The facts are here in the open, with no login and no maze of PDFs. Fully accessible, because security should be clear to everyone.
data within Europe · developed and managed in the Netherlands · our own ACM registration for telephony
certification and standards
what we are certified for
We work on the quality of our service continuously. Our foundation is ISO 27001, and that is deliberately one standard rather than a row of marks. Below you will find what each certification covers, with the details you need to check it.
ISO/IEC 27001
certified
Information security, certified by DigiTrust, which works under the supervision of the Dutch Accreditation Council. Standard NEN-EN-ISO/IEC 27001:2023/A1:2024, certificate DGT2717211134, valid from 13 April 2026 to 13 April 2029, with statement of applicability v6.3 dated 23 March 2026. Surveillance audit every year.
Scope: “Information security related to the development, implementation and maintenance of intelligent omni-channel software that handles all incoming and outgoing communication centrally and delivers it to the right people in an organisation.”
Microsoft 365 App Certification
certified
The Unexus Connect Teams integration goes through the Microsoft 365 App Certification every year, including an independent penetration test of the environment.
how it is set up
everything in our own hands
developed in the Netherlands
The software is developed 100 per cent in the Netherlands. No offshore development team. Where it runs is your choice; see below.
managed from Baarn
Our own service desk answers. Same language, same time zone, and someone who knows your set-up.
our own ACM registration
We provide the telephony ourselves. One contract and one service desk, including when something is wrong with the connection.
you choose where it runs
By default in Microsoft Azure, with data within Europe. Your own data centre is also an option.
where it runs
where your data sits
By default the platform runs in Microsoft Azure, West Europe region, with development and management in the Netherlands and our own ACM registration for telephony. If you would rather not be in the public cloud, it can run entirely outside it.
Where it runs
Who does what
What that means
Hosting by Unexus in Azure
Unexus handles management, monitoring, updates and releases
The SLA includes an availability guarantee of up to 99.9 per cent and recovery times per priority. Backups and storage are arranged by Unexus.
Hosting in your own or a partner data centre
Unexus supplies the software, releases and support
The customer or partner manages the infrastructure and is responsible for availability and backups. AI features then use Azure services through the customer's own keys, and additional licences apply. In that case the SLA covers support for the software, not the infrastructure.
what we mean by data sovereignty
You decide where your data sits, who can actually reach it and which legal regime applies. With us that follows from the option to host the platform yourself, not from a label on our cloud environment.
Organisations that want to go further can run the platform entirely outside the public cloud: in their own data centre or with a Dutch partner. The data then sits in their own domain and is not hosted by a US cloud provider, which means access under the US CLOUD Act is not realistically in play either.
and what we do not offer today
For completeness: the platform is built on Microsoft technology, Windows Server and SQL Server. Even when you host it yourself, Microsoft licences are still needed for that. We can place data location and access entirely within the Dutch and European domain; complete independence from US software is not something we offer today.
We deliberately build the platform so that this dependency does not deepen.
what to take into account when self-hosting
Managing the infrastructure yourself, or a partner who does
Additional Microsoft licences
AI features through your own Azure keys, or switching those features off
sub-processors
who else is involved
Four parties, each with its own role. A new or changed sub-processor is announced to our customers in writing in advance, with 30 days to object, in line with the data processing agreement.
Sub-processor
Role
Location and safeguards
Microsoft Ireland Operations Ltd
Hosting of the platform in Azure, West Europe region, and the Azure AI services, among them Azure Speech, Azure OpenAI and Azure Language
EU, West Europe region
CM.COM Netherlands B.V.
Delivery of WhatsApp and SMS messages
the Netherlands
Google Cloud EMEA Ltd and Google LLC
Firebase Cloud Messaging: delivery of push notifications on Android and iOS. Only when the optional mobile app is used. Processes device and registration tokens, IP addresses and notification content, in transit
EU and US, safeguarded with standard contractual clauses and the EU-US Data Privacy Framework, under the Firebase Data Processing and Security Terms
Apple Distribution International Ltd and Apple Inc.
Apple Push Notification service: delivery of push notifications on iOS. Only when the optional mobile app is used. Processes device tokens, IP addresses and notification content, in transit
EU and US, safeguarded with standard contractual clauses and the EU-US Data Privacy Framework, under the Apple Developer Program License Agreement
If you choose sovereign hosting in a Dutch data centre, the data centre providing that colocation is not on this list: without access to the data it is not a sub-processor.
documents
what you can request
The facts are in the open on this page, with no form and no login. How we secure the platform is set out in our technical and organisational measures. Two documents have to be requested, and the reason for that is written out below.
