For your procurement and contract management
This page describes what we take on contractually, how the setup runs and which documents you get from us.
What we take on
Every point can be checked: in the data processing agreement, in the certificate, or in the environment itself.
The environment
Your environment stands on its own, on a dedicated server with its own database, shielded by IP whitelisting. No data from other organisations is held in it.
The processing
Processing in your environment stays in the Netherlands, and does not go outside the European Economic Area, not through a subprocessor either.
The audit log
The audit log cannot be switched off. Every query, every finding and every time a case file is opened is recorded, and that is not a setting you or we can change. If you delete a case file, everything belonging to it goes with it, including its log.
Reconstructability
When you close an investigation we archive the report and fix the underlying material, so that years later it can be shown as it stood then.
Repeatability
The system is deterministic and does not learn from earlier case files. Every flag can be traced back to the rule that raised it, so in two years you can still explain why it went off then. Change those rules and the outcome changes with them, and that is visible too.
Certification
Our information security management system is ISO 27001 certified for the development and hosting of Noctua. We maintain that certification for as long as your agreement runs, with periodic assessment by an accredited body.
If you stop
You decide what happens to the data: transfer in a form agreed with you, or destruction. After that the server is removed, and within seven days the backups have expired as well.
Contact
You have one fixed contact person. Support and changes to your flags or permissions run through that person, not through a rotating desk.
What stays with you. The legal basis, the retention period and who has access. The weighing of every flag. The decision and the reasoning beneath it. We do not take that over, and we cannot: the fact-finding rests with your organisation.
From signing to working
The setup consists of choices your organisation makes and we record. Within four weeks there is a production-ready environment your users can log in to. In this order:
- What you are allowed to query. Which sources are available to you follows from your legal basis and from the agreements underneath them. We determine that together, before anything is set up.
- The data processing agreement. The standard model of the VNG, the association of Dutch municipalities, or your own.
- Your environment. A dedicated server with its own database, shielded by IP whitelisting, so the environment is not reachable for third parties. If you choose hosting on your own infrastructure, we set that up together with your IT department and the planning runs through your organisation.
- The grounds from your policy. Which sectors, grounds and threshold values lead to deeper investigation is set up together with your team, so that what is in the system matches what your organisation has established.
- The report template. Set up for your organisation, and where you must be able to hand over a case file, arranged with the substantiation that belongs to it.
- Connecting the sources. You supply your organisation’s PKIoverheid certificate and we install it on the server, so that queries run under your own legal basis. If you do not have one yet, we help with the application. We arrange access to the commercial registers.
- Optional: single sign-on. This is where your IT department comes in, not for the use itself. What your IT department needs is ready here; once those details are in, it is quickly arranged on our side.
What we need from you, your organisation decides itself:
- Which flags you want and on what: the threshold values, the SBI codes (the Dutch industry classification) and the further grounds that follow from your policy rule.
- Who is going to work with the platform, in users and departments.
- Who may view, edit and close what, per department or per user.
The documents
Available are:
- The data processing agreement
- The ISO 27001 certificate with the Statement of Applicability
- Documentation for your DPIA
- Our annex for the record of processing activities
- The model SLA, to which the GIBIT 2020 applies
We send the set after a short conversation, so that we know which parts apply to your organisation. After that the set is yours and you distribute it internally as you see fit.
Cost
There is a package for small, medium and large organisations. A municipality of twenty thousand inhabitants does not take the same thing as one of the four largest cities, and does not pay the same either. A limited budget is therefore no reason not to have the conversation.
What exactly you take differs further per organisation: the number of users, the sources you are authorised for, and whether you run on our infrastructure or your own. That is why there is no price list on this site. What it comes to in your situation, and what that means for the procedure you have to follow, we go through in the conversation.
Send us your specification
Do you have a programme of requirements, a questionnaire or a draft specification? You get it back in writing, answered per requirement, with a reference to the document that supports it. Where we do not comply, that is stated too.