Security and evidence
Trust center
What your procurement and your IT want to know, in one place. Where the data sits, who owns it, how tenants are separated and what happens in an incident.
Certification
sinnograte is certified to ISO 27001, for development and operation. That is the difference that counts in a review: not only is the code written under a governed process, the operation of the instances runs under it too.
The certificate and its scope are available for inspection. Ask for it and we will send it.
Where the data sits
Operation runs in European data centres, and the data does not leave the EU. Which region exactly is settled in the contract, not dictated by us.
On premises is possible. HVACloud also runs in your own data centre. That is a different licence model, not a different product.
For manufacturers buying under group policy, what usually decides it is not where it sits today but whether it can go where the policy requires. The answer to that is yes.
We name the operator and location of the current data centre on request.
Tenant separation
Every manufacturer gets a dedicated instance. No shared database, no common application in which a tenant column would be the only separation.
The question behind this is usually: what happens if another customer of this platform is compromised. The answer is that it does not touch your instance.
Inside your instance, tenants mirror your structure: you as the manufacturer, system partners below, operators below them. Each sees their own section.
Data ownership
The data from your plants belongs to you. You decide who sees it, how long it is kept and what happens to it if the relationship ends. An export of your fleet is part of the agreement and not a negotiation at the end.
Sign in and rights
Sign in runs through Keycloak. Your existing corporate sign in can be connected instead of your staff managing yet another password. Rights hang off roles, not off individual accounts, and new users arrive through an invitation route.
Device access
Only approved hardware connects, against documented criteria. Which devices are approved is your decision inside your tenant. A device that supplies plant data and accepts commands does not belong on an open list.
Resilience
Load tests with 5,000 concurrent clients ran without degradation. The architecture is designed for 100,000 plants.
These figures are not meant as advertising but as an answer to whether the platform will still carry your fleet in ten years.
Reporting a vulnerability
If you find a weakness, please write to office@sinnograte.at. Tell us what you found and how it can be reproduced.
We confirm receipt within two working days and come back with an assessment. Anyone who reports a weakness responsibly and gives us time to fix it has nothing to fear from us.
Documents on request
This website is public, some of the evidence is not. On request and, where needed, under a non-disclosure agreement:
- ISO 27001 certificate with scope
- Data processing agreement under Article 28 GDPR
- List of sub-processors
- Technical and organisational measures
- Architecture description for your IT department
Ask us and we will work out which of these you need.
21 September 2026