{"id":2682,"date":"2026-08-11T13:55:28","date_gmt":"2026-08-11T11:55:28","guid":{"rendered":"https:\/\/staging.elyxion.eu\/?page_id=2682"},"modified":"2026-08-13T10:44:13","modified_gmt":"2026-08-13T08:44:13","slug":"security-overview","status":"publish","type":"page","link":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/","title":{"rendered":"Security Overview"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><div class=\"vc_row wpb_row top-row porto-inner-container wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f\"><div class=\"porto-wrap-container container\"><div class=\"row\"><div class=\"vc_column_container col-md-12\"><div class=\"wpb_wrapper vc_column-inner\"><div class=\"vc_empty_space\"   style=\"height: 50px\"><span class=\"vc_empty_space_inner\"><\/span><\/div>\r\n\t<div class=\"wpb_text_column wpb_content_element wpb_custom_7c91d232724f73626cc933bd95b25ff0\" >\r\n\t\t<div class=\"wpb_wrapper\">\r\n\t\t\t<h2><span style=\"font-size: 20px;\">1. Security Philosophy<\/span><\/h2>\n<p><strong>elyXion<\/strong> designs and operates services using risk-based security, least privilege, defence in depth, secure defaults, separation of duties where practical, and continuous improvement. We draw on Microsoft security guidance, Zero Trust concepts, cloud well-architected practices, and recognised industry controls where relevant.<\/p>\n<p>Alignment is not certification. <strong>elyXion<\/strong> does not claim <span style=\"color: #ff0000;\">ISO 27001, SOC 2, NEN 7510<\/span>, Cyber Essentials, Microsoft Solutions Partner, or other certification unless a future statement names the certified entity, scope, auditor, and validity.<\/p>\n<h2><span style=\"font-size: 20px;\">2. Shared Responsibility<\/span><\/h2>\n<p><strong>Security responsibilities vary:<\/strong><\/p>\n<ul>\n<li>Microsoft secures its cloud platform according to its service model.<\/li>\n<li>elyXion secures systems and activities within its contracted control.<\/li>\n<li>Customers secure their users, business processes, data decisions, endpoints, approvals, and responsibilities retained in the service description.<\/li>\n<\/ul>\n<p>The Order Form and architecture should make this allocation explicit.<\/p>\n<h2><span style=\"font-size: 20px;\">3. Governance and Risk<\/span><\/h2>\n<p><strong>elyXion<\/strong> intends to maintain security ownership, policies, asset and supplier awareness, risk assessment, exception handling, and periodic management review. Risks are prioritised by likelihood, impact, exposure, and service criticality.<\/p>\n<h2><span style=\"font-size: 20px;\">4. Identity and Access<\/span><\/h2>\n<p><strong>Controls may include:<\/strong><\/p>\n<ul>\n<li>Microsoft Entra ID or another approved identity provider;<\/li>\n<li>Multi-factor authentication for privileged and remote access;<\/li>\n<li>Role-based access and least privilege;<\/li>\n<li>Separate privileged identities where proportionate;<\/li>\n<li>Conditional Access based on service and risk;<\/li>\n<li>Joiner, mover, leaver processes;<\/li>\n<li>Periodic access and service-principal review; and<\/li>\n<li>Time-bound or approval-based privileged access where available.<\/li>\n<\/ul>\n<p>Customer tenant access should use delegated, auditable methods rather than shared credentials where technically possible.<\/p>\n<h2><span style=\"font-size: 20px;\">5. Device and Workplace Security<\/span><\/h2>\n<p><strong>elyXion<\/strong> -managed endpoints should use supported operating systems, encryption, screen lock, malware protection, patching, and central management appropriate to risk. Personnel must protect devices, report loss promptly, and avoid local storage of Customer Data unless needed and authorised.<\/p>\n<h2><span style=\"font-size: 20px;\">6. Network and Infrastructure Security<\/span><\/h2>\n<p>Architecture may use segmentation, firewalls, security groups, private connectivity, restricted management interfaces, web application firewalls, DDoS protections, hardened images, and secure administrative paths. Actual controls depend on the hosted design.