Technical and Organisational Security Measures (TOMs) — Sustalium
Document Ref: TOMS-2026-V1.4 · Last updated: 31 August 2026
Sustalium B.V. has implemented and will maintain the following technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR.
Access Control
Access to systems and data is restricted to authorized personnel based on the principle of least privilege. Multi-factor authentication is required for access to critical systems.
Encryption
All Customer Data is encrypted in transit using TLS 1.2 or higher. All Customer Data is encrypted at rest using industry-standard AES-256 encryption.
Data Minimization
The Company collects and processes only the Personal Data that is necessary to provide the Services.
Logging and Monitoring
The Company maintains detailed logs of access to critical systems and monitors for suspicious activity. Furthermore, the platform maintains an immutable, cryptographically-verifiable audit trail of all critical customer data events (such as data submission and report generation) to support customer compliance and audit requirements.
Incident Response
The Company maintains a formal Incident Response Plan to identify, manage, and remediate security incidents in a timely manner.
Personnel Security
All personnel with access to Personal Data are subject to confidentiality obligations and undergo regular security and data protection training.
Business Continuity
The Company maintains a Business Continuity and Disaster Recovery plan, including regular backups of Customer Data, to ensure the availability of the Services.
Questions? Contact us through our contact page for any questions about our security measures.