Reference standards
- A written security and quality management system, with policies, procedures and records.
- Risk assessment and statement of applicability of controls, updated every year.
- Internal audit and management review once a year.
- No certification claims: we only state what we can prove with documents.
Data and infrastructure
- The applications we manage run on Hetzner servers in data centres inside the European Union.
- Each client has a dedicated server or instance, database and credentials: no database is shared between clients.
- DNS, TLS certificates and website protection through Cloudflare.
- Server access only with personal SSH keys, behind an active firewall.
Access
- Multi-factor authentication required on work and administration tools.
- Everyone has only the access their role needs.
- Access review every 6 months; access removed within 1 working day when someone leaves a project.
Secure development
- Every code change is reviewed by a second person before release.
- Automated pipeline with tests, secret scanning, static analysis and dependency checks.
- Production releases only through the pipeline, never by hand.
- Security updates: critical within 7 days, high within 30 days.
Backup and continuity
- Daily server backup kept for 7 days, plus an encrypted database copy on separate storage kept for 30 days, always in the EU.
- Recovery targets: maximum data loss of 24 hours (RPO), recovery within 8 working hours (RTO).
- Restore test every 6 months and continuity exercise every year.
Privacy and GDPR
- When we handle data on your behalf we act as processor and sign an agreement under Article 28 GDPR.
- If a personal data breach occurs we inform you without delay and in any case within 24 hours of discovery.
- Logs kept for at least 30 days; an extract of your logs reaches you within 10 working days of the request.
- At the end of the contract we return your data within 30 days of the request and delete it within the following 30 days.
- Third-party AI services only for the features the project requires and only with the data you have authorised.
Clients subject to NIS2 and DORA
Because of its size, 1801 is not directly in scope of the NIS2 directive. We are ready, however, to work as a supplier to companies subject to NIS2 and to financial entities subject to the DORA regulation.
- Contract addendum with the security requirements of your sector.
- Notice of a significant incident affecting your service within 4 hours of discovery, update within 24 hours and report within 72 hours.
- Audit and information access rights, including for your supervisory authority.
- Exit plan with data return and cooperation when moving to another supplier.
- Up-to-date list of the suppliers we use to deliver the service.
Documents available on request
To assess 1801 as a supplier you can ask us for these documents. Some are shared after a non-disclosure agreement is signed.
- Managed service information sheet.
- Data processing agreement (Article 28 GDPR).
- Addendum for financial sector clients (DORA) and NIS2 entities.
- Summary of security policies and statement of applicability of controls.
Report a security issue
If you notice a vulnerability or a possible incident on a 1801 service, write to support@1801.it
Last updated: 22 September 2026.