Security and Compliance

We operate in the critical infrastructure sector - data security is our top priority.

The choice of architecture (cloud or on-premise), infrastructure partners, and technical controls is aligned with water utility operator requirements. Below is a clear and honest overview of what is available today and what is planned for the coming quarters.

Two deployment models

The customer chooses the model that matches their security policy and internal requirements.

Default

Cloud (SaaS)

The application runs on Google Cloud Platform infrastructure in the European region. The customer does not maintain server infrastructure - we handle hosting, updates, backups, and monitoring.

  • All data in the EU - full GDPR compliance
  • Automatic backups and 24/7 monitoring
  • Application updates managed by our team
  • Lower entry cost, no infrastructure investment
For critical requirements

On-premise

Full platform installation on customer servers. Data never leaves the organization infrastructure - a typical choice for utilities with a policy of keeping critical data in their own network.

  • Data stored exclusively in customer infrastructure
  • Full data sovereignty - ready for internal audits
  • Customer manages server infrastructure maintenance
  • Updates agreed individually

Both options run the same software - they differ only in data location, billing model, and infrastructure responsibility scope.

Cloud infrastructure - Google Cloud Platform

In the SaaS model, we host the platform on Google Cloud infrastructure in the European region.

EU region

All data is stored in European Google Cloud data centers. No data transfer outside the European Economic Area - GDPR compliance without additional standard clauses.

Cloud SQL Enterprise

PostgreSQL database hosted in Cloud SQL Enterprise with automatic backups, point-in-time recovery, and optional high availability (HA).

Default encryption

Google Cloud encrypts data at rest and in transit by default, without extra configuration. Encryption keys are managed by Google, with optional customer-managed keys (CMEK).

Backups

Automatic Cloud SQL backups with configurable retention. Database state can be restored to any point from recent days (point-in-time recovery).

Google Cloud infrastructure certifications

Google Cloud Platform, the infrastructure we host on, holds the following security certifications, regularly validated by independent auditors:

ISO/IEC 27001 Information security management
ISO/IEC 27017 Cloud services security
ISO/IEC 27018 Cloud privacy
SOC 2 / SOC 3 Security and privacy controls
GDPR Full compliance with EU regulations
ISO/IEC 27701 Privacy information management

Choosing Google Cloud as the core infrastructure means our customers inherit a broad set of built-in protections and compliance controls delivered by a global cloud operator with top industry standards. We build our own organizational and technical processes on the same standards and best practices, in close cooperation with water utility customers.

Full Google Cloud certification list ->

Application security mechanisms

What specifically protects data inside the HydroNexis platform.

Connection encryption

All client-application communication is secured with HTTPS/TLS. This covers the web portal, mobile app, and API integrations.

Access control (RBAC)

Each user is assigned a role (for example operator, manager, dispatcher) with specific permissions per screen and per action. Permission policy is configurable for each organization.

Organization isolation

Data of each organization (tenant) is logically isolated. Users can see only their own assets and operations. Organizations have no cross-access to data.

Operations audit trail

Every remote pump-control operation (start, stop, range change) is logged with details: who, when, and in which mode. Full audit trail for security-policy compliance.

Password policy

User passwords follow policy rules for minimum length, complexity, and periodic refresh. Passwords are stored as hashes (scrypt) - never in plain text.

Account management

User accounts are never deleted - only deactivated. This preserves operation and reporting history for audit purposes. Password reset is protected by a verification mechanism.

Regulatory compliance

We support water utility operators in meeting Polish and EU regulatory requirements.

GDPR

All data is processed in line with GDPR. Hosting is EU-only, data is encrypted, and data-subject rights are supported (access, rectification, deletion). A data processing agreement (DPA) is signed with each customer.

Regulatory reports

The platform generates reports required from water operators: statistical report M-03, national wastewater program reporting, and reports for sanitary and water authorities. Report formats are updated with current regulations.

water abstraction permits

The CSZU module automatically monitors permit expiry dates with notifications 90, 60, and 30 days before expiration. Statuses VALID / CRITICAL / EXPIRED are visible on the organization dashboard.

Geodetic standards

The GIS module (pilot phase) is designed for full compliance with Polish geodetic standards: K-GESUT, BDOT500, EGiB, EMUiA, official GML validation, and geodetic work submissions to PODGiK.

Security roadmap

What we plan for the coming quarters. Specific timelines are agreed with customers during the sales cycle.

Multi-factor authentication

MFA (TOTP/SMS) for users with access to critical functions. Launch date is agreed during implementation planning with customers.

SSO / OAuth

Single Sign-On with existing customer identity infrastructure (Active Directory, Microsoft Entra, Google Workspace). Timeline agreed individually.

ISO 27001 certification

HydroNexis plans organizational ISO 27001 certification as a target state. Today we run on certified Google Cloud infrastructure.

External security audits

After pilot deployments, we plan regular penetration tests and code audits performed by independent companies. Reports available to customers on request.

Security questions?

We will prepare detailed technical documentation tailored to your IT and compliance requirements.