top of page
add_aw_logo_white [Konvert].png

Operations and Security

Full control of operations, security, and compliance

Utsikt över centrala Stockholm

Reliable operations with full control in Sweden

Each customer gets a dedicated database, and we run all operations in Sweden. We store data in Microsoft data centres and back it up every night. We retain daily backups for at least 3 months and weekly backups for at least 2 years, which ensures you can always restore information when needed. You get a stable operating environment that provides security and long term access to your organisation’s data.

Over 99,9%
availability

Add delivers a stable and reliable operating environment that ensures you always access the platform when you need it. Robust infrastructure, continuous monitoring, and proactive prevention work create this high availability.

Always see who did what and when

Add logs all activity automatically and stores it continuously, and administrators can read it directly in the interface. You get full traceability for changes, login attempts, and permission updates. The database protects the logs and nobody can tamper with them. Only authorised users can view the logs in Add, and Add also collects the information in a user log where you can follow up all activity. Microsoft Azure also provides complete logging in the operating environment. This creates transparency
and security in daily work and during audits.

Always prepared
for operational disruptions

Add runs under 24 7 monitoring so you can detect and manage disruptions quickly. External and internal systems trigger alerts when deviations occur, for example if a service becomes unavailable or if someone attempts an intrusion. If an attack occurs, protective measures can shut down the platform to reduce the risk of spread. We continuously track availability statistics to secure stable operations. We prioritise critical incidents and resolve them immediately, and we can deploy important bug fixes between releases to protect your organisation quickly.

A scalable platform that grows
with your organisation

Add adapts to your organisation’s needs. The platform runs in a fully scalable environment that you can expand instantly when needed, and it ensures high performance even under heavy load. You secure speed and availability in everyday work and during peak periods.

Quality assurance
in development

We develop Add with security as a priority. We plan, review, and test every new release against OWASP Top 10 to minimise risk. We implement improvements systematically based on ISO 27001, and we apply the four eyes principle in both development and testing. This approach strengthens Add continuously and ensures it meets high requirements for security and quality.

GDPR secure handling of all data

Add complies with applicable data protection legislation. We sign a data processing agreement with every customer, and each customer receives a dedicated database for increased security. Only in specific cases can an authorised support person receive temporary access. If you suspect an incident, you can follow established routines for remediation and reporting within 72 hours, which ensures Add meets GDPR and the requirements from the Swedish Authority for Privacy Protection.

Meets the
NIS2 Directive

Add supports your organisation in meeting the requirements of the NIS2 Directive in a secure way. We maintain routines to detect, report, and manage security incidents during and outside office hours. Continuous monitoring, logging, and structured processes ensure you can handle incidents immediately and report them to the right authorities on time.

The right information to
the right person

You can control all access in Add with high precision. You can link permissions to roles, organisational units, user groups, or for example project affiliation. You can also control access at information level, from reading and editing to creating, archiving, or translating. You gain full control of who accesses what, which creates security and flexibility in daily work.

ISO 27001 Certified for your peace of mind

Add is certified according to ISO 27001, the international standard for information security. This certification confirms that we work systematically to protect information, manage risks, and ensure secure practices across the development, operation, and maintenance of our platform. For you, this provides added confidence that information security is embedded throughout both our platform and the way we work.

informationssäkerhetspolicy.png
informationssäkerhetspolicy.png

Information security policy

Scope This policy defines the purpose, direction, principles, and basic rules for the information security management system (ISMS) at Addsystems. General objectives Addsystems strives to minimize the risk of security incidents and ensure that internal and client data is managed in a secure manner. We preserve confidentiality, integrity, and availability through a structured risk management process and by meeting all legal, regulatory, and contractual requirements.Addsystems conducts long-term and systematic information security work based on ISO 27001. We follow up on information security performance by reporting deviations, managing deficiencies, assessing risks, and reporting incidents to relevant authorities when required. Our goals and activities are defined using updated analyses of interested parties and risk assessments and by using a SWOT. Goals •The information at Addsystems including client data is protected at an appropriate administrative and technical level, based on completed information security classifications and risk analyses. •To be an organization with a clear division of responsibilities for information resources and with relevant roles for management and implementation of systematic information security work. •All employees must be familiar with this policy and thereby be observant on risks, suggest improvements, in combination with seeking necessary information to live up to this policy. The company will provide relevant training on fixed intervals for all employees. The CEO must ensure that sufficient resources are available to maintain and improve the ISMS. Responsibility The Management Team is accountable for the ISMS and must annually review this policy, evaluate objectives, and ensure that internal audits are conducted. The ISMS Steering Committee is responsible for decisions related to significant changes to the ISMS.The ISMS Team coordinates the ongoing operational work.

bottom of page