<\/p>\n<h2><span style=\"font-size: 20px;\">7. Secure Delivery<\/span><\/h2>\n<p>Changes should be traceable, reviewed, tested, approved according to risk, and recoverable. Infrastructure as Code and CI\/CD may improve repeatability. Secrets should use approved vaults and never be committed to source control. Production access and deployment rights should be restricted.<\/p>\n<h2><span style=\"font-size: 20px;\">8. Vulnerability Management<\/span><\/h2>\n<p><strong>elyXion<\/strong> intends to monitor relevant advisories, assess exposure, prioritise remediation, and track exceptions. Timelines depend on severity, exploitability, service criticality, vendor fixes, testing, and Customer approval. Unsupported systems may require compensating controls or retirement.<\/p>\n<p>Independent penetration testing is not implied and should be commissioned according to risk and service maturity.<\/p>\n<h2><span style=\"font-size: 20px;\">9. Logging and Monitoring<\/span><\/h2>\n<p>Security-relevant authentication, administrative action, service health, and application events may be logged. Access to logs is restricted. Retention and alerting vary by service. Monitoring does not guarantee detection of every event and is not 24\/7 unless contracted.<\/p>\n<h2><span style=\"font-size: 20px;\">10. Encryption and Secrets<\/span><\/h2>\n<p><strong>elyXion<\/strong> uses supported encryption for data in transit and platform encryption at rest where available and appropriate. Highly sensitive keys, tokens, and credentials should be held in approved secret stores. Customer-managed keys are available only where designed and contracted.<\/p>\n<h2><span style=\"font-size: 20px;\">11. Data Handling<\/span><\/h2>\n<p>Data should be minimised, classified where required, and kept in approved locations. Production data should not be used in development unless justified, protected, and authorised. Secure deletion follows provider capabilities, retention rules, and backup cycles.<\/p>\n<h2><span style=\"font-size: 20px;\">12. Supplier Security<\/span><\/h2>\n<p>Supplier review considers service criticality, access, data types, contractual safeguards, incident obligations, data location, resilience, and exit. The Subprocessor List addresses providers processing Customer Personal Data.<\/p>\n<h2><span style=\"font-size: 20px;\">13. Incident Response<\/span><\/h2>\n<p>The process covers reporting, triage, containment, eradication, recovery, evidence, communication, privacy assessment, and lessons learned. Customer notification depends on impact, contractual role, and available facts. The DPA governs Customer Personal Data breaches.<\/p>\n<h2><span style=\"font-size: 20px;\">14. Resilience<\/span><\/h2>\n<p>Backups, redundancy, restoration, and continuity arrangements are service-specific. <strong>elyXion<\/strong> distinguishes successful backup jobs from verified recoverability. Recovery objectives apply only where stated and tested.<\/p>\n<h2><span style=\"font-size: 20px;\">15. Personnel<\/span><\/h2>\n<p>Personnel are bound by confidentiality and receive role-relevant security instruction. Background screening, if required, must be specified by role, law, and customer contract; it is not universally claimed.<\/p>\n<h2><span style=\"font-size: 20px;\">16. Customer Assurance<\/span><\/h2>\n<p><strong>elyXion<\/strong> may respond to reasonable questionnaires and provide policies or evidence under confidentiality. It may withhold exploit details, credentials, other-customer information, or material whose disclosure creates risk.<\/p>\n<h2><span style=\"font-size: 20px;\">17. Continuous Improvement<\/span><\/h2>\n<p>Controls evolve with threats, business growth, legal duties, incidents, architecture, and provider capabilities. Material changes to contracted safeguards follow the Agreement and DPA.