CRITICAL BUSINESS INFORMATION DEMONSTRABLY SECURE
Information security and compliance
Data breaches, costly hacks and non-compliance. Adequate information security is crucial for every organisation. Your business information is guaranteed to be secure with Xtendis, without having to compromise on its accessibility.
At WoodWing Xtendis, information security is paramount
> 35 years
of experience with document security
> 3.000.000.000
documents securely stored
> 7.000.000
end-users with easy and secure access to documents
> 650
organisations entrusting their business information to us
Securing data and privacy
Every organisation possesses sensitive information and personal documents. The security of this information is enforced by increasingly stringent laws and regulations. This becomes a real headache due to the extensive fragmentation of data and the potentially significant consequences if things go wrong. What you need is structure and transparent management, and that is exactly what Xtendis provides.
The challenge
Information is captured in large quantities of very different documents. These, in turn, are stored in various business systems. How do you guarantee the security of documents without having to compromise on accessibility?
What do you need?
• A single, central system in which all types and sizes of business information can be effortlessly stored and retrieved.
• Good capabilities for professional identity and access management, allowing easy and efficient management of user access rights.
• A watertight audit trail that records important actions per document.
What does it yield?
From compliance to reducing the potential impact of cyber attacks, with Xtendis, you effortlessly enhance the security of documents through tight management of users and access rights. Without unnecessarily hindering access to documents. Additionally, you always have insight into who is doing what with documents, laying a strong foundation for demonstrable compliance.
Securing data and privacy
Every organisation possesses sensitive information and personal documents. The security of this information is enforced by increasingly stringent laws and regulations. This becomes a real headache due to the extensive fragmentation of data and the potentially significant consequences if things go wrong. What you need is structure and transparent management, and that is exactly what Xtendis provides.
The challenge
Information is captured in large quantities of very different documents. These, in turn, are stored in various business systems. How do you guarantee the security of documents without having to compromise on accessibility?
What do you need?
• A single, central system in which all types and sizes of business information can be effortlessly stored and retrieved.
• Good capabilities for professional identity and access management, allowing easy and efficient management of user access rights.
• A watertight audit trail that records important actions per document.
What does it yield?
From compliance to reducing the potential impact of cyber attacks, with Xtendis, you effortlessly enhance the security of documents through tight management of users and access rights. Without unnecessarily hindering access to documents. Additionally, you always have insight into who is doing what with documents, laying a strong foundation for demonstrable compliance.
This is how WoodWing Xtendis secures your documents
The core function of Xtendis is to monitor the digital sustainability of potentially valuable documents. This is done based on the 4 pillars of information security. Each of these pillars has its own security risks and measures to reduce them where possible.
The WoodWing Xtendis organisation
ISO 27001
The fact that WoodWing Xtendis complies with this international standard gives you extra confidence and assurance regarding the security of your data.
See our official ISO 27001 certificate listing.
NEN 7510
This standard is a derivative of ISO 27001 and focuses on information security within the healthcare sector.It concerns ensuring the availability, integrity, and confidentiality of all information for responsible patient care.
See our official NEN 7510 certificate listing.
ISAE 3042 type II
The ISO 27001 standard gives you as a customer the guarantee that WoodWing Xtendis demonstrably meets all requirements and qualifications to handle your information correctly. The ISAE 3402 attestation is an extension of this and provides you with additional assurance that WoodWing Xtendis operates in accordance with the guidelines.
FSQS-NL
WoodWing Xtendis holds the FSQL-NL certificate. This allows customers in the financial sector to demonstrate to regulators that we formally meet all qualifications regarding data security and compliance with local regulations and codes of conduct.
ISO 27001
NEN 7510
ISAE 3042 type II
FSQS-NL
The Xtendis software
Authenticity
Xtendis assigns immutable attributes to every document that is recorded.This allows you to perform authenticity checks on any document.
Audit trail
The Xtendis Audit Trail records all actions within the system. This way, the source of every data mutation can always be traced within the system.
Identity Management
Within Xtendis, you can assign rights to users and systems in an advanced manner. These determine, among other things, which employees can input and/or partially or fully delete documents. Unwarranted deletion actions can be restored in Xtendis within 14 days.
Hashing, encryption, and other techniques
Various techniques are deployed in Xtendis to secure documents, metadata and other system data.
Integrity
Xtendis implements document integrity in several ways. First, all documents are recorded in a non-manipulable file format. Secondly, Xtendis protects documents from direct access by users. Adding and consulting documents always takes place via Xtendis components. It is therefore not possible to exchange files outside Xtendis.
Using the Control Hashes applied to document files, you can proactively check the integrity of documents in Xtendis.
Two-factor authentication
Although Xtendis is often linked to Identity Management systems, it also supports 2-factor authentication. Multi-factor authentication can be configured per user.
