Skip to content
Security and compliance

How we protect your software and your data

We build and run applications for companies that handle important data: banks, fintech, consulting and retail. This page explains, in plain words, the rules we follow every day.

1801 is not ISO certified. Our processes are aligned with ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and ISO 9001, and we check them every year with a documented self-assessment.

Reference standards

  • A written security and quality management system, with policies, procedures and records.
  • Risk assessment and statement of applicability of controls, updated every year.
  • Internal audit and management review once a year.
  • No certification claims: we only state what we can prove with documents.

Data and infrastructure

  • The applications we manage run on Hetzner servers in data centres inside the European Union.
  • Each client has a dedicated server or instance, database and credentials: no database is shared between clients.
  • DNS, TLS certificates and website protection through Cloudflare.
  • Server access only with personal SSH keys, behind an active firewall.

Access

  • Multi-factor authentication required on work and administration tools.
  • Everyone has only the access their role needs.
  • Access review every 6 months; access removed within 1 working day when someone leaves a project.

Secure development

  • Every code change is reviewed by a second person before release.
  • Automated pipeline with tests, secret scanning, static analysis and dependency checks.
  • Production releases only through the pipeline, never by hand.
  • Security updates: critical within 7 days, high within 30 days.

Backup and continuity

  • Daily server backup kept for 7 days, plus an encrypted database copy on separate storage kept for 30 days, always in the EU.
  • Recovery targets: maximum data loss of 24 hours (RPO), recovery within 8 working hours (RTO).
  • Restore test every 6 months and continuity exercise every year.

Privacy and GDPR

  • When we handle data on your behalf we act as processor and sign an agreement under Article 28 GDPR.
  • If a personal data breach occurs we inform you without delay and in any case within 24 hours of discovery.
  • Logs kept for at least 30 days; an extract of your logs reaches you within 10 working days of the request.
  • At the end of the contract we return your data within 30 days of the request and delete it within the following 30 days.
  • Third-party AI services only for the features the project requires and only with the data you have authorised.

Clients subject to NIS2 and DORA

Because of its size, 1801 is not directly in scope of the NIS2 directive. We are ready, however, to work as a supplier to companies subject to NIS2 and to financial entities subject to the DORA regulation.

  • Contract addendum with the security requirements of your sector.
  • Notice of a significant incident affecting your service within 4 hours of discovery, update within 24 hours and report within 72 hours.
  • Audit and information access rights, including for your supervisory authority.
  • Exit plan with data return and cooperation when moving to another supplier.
  • Up-to-date list of the suppliers we use to deliver the service.

Documents available on request

To assess 1801 as a supplier you can ask us for these documents. Some are shared after a non-disclosure agreement is signed.

  • Managed service information sheet.
  • Data processing agreement (Article 28 GDPR).
  • Addendum for financial sector clients (DORA) and NIS2 entities.
  • Summary of security policies and statement of applicability of controls.
Request security documents

Report a security issue

If you notice a vulnerability or a possible incident on a 1801 service, write to support@1801.it

Last updated: 22 September 2026.

Request security documents

One reply from an engineer, not a form autoresponder. If it isn't a fit, we'll say so on the first call.

Locations
Italy · Czechia · Japan

A person reads it, not an autoresponder. We use your details to reply to this request; see the privacy notice.