Oversight

Evidence you can show.

Foundix is not a law firm and not an automatic certification. The foundation and SOVGO are designed to carry evidence you can put in front of an auditor or supervisor.

DORA

Operational resilience: recovery path, logging, access, foundation supply chain. ICT third-party risk falls when the control plane is under EU direction.

NIS2

Measures at network (SOVNC) and operations (SOVGO) level, notification chain preparable, no unknown subprocessors in the critical path.

GDPR

Processing bounded, no trackers on this site, data residency NL/EU or on-prem, key custody documentable.

ISO 27001

Designed to support ISMS evidence (access, crypto, backup, change). Certification status is not claimed unless completed: [CERT_STATUS].

Artefacts the chain can produce

Access logs, change trails, backup verification reports, SOVNC policy exports, ZFS tenant-isolation evidence, key-custody description, runtime supply-chain list.

What we are not

Not DPO-as-a-service, not legal advice, not ‘GDPR certified’, not a guarantee that your organisation is compliant because you buy Foundix. Compliance remains with the controller.