Authenticity
Audit trail
Identity Management
Hashing, encryption, and other techniques
Integrity
Two-factor authentication
The Xtendis platform
99.98% Availability
The two sustainable, carrier-neutral data centres where Xtendis is hosted are rated TIER3+, the highest attainable level in the Netherlands. This guarantees a minimum availability of 99.982% for the existing infrastructure.
High operational reliability
The power supply, cooling, and connectivity of both data centres are fully redundant. This is the highest possible redundancy and ensures equal reliability.
Top security
Communication to and from the online Xtendis environment takes place through secure protocols. The infrastructure security is of the highest level: the data centres – both located in the Netherlands – are ISO 27001, ISO 14001 and ISO 9001 certified.
Additional
Optionally, you can use IP Whitelisting, where your customer environment can only be accessed from addresses that you indicate are reliable.
99.98% Availability
High operational reliability
Top security
Additional
Safeguards and guarantees
CloudSecure
One of the ways WoodWing Xtendis ensures the continuity of its services is through the CloudSecure arrangement managed by an independent party (Xtendis Secure Foundation).
This structure ensures that if WoodWing Xtendis ceases to exist, all necessary rights and agreements transfer to an independent foundation.
This involves not only the rights to Xtendis software but also agreements with the data centre, for example.
Data portability
As an Xtendis customer, you can receive exports of the documents and data managed by the software at any time.It is possible to agree in advance on the export format and pricing.
Right to audit/examine
As a customer of WoodWing Xtendis, you have the option to include a right to audit in the agreements. This allows you or an independent third party to conduct an audit at WoodWing Xtendis or a subcontractor engaged by us.
With the right to examine, WoodWing Xtendis cooperates with supervisory authorities to conduct investigations (or have them conducted) if desired, thereby providing the supervisory authorities with relevant information.
Data processing agreement
In compliance with the GDPR, we will draw up a processor agreement together with you as our customer. You can use a standard set-up developed by us.
CloudSecure
Data portability
Right to audit/examine
Data processing agreement
Frequently asked questions about information security
We have compiled the most frequently asked questions about information security for you. Is your question not listed? Please feel free to contact us. We are happy to help!
Why is information security important?
In a time when technology is deeply ingrained in our daily activities and business operations, information security becomes increasingly crucial. For example, to:
- protect sensitive information such as personal, customer, and financial data from unauthorized access, theft, and misuse.
- prevent damage to trustworthiness and reputation by protecting against data breaches and related occurrences.
- ensure compliance with laws and regulations, thereby avoiding fines and other (legal) issues.
What functionality does effective DMS software provide for ensuring information security?
Modern DMS software provides extensive functionality to secure information. Some key examples include:
- Access controls: the ability to set strict access controls so that only authorized users have permission to access specific documents or areas within the system.
- Encryption: the ability to encrypt documents and data, both during storage and transmission.
- Audit trails: maintaining a detailed log of all activities within the DMS software, including who accessed, modified, or deleted documents.
- Integrity checks: ensuring the integrity of documents by detecting unauthorized changes and manipulations.
What does the ISO 27001 certification stand for?
The ISO 27001 certification is an international Information Security Management Systems (ISMS) standard. It provides a framework for effectively managing information security within an organization. The ISO 27001 certification is awarded to organizations that demonstrate compliance with the standard and have implemented a robust information security system.
What does the ISAE 3402 Type II declaration stand for?
ISAE 3402, or the International Standard on Assurance Engagements 3402, pertains to assurance statements issued by service organizations. This global standard is utilized to report on controls performed by service organizations that are critical to the internal control of their customers.
How is data protection handled in WoodWing Xtendis?
Data protection laws and regulations continue to increase in quantity and complexity. As a document management system, WoodWing Xtendis naturally complies with all security measures to protect user data. This is evidenced by our ISO 27001 and ISAE 3402 Type II certifications.
WoodWing Xtendis is a cloud solution where data is stored outside my company. What happens in case of a continuity-threatening calamity?
WoodWing Xtendis offers a CloudSecure feature, allowing organizations to store their critical documents securely. In the event that the parent company, WoodWing, ceases to exist, the source code of WoodWing Xtendis will transfer to an independent foundation that will continue to provide the service. Moreover, we can make arrangements for the migration of documents and metadata from WoodWing Xtendis.
The power of organized content
Are you also ready for smart, compliant, powerful, and secure document management?
Make sure your organization is harnessing the full potential of your employees. Stop hindering them with fragmented content, outdated files, different versions, and inefficient systems and workflows. Instead, take control of your content and empower your team to focus on activities that truly add value. Get to know Xtendis.
This is 20 minutes of your time well spent
Discuss your challenges with one of our experts
Want to make sure your business information is securely stored, edited, and shared? Don't wait until tomorrow to take advantage of our knowledge and experience – we'd love to help!
“Imperdiet auctor varius ipsum eros fermentum amet cras.”
Yani Björkholm
Product expert at ChannelEngineWe help you to take charge of your content with our world-class content and information management solutions.
Receive our Newsletter?