Compliance
Two regulations ask something of us directly, rather than only of you. What follows is our side of each: what the requirement is, and what we do about it. Every line is already written into the terms or the data processing agreement.
DORA compliance
Regulation (EU) 2022/2554 has applied to financial entities since 17 January 2025. If you are one, we are an ICT third party service provider to you, and Article 30 sets out what the contract between us has to contain.
Kombine is not a designated critical ICT third party provider. That designation is made and published by the European Supervisory Authorities and applies to providers whose failure would move the financial system. The Article 30 provisions below apply to us regardless.
A description of the service
What the service does, and what it does not, is set out in the terms and on this page. Not a clause reading "various IT services".
Where processing happens
Stockholm, eu-north-1, and customer data does not leave the European Union. Every sub-processor, its role and its region is published.
Integrity and confidentiality
The measures listed under Data security above, in full, including field level encryption of integration credentials.
Access, recovery and return of data
A full export throughout the subscription and for 30 days after termination, then deletion. Return of your data does not depend on our cooperation.
Incident notification and assistance
We notify you without undue delay with what we know at the time, and keep updating. The purpose is to let you meet your own reporting window, including 72 hours under the GDPR and what you owe under NIS2.
Sub-outsourcing
The list is published. Thirty days notice to workspace administrators before we add or replace one, and you may object on reasonable grounds and terminate the affected part without penalty.
Audit and access rights
Security documentation and summaries of independent testing on request. Beyond that you may audit us, or appoint an auditor who is not a competitor, once a year on reasonable notice and more often if an incident justifies it.
Service levels
Read this one before you sign. Standard subscriptions carry no contractual uptime figure and the terms say so plainly. DORA expects quantitative targets where a service supports a critical or important function, so if ours supports one of yours, agree them with us first.
Exit and termination
The exit route is the product. The same build runs on your own hardware against a licence key, so leaving is a change of address rather than a migration project. Notice periods are in the terms.
Cooperation with authorities
We cooperate with your competent authority and with resolution authorities, and we do not treat a supervisory request as a commercial negotiation.
KSI and KSRA compliance
The Cybersecurity Law transposes NIS2 into Lithuanian law, and the Description of Cybersecurity Requirements, approved by Government Resolution No. 818 and in force in the version set by Resolution No. 945 of 6 November 2024, sets out what an entity has to do. It has applied to essential and important entities since 1 September 2025, supervised by the National Cyber Security Centre.
The description is organised into eight blocks. Below is what we do about each of them in running this service. Where a block is about how a supplier behaves, the supplier is us.
Security management
A named person accountable for the security of the service, written policies behind the decisions, and a record of who approved what. We run Kombine on Kombine, so our own control record is kept the way our customers keep theirs.
Risk assessment
Risks are registered with an owner and a treatment. Findings from scanning, from dependency and image checks on every build, and from external testing all land in the same register.
Third party security
Every sub-processor is assessed before it is used and published once it is. Adding one is a thirty day notice to customers, not a quiet change.
Incident management
Incidents are handled against a written procedure with owners and deadlines, and the trail is timestamped. Customer notification is without undue delay and is a contractual obligation rather than a courtesy.
Business continuity
Backups nightly across three tracks with tested restores. The self-hosted option means no customer depends on our continued existence to keep running.
Register of subjects
The organisational data the register asks for is kept current, and the company details behind it are published on the contact page rather than held privately.
Technical controls
The measures under Data security above: encryption at three layers, multi factor authentication, permissions per module, signed agents, and audit entries kept ninety days live and archived after.
Audit and effectiveness
The platform is penetration tested by an external party and findings are tracked to closure. Customers may audit us under the data processing agreement, and the evidence we hand over carries timestamps and sources.