Security and compliance

Data does not leave the EU. Period.

Decree is built on Scaleway in Paris. Schrems II is a design premise, not an appendix.

by Decree

Facts

The platform's security profile

100 %
EU hosting
0
US subprocessors in critical data flows
Encrypted
In transit and at rest

Compliance track

Built for the regulated market

GDPR

By design and by default. Not a checklist — a design premise.

Data processing agreements

DPA as standard for every customer.

ISAE 3402

We are working towards attestation.

ISO 27001

We are working towards certification.

NIS2

Relevant for customers in critical infrastructure and emergency preparedness.

Data portability

You can always get your data out, in an open format.

Questions and answers

Security in practice

Where does our data live?

With Scaleway in Paris. EU only.

Is Decree subject to the CLOUD Act?

No. We have no US subprocessors in critical data flows.

Can we export our data?

Yes. Data portability is part of the contract, not a favour.

Is Decree ISO 27001-certified?

Not yet. We're working towards certification. We design and operate by the standard's principles.

What about Schrems II?

Handled in the platform's design. Data does not leave the EU. Standard contractual clauses don't come into play for our hosting setup.

Insights

Related reading

Want to see our subprocessor list?

We send it when we start a conversation. Write to us.

Why Decree

Built for Danish businesses that can't afford doubt about data sovereignty

The market is starting to ask the questions we already answered.

1
data center
0
US transfers
1
data processing agreement
1
vendor
01

One data center, zero international data transfers

All your data sits with Scaleway in Paris. No replication to the US, no subprocessor spaghetti, zero Schrems II exposure.

02

CLOUD Act-free infrastructure

Decree is Danish-owned and EU-hosted. We don't fall under US jurisdiction. Microsoft's sovereign cloud doesn't solve it — we do.

03

NIS2-ready vendor in your supply chain

NIS2 took effect in Denmark on 1 July 2025. We have the documentation ready when your auditor asks about your vendor risk assessment.

04

Battle-tested in critical infrastructure

Mit Beredskab runs alarms on schools. Foreningen Neptun sails offline-first on the other side of the world. We don't build to usually-work.

05

One vendor to call

When something goes wrong it's our job to find it, close it and explain it. You don't chase information between fifteen vendors.

06

Custom-built without enterprise bureaucracy

You talk to the people building the solution. Custom modules in days, not in a six-month discovery phase.

Solutions

All solutions

The whole digital backbone. Pick the modules you use, pay for the rest when you grow.

Hosted in the EU. Built for Denmark.

Start a conversation