<\/p>\n\r\n\t\t<\/div>\r\n\t<\/div>\r\n<\/div><\/div><\/div><\/div><\/div><div class=\"vc_row wpb_row top-row vc_custom_1786610644378 vc_row-has-fill porto-inner-container wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f\"><div class=\"porto-wrap-container container\"><div class=\"row\"><div class=\"vc_column_container col-md-6 vc_custom_1786436452278\"><div class=\"wpb_wrapper vc_column-inner\">\r\n\t<div class=\"wpb_text_column wpb_content_element vc_custom_1786446460806 wpb_custom_7c91d232724f73626cc933bd95b25ff0\" >\r\n\t\t<div class=\"wpb_wrapper\">\r\n\t\t\t<table>\n<tbody>\n<tr>\n<td width=\"150\"><strong>Owner:<\/strong><\/td>\n<td width=\"250\">elyXion<\/td>\n<\/tr>\n<tr>\n<td width=\"150\"><strong>Version:<\/strong><\/td>\n<td width=\"250\">1.0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n\r\n\t\t<\/div>\r\n\t<\/div>\r\n<\/div><\/div><div class=\"vc_column_container col-md-6\"><div class=\"wpb_wrapper vc_column-inner\">\r\n\t<div class=\"wpb_text_column wpb_content_element vc_custom_1786446473716 wpb_custom_7c91d232724f73626cc933bd95b25ff0\" >\r\n\t\t<div class=\"wpb_wrapper\">\r\n\t\t\t<table>\n<tbody>\n<tr>\n<td width=\"150\"><strong>Last updated:<\/strong><\/td>\n<td width=\"250\">11 Aug 2026<\/td>\n<\/tr>\n<tr>\n<td width=\"150\"><strong>Status:<\/strong><\/td>\n<td width=\"250\">Draft for legal and operational review<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n\r\n\t\t<\/div>\r\n\t<\/div>\r\n<\/div><\/div><\/div><\/div><\/div><div class=\"vc_row wpb_row row top-row wpb_custom_034b39d9bc6c6b310d69e39f0ccf274f\"><div class=\"vc_column_container col-md-12\"><div class=\"wpb_wrapper vc_column-inner\"><div class=\"vc_empty_space\"   style=\"height: 50px\"><span class=\"vc_empty_space_inner\"><\/span><\/div><div class=\"vc_empty_space\"   style=\"height: 50px\"><span class=\"vc_empty_space_inner\"><\/span><\/div><\/div><\/div><\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"1. Security Philosophy elyXion designs and operates services using risk-based security, least privilege, defence in depth, secure defaults, separation of duties where practical, and continuous improvement. We draw on Microsoft security guidance, Zero Trust concepts, cloud well-architected practices, and recognised industry controls where relevant. Alignment is not certification. elyXion does not claim ISO 27001, SOC [...]","protected":false},"author":1,"featured_media":1195,"parent":2548,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"content-type":"","rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","footnotes":""},"class_list":["post-2682","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Overview | Security Practices | elyXion<\/title>\n<meta name=\"description\" content=\"Learn how elyXion approaches security, including identity and access, infrastructure, vulnerability management, encryption, incident response and resilience.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"nl_NL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Overview | Security Practices | elyXion\" \/>\n<meta property=\"og:description\" content=\"Learn how elyXion approaches security, including identity and access, infrastructure, vulnerability management, encryption, incident response and resilience.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/\" \/>\n<meta property=\"og:site_name\" content=\"elyXion\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-13T08:44:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/staging.elyxion.eu\/wp-content\/uploads\/2026\/07\/elyXion-Feature-Image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/\",\"url\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/\",\"name\":\"Security Overview | Security Practices | elyXion\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/staging.elyxion.eu\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/elyXion-Feature-Image.jpg\",\"datePublished\":\"2026-08-11T11:55:28+00:00\",\"dateModified\":\"2026-08-13T08:44:13+00:00\",\"description\":\"Learn how elyXion approaches security, including identity and access, infrastructure, vulnerability management, encryption, incident response and resilience.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/#breadcrumb\"},\"inLanguage\":\"nl-NL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"nl-NL\",\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/#primaryimage\",\"url\":\"https:\\\/\\\/staging.elyxion.eu\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/elyXion-Feature-Image.jpg\",\"contentUrl\":\"https:\\\/\\\/staging.elyxion.eu\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/elyXion-Feature-Image.jpg\",\"width\":1200,\"height\":800,\"caption\":\"Advancing Intelligence Through Logic and Innovation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/trust-center\\\/security-overview\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Overview\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/#website\",\"url\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/\",\"name\":\"elyXion\",\"description\":\"Advancing Intelligence Through Logic and Innovation to deliver secure, scalable Microsoft solutions, powered by European-owned infrastructure through the elyXion Portal.