ISO 27001 certificate
Certificate DGT2717211134, issued by DigiTrust, valid from 13 April 2026 to 13 April 2029
Ewoud Bloemendal, CTO, holds final responsibility for information security at Unexus.
responsible disclosure
reporting a vulnerability
If you find a weak spot in our systems, let us know. Below is where you may look, what we ask of you, and what you get back from us.
what it covers
unexus.nl and the ucsnet domains: ucsnet.nl, ucsnet.eu, ucsnet.dk, ucsnet.se, ucsnet.at and ucsnet.co.uk, including the subdomains below them. If a system is not among those, it falls outside this policy.
what we ask of you
Look no further than you need to in order to demonstrate the problem, and leave other people's data alone. No scans that put load on the service, no disruption, no approaching staff. Do not share your finding with anyone else while we are working on it.
what we do
We confirm your report within five working days and we take no legal action against good-faith reporters who act carefully. We keep you posted and publish in consultation with you. There is no reward; credit is available if you want it.
Send your report to security@unexus.nl. Include what we need to trace it: what you did, when, and from which IP address.
the questions a buyer asks
ask, and we answer
These are the questions we get most often once someone wants to know whether this is secure enough. The answers come from our CTO and are set out here in full, not in an appendix.
Where is our data held?
The production environment runs in Microsoft Azure, West Europe region (the Netherlands). Backups are kept within the European Union. Customer data does not leave the EU.
Can we choose where it runs?
Yes. The standard solution runs in Microsoft Azure, West Europe region. If you would rather not be in the public cloud, you can choose sovereign hosting by Unexus in a Dutch data centre, or host it yourself.
Is the data centre run sustainably?
The standard solution runs in Microsoft Azure. For the sustainability of that environment we refer to Microsoft's own sustainability reporting.
Who provides the telephony?
We do. Fixed telephony runs on our own registration with ACM, the Dutch telecoms regulator; mobile we supply as SIM and eSIM cards through Odido. So the platform and the connection come from one supplier with one service desk.
Are the systems independently tested?
Yes. Our systems are tested every year by an independent specialist, covering both the external infrastructure and the web applications and APIs. We share the management summary of the most recent test on request under a confidentiality agreement, through security@unexus.nl.
What availability percentage is in the SLA?
That depends on the service package: 99.5 per cent for Silver, 99.7 per cent for Gold and 99.9 per cent for Platinum. The current status and the incident history are open for anyone to follow on our status page, Unexusservice.nl.
How quickly are you running again after an incident?
We handle incidents according to the priorities and recovery times in the SLA. On the highest service package a P1 incident is picked up within 30 minutes and resolved within 3 hours. The platform runs in an Azure region with several data centres, and recovery is from backups.
Which sub-processors are there?
Microsoft for hosting and the AI services, CM.com for WhatsApp and SMS messages, and Google and Apple for push notifications if you use the mobile app. The full list with role and location is further down this page. A new or changed sub-processor is announced in writing in advance, with 30 days to object, in line with the data processing agreement.
What happens in the event of a data breach?
On a suspected data breach we inform the affected customer without delay, within 24 hours of discovery at the latest. As the controller you are the one who reports to the Dutch Data Protection Authority within 72 hours where that is required. Unexus does not report itself, but supplies all the information needed for the report and the investigation. Our own sub-processors are contractually obliged to inform us within 24 hours.
Is there a standard data processing agreement?
In practice we work with the customer's template: municipalities, housing associations and care organisations almost always have their own model agreement. We set it against our processing activities and it is usually settled quickly. If you do not have one, we supply one.
Are you covered by NIS2?
No. Unexus does not fall under NIS2, but we do set up our measures along the lines of the NIS2 duty of care. We do not claim BIO2.
What about the AI features?
They are off by default and you switch them on per queue. They use Azure services within the European Union only, and nothing is trained on your data. There is more on the page about AI in customer contact.
Who do I report a vulnerability to?
To security@unexus.nl. We confirm your report within five working days and we take no legal action against good-faith reporters who act carefully. Ewoud Bloemendal, CTO, holds final responsibility for information security at Unexus.
is your question not here?
Send it to security@unexus.nl. If the answer is useful to others as well, it goes on this page. If your question is not about security, start with the frequently asked questions.