A control-by-control view of how the platform's technical capabilities support GDPR, NIS2, DORA, and ISO/IEC 27001 — and where features are still maturing.
SecureShare provides technical controls that support compliance. It does not, by itself, make an organization compliant — that depends on your policies, processes, and how you deploy and operate the platform. The mapping below shows which controls the software addresses and how.
EA marks early-access capabilities still under active development. Tamper-evident audit integrity is optional and best-effort (see the Security page).
Protecting personal data through security of processing, accountability, and data-subject rights.
| Art. 32 — Security of processing | XChaCha20-Poly1305 authenticated encryption at rest; optional client-side, zero-knowledge encryption for password-protected files; per-tenant key hierarchy with rotation, backed by AWS KMS or OpenBao. |
| Art. 25 — Data protection by design & by default | Encryption is on by default, tenants are strictly isolated, and access is governed by granular RBAC and per-resource ACLs that inherit through folders. |
| Art. 5(2) & 30 — Accountability & records of processing | A tamper-evident audit trail records every security-relevant action — who, what, when, and source IP — with configurable, long-term retention. |
| Art. 33–34 — Breach awareness | New-device login alerts, session fingerprinting, and the audit trail support detection and investigation. Detection feeds your own notification process — there is no built-in breach-notification workflow. |
| Art. 17 & 5(1)(e) — Erasure & storage limitation | Governed file and user deletion, plus retention policies and disposition. EA — retention is early-access; erasure is administrator-gated and blocked while a legal hold is active. |
| Chapter V — Data residency & transfers | Self-hosted, on-premises, or fully air-gapped deployment keeps personal data within your chosen jurisdiction. |
Cybersecurity risk-management measures under Article 21 for essential and important entities.
| Art. 21(2)(h) — Cryptography & encryption | Modern authenticated encryption (XChaCha20-Poly1305, Argon2id) with a layered key hierarchy and external key management (AWS KMS / OpenBao). |
| Art. 21(2)(i)/(j) — Access control & authentication | Granular RBAC, per-resource ACLs, TOTP multi-factor authentication, OIDC SSO, and LDAP / Active Directory. |
| Art. 21(2)(b) — Incident handling | Tamper-evident audit logging, SIEM webhook forwarding, and login-anomaly alerts support detection, triage, and response. |
| Art. 21(2)(e) — Security in acquisition, development & maintenance | Security-critical configuration is validated at startup to prevent insecure deployments; containerized delivery supports controlled rollout. |
ICT risk-management requirements for financial entities and their service providers.
| Art. 9 — Protection & prevention | Encryption of data at rest and in transit, strong authentication (MFA / SSO), and least-privilege access control across tenants. |
| Art. 10 — Detection | Audit logging of ICT-related events, new-device and session-anomaly alerts, and SIEM webhook forwarding for monitoring. |
| Art. 9 — ICT logging & retention | Configurable, long-term retention of audit events in a dedicated analytics store. |
| Record-keeping | WORM immutability (governance and compliance modes) for unalterable financial records. EA — early-access; pair with storage-level object lock for end-to-end guarantees. |
Annex A controls an ISMS implementer can satisfy with platform-level capabilities.
| A.8.24 — Use of cryptography | XChaCha20-Poly1305, Argon2id, and BLAKE2b; keys sourced from an environment secret, AWS KMS, or OpenBao, with per-tenant rotation. |
| A.5.15–5.18 & A.8.5 — Access control & authentication | RBAC, per-resource ACLs, TOTP MFA, OIDC SSO, session fingerprinting, and instant revocation. |
| A.8.15–8.16 — Logging & monitoring | Tamper-evident audit trail with SIEM webhook forwarding and analytics warehousing. |
| A.5.14 — Information transfer | Encrypted internal sharing and expiring, password-protected, revocable external links and upload requests. |
| A.5.33 — Protection of records | Retention policies and WORM immutability. EA — early-access. |
Framework citations are provided to show where controls apply; they are not a claim of certification or legal advice. Feature availability may depend on edition, configuration, and deployment. Specifications are subject to change.
Talk to our team about your specific GDPR, NIS2, DORA, or ISO/IEC 27001 obligations and deployment model.