Trust Centre
At Joinly and Koppelhet, trust is central. Our customers trust us with their most valuable data: personal data, company data and sensitive information. That is why we ensure that security, privacy and availability are not just promises, but are built into our product, our processes and our team.
Security in short
- ISO 27001Certified and audited annually by DigiTrust
- GDPRA data processing agreement and our own Data Protection Officer
- Penetration testTested independently every year by ThreadStone
- Data locationAll data and resources in Amsterdam (NL)
- Availability99.9% average uptime, monitored 24/7
- Sign-inAlways with two-factor authentication
GDPR
We fully comply with the requirements of the General Data Protection Regulation (GDPR).
Data is processed solely for clear and defined purposes.
Customers always retain insight and control over their data.
We have appointed a Data Protection Officer (DPO) and perform periodic audits.
ISO 27001
Our processes are designed in accordance with the international ISO 27001 standard for information security. This guarantees that we manage risks and security measures in a structured and controlled manner.
We are ISO27001 certified and are audited annually by Digitrust.

Pentest
Our applications are regularly tested by independent security experts through penetration testing.
Any findings are immediately resolved and integrated into our development process.
The most recent penetration test was conducted by Threadstone.

Documents
Documents and certificates
Reviewing Joinly for your organisation? These are the documents you will need. Some you can download straight away, the rest we send over as soon as you ask.
- ISO 27001 certificateDownload
Our information security certification, audited every year by DigiTrust.
- Statement of ApplicabilityOn request
Which controls from the standard we have implemented, and which do not apply and why.
- Privacy statementDownload
Which personal data we process, for what purpose, and what rights you have.
- Data processing agreement (DPA)On request
The agreement between you as controller and Joinly as processor, including the sub-processor register.
- Penetration test reportOn request
The management summary of the most recent penetration test by ThreadStone, with the status of the follow-up.
- Terms and conditionsDownload
The contractual basis underneath the service.
Need a document that is not listed here, for a security questionnaire or a tender? Let us know and we will see what we can do.
Security
We build security into every part of our infrastructure and application.
Encryption
Database: Databases are secured with SHA256 encryption, both at rest and in transit.
Application layer: Privacy-sensitive data is additionally hashed and encrypted (SHA256).
Communication: All data traffic is sent via SSL/TLS encryption.
Locations
All data and resources are hosted exclusively in Amsterdam (NL).
Secure Development
Secure development according to OWASP guidelines.
Code reviews and security checks in CI/CD pipelines.
Annual penetration testing by external security specialists (Threadstone).
We publish a security.txt file for responsible disclosure.
Availability
Our customers rely on continuous access. That is why we monitor our systems 24/7 and use a scalable cloud infrastructure.
Uptime: 99.9% average uptime, 99.7% minimum uptime
Privacy and data
We are a processor of personal data and offer our customers a transparent data processing agreement (DPA). This defines how we handle personal data and how we comply with the GDPR.
The platform
Access to Joinly itself
Joinly manages access. So you will want to know how access to Joinly is arranged, who on our side can reach it, and what every action leaves behind.
Sign-in with two-factor authentication
Every administrator signs in with a password combined with a second factor. That second factor is on for everyone and is not a per-user setting. You can also link an account to Microsoft, so administrators sign in with their existing Microsoft account and user management stays with you.
Who on our side can reach it
Our people work with personal accounts under least privilege, always with two-factor authentication. We review who has which access periodically and remove what is no longer needed. Everyone is bound by a confidentiality clause and follows an annual security awareness programme.
API keys with a fixed scope
The public REST API works with API keys. You set per key what it gives access to, and afterwards you can see which change came in through which key.
An audit log that can only be added to
Every change lands in the audit log together with where it came from: an HR import, a manual action, a change from Entra, the system itself or an API key. The workflow that caused it is recorded alongside. The log cannot be edited or deleted through the application, only added to. That is what an auditor wants to see when they ask who was given which access when.
Data and sub-processors
Where your data is held
Joinly is the processor of personal data, you remain the controller. That distinction determines who decides what, and it is fixed in the data processing agreement.
Inside the European Union
All data and resources are hosted exclusively in Amsterdam (NL) and therefore inside the European Union. There is no environment outside the EU that production data goes to.
Only the data that is needed
Joinly processes the employee data needed to manage accounts and access, such as name, email address, job title, department and the start and end dates of employment. Which fields your source system supplies is something you set yourself in the import configuration. Nothing beyond that comes in.
Separated from other customers
Data is separated per organisation and that separation is enforced in the platform itself, not only in the screens. Every customer integration has its own credentials that are never shared. If you want to go further, we can provide a separately provisioned environment for you.
Sub-processors
For parts of the service, such as hosting and sending email, we engage sub-processors. They are all established in the EU and bound by the same requirements as we are. The current list belongs with the data processing agreement, which you can request above.
Backups and recovery
We back up your data and test periodically that restoring actually works, with a report of it. Our continuity plan is part of the ISO 27001 system and describes what we do if the platform or a supplier goes down.
Getting your data out, and having it removed
During the term you get data out of Joinly without us in the middle: the platform exports to Excel and the public REST API gives access to the same records. When the agreement ends we hand over the configuration in a readable format, your environment stays available for an agreed period to support the handover, and after that we remove your data from production and from the backups, with a written confirmation of deletion.
When something goes wrong
Incidents and data breaches
Our systems are monitored 24/7. Even so, something can always go wrong, and then you will want to know what to expect from us.
