We build for security first.
Our tenants depend on it.
Accure focuses on Security, Compliance and Trust — alongside 24/7/365 operations with 99.95% uptime and world-class cloud infrastructure for every Accure tenant. Your data never leaves the EU. Your service never sleeps.
24/7/365 monitoring · 99.95% uptime SLA · <24h breach notification · EU data residency · Zero-trust access · End-to-end encryption
Four pillars. Every tenant. Every day.
Our Information Security Management System (ISMS) is built around four non-negotiable principles that govern every aspect of how we handle your data.
Confidentiality
Only authorised persons access your data. Strict role-based controls, MFA everywhere, and full tenant isolation in our multi-tenant Azure environment.
Integrity
Your data is accurate and unaltered. Every document, transaction, and record is protected against unauthorised modification — by accident or by attack.
Availability
99.95% uptime. 24/7/365 automated monitoring. Redundant infrastructure across Azure Western and Northern Europe. Your service is always there when you need it.
Traceability
Complete audit trail of every access event, transaction, and administrative action. Logs retained for 12 months minimum, protected against tampering.
Azure security and EU sovereignty — by design.
Accure One, Accure One, and Accure for M3 are all deployed on Microsoft Azure — exclusively in Western Europe (Netherlands) and Northern Europe (Ireland). Microsoft's EU Data Boundary ensures that customer data stays inside the EU at all times.
We inherit the full depth of Azure's security and compliance posture — and layer Accure's own controls on top.
- Azure Security Centre (Microsoft Defender for Cloud) — continuous threat monitoring
- Azure Active Directory / Entra ID — identity and access management, SSO, MFA
- Azure Key Vault — secrets, keys, and certificate management
- RBAC on all resources — least-privilege access enforced
- All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Azure DDoS Protection Standard on all production workloads
- Azure Monitor + Application Insights — 24/7 automated alerting
- Microsoft carbon neutral since 2012 — carbon negative target 2030
Your tenant. Our responsibility.
Every Accure tenant runs on fully managed, multi-tenant Azure infrastructure — operated by Accure's Cloud Operations team 24/7/365. No servers for you to run, patch, or worry about.
24/7/365 Monitoring
Automated monitoring covers every Accure tenant continuously. Alerts trigger instantly on any anomaly, with on-call escalation and documented incident response.
Multi-region redundancy
Production workloads run across Azure Western Europe and Northern Europe. Full customer data isolation between tenants — no cross-tenant data access is architecturally possible.
Zero-downtime updates
Platform updates are deployed without service interruption. Major changes require 3 months' advance notice; minor changes 1 month. Your output operations continue uninterrupted.
Backup & recovery
All tenant data and system-critical configurations are backed up continuously. Recovery procedures are regularly tested. RTO and RPO commitments available in ESLA/USLA.
Identity & access
MFA on all access paths. Role-based access control enforced at every layer. Inactive accounts disabled after 45 days. All privileged access is session-monitored and audited.
Compliance reporting
Incident reports, audit logs, and security posture documentation available on request. Quarterly access reviews. Annual security awareness training for all staff.
Governed by policy. Driven by culture.
Accure's information security governance is built on two formal policies that apply to all employees, contractors, partners, and suppliers — with annual review and board-level accountability.
ISMS — Information Security Management System
Accure's master information security policy governs how all information assets are protected across the organisation. It defines the four pillars of information security — Confidentiality, Integrity, Availability and Traceability — and assigns clear ownership at every level.
- Covers all information processing regardless of medium or environment
- Risk assessments and impact assessments conducted annually
- Security Manager role with board-level mandate
- Annual security plan approved by Accure board
- Mandatory for all staff, partners, and subcontractors
- Continuous training and security awareness programme
Access Control — NIS2 & SOC 2 Aligned
Accure's user access policy governs all access to Accure Cloud Solutions and internal IT systems. Designed to meet NIS2 Directive (EU 2022/2555) and SOC 2 Trust Services Criteria requirements for security, availability, and confidentiality.
- Least-privilege and need-to-know principles enforced
- MFA mandatory for all internal, external, and privileged access
- Accounts auto-disabled after 45 consecutive days of inactivity
- Quarterly access reviews — all user access validated
- Access logs retained minimum 12 months
- Immediate access revocation on termination of employment
All documents. Always current.
Data Processing Agreement
GDPR-compliant DPA with Standard Contractual Clauses. Updated Feb 2026.
Privacy Policy
How Accure collects, uses, and protects personal data. GDPR aligned.
General Terms (EN)
Standard terms for Accure One — Europe, Asia and USA.
Allmänna Villkor (SV)
Allmänna villkor för Accure One — Sverige/Norden.
Talk to our Security team.
Need a security questionnaire completed, an audit package, or a custom ESLA/USLA conversation? Our Security Officer and Cloud Operations team are ready.
