments.

Read DPA (PDF)

Privacy Notice

How personal information is handled.

Read notice (PDF)

Subprocessors & service providers

Provider roles, including application services and public website tools.

View providers

Terms of Use

The terms governing use of the Folderit service.

Read terms (PDF)
AVAILABLE TO REQUEST

ISO/IEC 27001:2022 certificate

Certificate EST-I-270571, including the certified management system scope.

Request certificate

Information Security Policy

Security governance and organisational safeguards.

Request policy

Incident Management Policy

Incident response, ownership and communication.

Request policy

Emergency Management Policy

Business continuity and service restoration procedures.

Request policy

Requests are reviewed before supporting documents are shared. Confidential materials are not publicly downloadable here.

Questions from buying teams

06 / YOUR REVIEW
What does Folderit’s ISO 27001 certification cover?

Folderit OÜ’s information security management system is certified to ISO/IEC 27001:2022. Its scope covers the design, development, installation, maintenance and management of cloud-based and on-premises document management systems. Certificate EST-I-270571 was issued on 28 October 2024 and states an expiry of 27 October 2027, subject to ongoing maintenance and audits.

Where is our data hosted?

Our Privacy Notice identifies Amazon hosting in Ireland, or another location selected where that option is provided. On-premises deployment is also available. Confirm the hosting location and service arrangement for your deployment during procurement.

Some service providers may involve processing outside the EEA. Review the Privacy Notice (PDF) and provider list for the relevant roles and safeguards.

Can we obtain a DPA or a HIPAA Business Associate Agreement?

Our standard DPA (PDF) is available for review. Contact our team about your contracting requirements or a BAA for a healthcare use case. Agree the applicable arrangements before processing protected health information.

Does Folderit make our organisation automatically compliant?

Compliance is a shared effort. Folderit provides security controls, document management capabilities and contractual commitments that support your programme. Your organisation remains responsible for its processing decisions, user access, configuration and operating procedures.

For example, retention automation must be configured to your approved schedule, and required log retention should be confirmed for your deployment.

Are website analytics used inside our Folderit workspace?

Google Analytics and Microsoft Advertising are used on the public Folderit website, not inside the Folderit application. Our subprocessor and service provider page distinguishes application services from tools used only on the public website.

How should we assess retention and deletion?

Set a retention schedule that reflects your organisation’s requirements and confirm the retention automation available for your plan. Moving a document to the recycle bin is not the same as permanent erasure. Include document versions, audit records and backup retention in your review.

Our DPDP readiness guide explains these configuration considerations. Ask our team to confirm export and deletion arrangements, including account closure, before contracting.

Can we specify recovery objectives and audit log retention?

Include your required recovery time, acceptable data loss and audit log retention period in your security review. Backup arrangements alone do not establish a contractual recovery time objective (RTO) or recovery point objective (RPO). Confirm availability and commitments for your intended deployment in the applicable agreement.

Can we send a security questionnaire or request supporting evidence?

Yes. Send your questionnaire, required documents and review timeline to info@folderit.com. Identify any specific requirements for hosting, recovery, authentication, log retention or contract terms so our team can address your intended deployment.

MOVE YOUR REVIEW FORWARD

Put your security questions to our team.

Tell us which documents you need, the deployment you are considering and your review timeline. We can help your IT, privacy and procurement teams assess Folderit together.

  1. Define the scope. Cloud or on premises, preferred hosting location, data categories and applicable regulatory requirements.
  2. Identify the evidence. Certificates, policy documentation, your security questionnaire and any specific testing or recovery evidence you need us to confirm.
  3. Confirm the commitments. Authentication, retention, recovery objectives, DPA or BAA requirements and your purchasing timeline.

Please send requirements rather than live customer records, credentials or other sensitive data. Our team can agree a suitable channel for confidential review materials.

Procurement & security reviews: info@folderit.com
Privacy enquiries: privacy@folderit.com

Page updated 30 September 2026. This overview summarises Folderit’s security and privacy information; the applicable agreements define service commitments. Security overview.