Compliance

Documented compliance,
audited every year.

ISO-certified operations, EU data residency, and regulatory alignment for GDPR, DORA, and NIS2. Documentation ready for your legal and security review.

ISO 27001:2022 ISO 9001:2015 GDPR DORA NIS2 RH Premier Partner
Request Documentation →
Certifications & frameworks

Independently audited evidence — not marketing copy.

Both ISO certifications are maintained continuously and audited on an annual cycle. Regulatory alignment is documented control-by-control.

01 / Information Security

ISO 27001:2022

Information-security management system. Audited annually by an independent third party. Covers risk management, access control, incident response, and continuous improvement.

Audit cycle
Annual
Scope
All Stakater operations
02 / Quality Management

ISO 9001:2015

Quality-management certification governing service delivery, operational processes, and customer support. Maintained continuously across all of Stakater.

Audit cycle
Annual
Scope
Service delivery & support
03 / Regulatory Alignment

GDPR · DORA · NIS2

EU data residency by default, financial-services resilience controls aligned to DORA, and security obligations under NIS2 for critical-infrastructure operators.

EU residency
Default
Documentation
On request
04 / Partnership

Red Hat Premier Partner

Premier Partner status plus the Container Management Specialist credential — the highest partnership level for OpenShift operations.

Tier
Premier
Specialism
Container Mgmt
Shared responsibility

Who owns what.

The boundary between Stakater's platform responsibility and your application responsibility is explicit, documented, and never a surprise on an audit call.

We secure the platform: the cluster, nodes, networking, storage, and managed services. You secure what runs on it: your code, your data policies, your user accounts.

You own
3 lines
Your application code YOU
Your data & access policies YOU
Your user accounts & IAM YOU
↕ boundary
Stakater owns
6 lines
Platform tools (ArgoCD, Vault, etc.) STAKATER
OpenShift cluster & upgrades STAKATER
Node health & capacity STAKATER
Networking & TLS certificates STAKATER
Storage & managed databases STAKATER
Physical infrastructure & DC STAKATER
Regulated industries

One platform. Three regulatory cases.

Documentation and operating posture tailored to whichever framework governs your workload.

01 / DORA

Financial services

ICT risk management, resilience testing, and incident reporting for banks and financial institutions operating in the EU.

02 / GDPR

Healthcare

EU deployment option for patient and health data, access controls, and audit logging for healthcare providers.

03 / NIS2

Critical infrastructure

Security measures, incident detection, and response procedures for essential-service operators under NIS2 obligations.

Documentation

What we can hand to your legal team.

Bring your compliance officer to the call. We'll walk through the shared-responsibility model, DPA terms, and framework-specific obligations in detail.

Request Documentation →
  • ISO 27001:2022 and ISO 9001:2015 certificates
  • Data Processing Agreement (DPA)
  • Security questionnaire responses
  • Shared responsibility model documentation
  • Incident response process documentation

Bring your compliance officer to the call.

Book a 30-minute call. We'll walk through certifications, DPA terms, and the specific obligations that apply to your workload.