DEMONSTRATION LEGAL DATA · Licence XXX-YYY is demonstration data and must be replaced with official evidence before production publication.
Mobile-ID · Digital Trust Platform
ISO/IEC 27001:2022Security policyService policyService status
POLICY PUBLICATION

Trusted Delivery Security Policy

This online publication describes information-security controls, risk management and protection of the service infrastructure.

StatusPublished summaryVersion1.0-summaryUpdated2026-08-04OwnerMobile-ID Trust Services Team
This publication provides website transparency and does not replace a formally approved policy or practice statement.
01

Objectives and scope

Protect confidentiality, integrity and availability of systems, data and evidence within the published scope.

02

Risk management

Identify, assess, treat and monitor risk on a recurring basis, prioritizing controls by impact and likelihood.

03

Access and identity controls

Role-based access, least privilege, strong authentication and periodic access reviews.

04

Cryptography and key management

Sensitive keys are lifecycle-managed with separation of duties and HSM use where required.

05

Monitoring and incident response

Logging, alerting, incident classification, investigation, remediation and notification follow defined procedures.

06

Business continuity

Contingency, backup, recovery and periodic testing support approved service-continuity objectives.

CLAIM CONTROL

Approved wording and interpretation limits

Approved

Mobile-ID applies risk-based information-security controls, access management, cryptographic protection, monitoring and continual improvement within the published management-system scope.

Prohibited

Absolutely secure; impossible to attack; 100% safe; data can never be lost.