You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
const title ="Compliance & Certifications | ISO 27001, GDPR, NIS2 | Defguard";
10
+
const description =
11
+
"Defguard compliance: ISO 27001 certified, EU-based for GDPR and NIS2. Biometric MFA, data sovereignty, SBOM, and open-source transparency for enterprise and regulated sectors.";
Defguard is ISO 27001 certified and built for European digital sovereignty: GDPR-native, NIS2-ready, with biometric MFA, full data residency, and transparent supply chain (SBOM).
<FlexibleSectionid="compliance-edge"leftRatio={1}title="European Digital Sovereignty: The Defguard Compliance Edge"theme="light">
73
+
<divslot="left">
74
+
<pclass="section-lead">
75
+
Defguard combines formal certification with practical, auditable controls designed for regulated teams operating under EU legal and security requirements.
76
+
</p>
77
+
<divclass="compliance-grid">
78
+
<divclass="compliance-item">
79
+
<h4>100% EU-Based & GDPR Native</h4>
80
+
<p>Headquartered and developed in Poland, Defguard ensures zero exposure to the US CLOUD Act. It provides a legally "clean" stack for GDPR compliance, where data jurisdiction and residency are non-negotiable.</p>
81
+
</div>
82
+
<divclass="compliance-item">
83
+
<h4>Biometric Zero-Trust MFA</h4>
84
+
<p>Defguard enforces MFA at the protocol level using Desktop & Mobile Biometrics (FaceID/TouchID). This creates a secure "something you are" factor that satisfies NIS2 and ISO 27001 (A.8.5) without the logistics of hardware key distribution.</p>
85
+
</div>
86
+
<divclass="compliance-item">
87
+
<h4>Granular Access Control (ISO A.5.15)</h4>
88
+
<p>Enforce the Principle of Least Privilege with centralized ACLs. Defguard prevents lateral movement by restricting remote users to specific internal resources, directly mapping to ISO 27001 Access Control requirements.</p>
89
+
</div>
90
+
<divclass="compliance-item">
91
+
<h4>Total Data Sovereignty</h4>
92
+
<p>A strictly self-hosted architecture that keeps all cryptographic keys, user metadata, and traffic logs on your private infrastructure. No external cloud relays or third-party auth providers are required, ensuring maximum privacy.</p>
93
+
</div>
94
+
<divclass="compliance-item">
95
+
<h4>Open-Source & Rust Transparency</h4>
96
+
<p>Built with memory-safe Rust, our code is fully open and verifiable. This provides the "Secure Development" evidence required for ISO 27001 (A.8.28) and eliminates the risk of "black box" proprietary backdoors.</p>
97
+
</div>
98
+
<divclass="compliance-item">
99
+
<h4>Supply Chain Security (SBOM)</h4>
100
+
<p>In compliance with the EU Cyber Resilience Act, Defguard provides a detailed Software Bill of Materials (SBOM) and public pen-testing results, allowing your security team to audit every "ingredient" in your remote access stack.</p>
101
+
</div>
102
+
</div>
103
+
</div>
104
+
</FlexibleSection>
105
+
106
+
<FlexibleSectionid="why-iso-27001"leftRatio={0.72}title="Why ISO 27001 Matters for Our Users"theme="light">
107
+
<divslot="left">
108
+
<p>At Defguard we have always built security into the core of our product — from protocol-level WireGuard® MFA, through open-source transparency, to data sovereignty and zero foreign legal exposure.</p>
109
+
<p>Achieving ISO 27001 certification formalizes and externally validates our Information Security Management System. It demonstrates to enterprises, regulated organizations and public sector clients that:</p>
110
+
111
+
<ulclass="benefits-list">
112
+
<li>Information security risks are systematically identified, assessed and treated</li>
113
+
<li>Security controls follow international best practices</li>
114
+
<li>Processes are continuously improved and audited</li>
115
+
<li>We maintain the same high standards internally that we provide to you</li>
116
+
<li>Your trust in Defguard as a secure, reliable VPN & zero-trust platform is backed by third-party certification</li>
<li>NIS2-ready architecture with true VPN-level MFA</li>
122
+
<li>Full EU data residency & governance (Poland-based)</li>
123
+
<li>Audit-ready logs and SIEM integration</li>
124
+
<li>Support for GDPR, HIPAA, PCI DSS, NIST & similar frameworks through strong technical controls</li>
125
+
<li><ahref="/sbom/">Software Bill of Materials (SBOM)</a> and <ahref="/pentesting/">public penetration testing reports</a> for supply chain and transparency audits</li>
Our ISO-27001:2013 certification and rigorous internal audits ensure that our systems, processes, and operations meet globally recognized benchmarks.
143
+
Our ISO27001:2023 certification and rigorous internal audits ensure that our systems, processes, and operations meet globally recognized benchmarks.
56
144
57
145
Beyond compliance, we offer fully transparent development process and <ahref="/security/">Secure By Design approach</a>.
58
146
</p>
@@ -130,32 +218,6 @@ const tags = [
130
218
</div>
131
219
</FlexibleSection>
132
220
133
-
<FlexibleSectionleftRatio={1}title="Why ISO 27001 Matters for Our Users"theme="light">
134
-
<divslot="left">
135
-
<p>At Defguard we have always built security into the core of our product — from protocol-level WireGuard® MFA, through open-source transparency, to data sovereignty and zero foreign legal exposure.</p>
136
-
<p>Achieving ISO 27001 certification formalizes and externally validates our Information Security Management System. It demonstrates to enterprises, regulated organizations and public sector clients that:</p>
137
-
138
-
<ulclass="benefits-list">
139
-
<li>Information security risks are systematically identified, assessed and treated</li>
140
-
<li>Security controls follow international best practices</li>
141
-
<li>Processes are continuously improved and audited</li>
142
-
<li>We maintain the same high standards internally that we provide to you</li>
143
-
<li>Your trust in Defguard as a secure, reliable VPN & zero-trust platform is backed by third-party certification</li>
0 commit comments