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/staging.elyxion.eu\\\/nl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"nl-NL\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Overview | Security Practices | elyXion","description":"Learn how elyXion approaches security, including identity and access, infrastructure, vulnerability management, encryption, incident response and resilience.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"nl_NL","og_type":"article","og_title":"Security Overview | Security Practices | elyXion","og_description":"Learn how elyXion approaches security, including identity and access, infrastructure, vulnerability management, encryption, incident response and resilience.","og_url":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/","og_site_name":"elyXion","article_modified_time":"2026-08-13T08:44:13+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/staging.elyxion.eu\/wp-content\/uploads\/2026\/07\/elyXion-Feature-Image.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/","url":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/","name":"Security Overview | Security Practices | elyXion","isPartOf":{"@id":"https:\/\/staging.elyxion.eu\/nl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/#primaryimage"},"image":{"@id":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/#primaryimage"},"thumbnailUrl":"https:\/\/staging.elyxion.eu\/wp-content\/uploads\/2026\/07\/elyXion-Feature-Image.jpg","datePublished":"2026-08-11T11:55:28+00:00","dateModified":"2026-08-13T08:44:13+00:00","description":"Learn how elyXion approaches security, including identity and access, infrastructure, vulnerability management, encryption, incident response and resilience.","breadcrumb":{"@id":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/#breadcrumb"},"inLanguage":"nl-NL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/"]}]},{"@type":"ImageObject","inLanguage":"nl-NL","@id":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/#primaryimage","url":"https:\/\/staging.elyxion.eu\/wp-content\/uploads\/2026\/07\/elyXion-Feature-Image.jpg","contentUrl":"https:\/\/staging.elyxion.eu\/wp-content\/uploads\/2026\/07\/elyXion-Feature-Image.jpg","width":1200,"height":800,"caption":"Advancing Intelligence Through Logic and Innovation"},{"@type":"BreadcrumbList","@id":"https:\/\/staging.elyxion.eu\/nl\/trust-center\/security-overview\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/staging.elyxion.eu\/nl\/"},{"@type":"ListItem","position":2,"name":"Security Overview"}]},{"@type":"WebSite","@id":"https:\/\/staging.elyxion.eu\/nl\/#website","url":"https:\/\/staging.elyxion.eu\/nl\/","name":"elyXion","description":"Advancing Intelligence Through Logic and Innovation to deliver secure, scalable Microsoft solutions, powered by European-owned infrastructure through the elyXion Portal.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/staging.elyxion.eu\/nl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"nl-NL"}]}},"_links":{"self":[{"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/pages\/2682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/comments?post=2682"}],"version-history":[{"count":7,"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/pages\/2682\/revisions"}],"predecessor-version":[{"id":2825,"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/pages\/2682\/revisions\/2825"}],"up":[{"embeddable":true,"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/pages\/2548"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/media\/1195"}],"wp:attachment":[{"href":"https:\/\/staging.elyxion.eu\/nl\/wp-json\/wp\/v2\/media?parent=2682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}