A data breach that affects your data is reported to you without delay and at the latest within 24 hours of us becoming aware of it. You hear from us what happened, which data and how many people are involved, the expected consequences and the measures we are taking. After that we keep you informed for as long as the incident runs.
That leaves you as the controller the room to decide within 72 hours whether the supervisory authority needs to be notified, which is what article 33 of the GDPR asks of you. The precise agreements on notification, deadlines and cooperation are set out in the data processing agreement.
Responsible disclosure
Found a vulnerability? Tell us
However much attention we pay to security, something can always slip through. If you discover a vulnerability in Joinly, we would like to hear about it. Then we can fix it before anyone is affected by it.
What we ask of you
- Report your finding at the address below, with enough information to reproduce it. Usually the URL or IP address and a description will do. For a more complex vulnerability we would like the steps as well.
- Do not take advantage of what you find. Do not retrieve more data than you need to demonstrate the problem, and do not change or delete anything belonging to someone else.
- Do not share the vulnerability with others while it is still unresolved.
- Do not use attacks on physical security, social engineering, distributed denial of service or spam, and do not target third-party systems.
What we promise
- We acknowledge your report within three working days, with our first assessment and an indication of when you will hear more.
- If you have kept to the points above, we will not take legal action in response to your report.
- We treat your report confidentially and will not pass your details to third parties without your permission.
- We keep you informed of progress until the vulnerability is resolved.
- If we publish anything about the finding, we will name you as its discoverer. If you would rather we did not, we leave your name out.
- We do not run a bug bounty and do not pay monetary rewards. We do take your report seriously, and you get the credit.
Frequently asked questions
Questions about security
The questions we get most often during a security review, a questionnaire or a tender. If yours is not here, just ask.
Is Joinly ISO 27001-certified?
Yes. Our processes are set up in line with the ISO 27001 standard for information security and we are audited annually by DigiTrust. You can download the certificate above, and the Statement of Applicability is available on request.
Where is my data held?
All data and resources are hosted exclusively in Amsterdam (NL) and therefore inside the European Union. No production data goes to an environment outside the EU.
Is my data separated from that of other customers?
Yes. Separation per organisation is enforced in the platform itself, not only in the screens, and every customer integration has its own credentials that are never shared. If you want to go further, we can provide a separately provisioned environment for you.
Who at Joinly can reach our data?
Only the people who need it for their work, with personal accounts under least privilege and always with two-factor authentication. We review who has which access periodically and remove what is no longer needed. Everyone is bound by a confidentiality clause and follows an annual security awareness programme.
How is access to Joinly itself secured?
Administrators sign in with an email address and password combined with a second factor. That second factor is always on. You can also link an account to Microsoft, so sign-in runs through the existing Microsoft account and user management stays with you. Access through the public API runs on API keys with a fixed scope.
Can I see the penetration test report?
Yes, on request. Our applications are tested every year by an independent party; the most recent penetration test was carried out by ThreadStone. You get the management summary with the status of the follow-up. Request it through the contact form and tell us what you need it for.
Can we run our own audit or penetration test?
Yes, yourself or through an independent third party. We make policy, process descriptions and documentation available for it and follow up on findings, the critical ones first. Because the platform serves several customers, we agree the notice, the scope and the timing beforehand; those terms are set out in the agreement.
Is there a data processing agreement?
Yes. We are a processor of personal data and offer a standard data processing agreement (DPA). It sets out how we handle personal data, how we meet the GDPR and which sub-processors we engage. You can request it through the contact form.
Can I see afterwards who was given which access?
Yes. Every change is in the audit log with its source: HR import, manual, from Entra, by the system or through an API key. The workflow that caused it is recorded alongside, and the log can only be added to, not edited or deleted. That is exactly the overview an ISO 27001 or NIS2 assessment asks of you.
Do you take backups, and do you test that restoring works?
Yes, and we test them. Periodically we actually restore a backup and record the report of it, so the recovery process is demonstrable rather than only described.
What happens in the event of a data breach?
We report it to you without delay and at the latest within 24 hours of becoming aware of it, with what we have at that point: what happened, which data and how many people it affects, the expected consequences and the measures we are taking. After that we keep you informed for as long as the incident runs. That leaves you the room to decide within 72 hours whether the supervisory authority needs to be notified.
How do you stop a mistake in the HR system from going straight through?
You can run an import configuration as a dry run first, exporting to Excel what would happen. On top of that, a threshold stops the import as soon as an unusual number of records would change at once. That way a mistake on the source side does not quietly reach your whole organisation.
What happens to our data when the agreement ends?
We hand over the configuration in a readable format, your environment stays available for an agreed period to support the handover, and after that we remove your data from production and from the backups with a written confirmation of deletion. The periods are set out in the agreement.
How do I report a vulnerability?
Through the responsible disclosure section above. We acknowledge your report within three working days, treat it confidentially and keep you informed until it is resolved. Our security.txt is at /.well-known/security.txt.
Why this is important
We believe that trust is the foundation of collaboration. By making our processes, technology, and certifications transparent, we give customers the assurance that their data is processed securely, reliably, and in compliance with laws and regulations.
Question not answered here?
A security questionnaire, a request for the data processing agreement or the penetration test report, or a question about how something works. Just ask. You will get an answer from someone who knows the platform.
Browsing is free
Ready to integrate all your applications?
With Joinly, you turn identity & access management into a streamlined process. From HR data to Entra access: fully automated, secure, and scalable.
Schedule a demo