Security, compliance and data protection.
Technical and organisational measures aligned with GDPR, applied on certified infrastructure (Microsoft Azure). Below: precisely what we implement, and where the limits are.
CIBINNO applies technical and organisational measures aligned with GDPR. We do not currently hold ISO certifications of our own; the infrastructure we run on is provider-certified (Microsoft Azure).
Security & compliance
Full access journal — every request is logged (user, IP, route, status, module), searchable, with 90-day retention.
Automatic attack detection and blocking — vulnerability scans (.env, .git, wp-admin) are auto-blocked, with real-time alerts.
Anti-brute-force login protection — repeated attempts trigger alerts and temporary IP blocking.
Role-based access (RBAC) and need-to-know — personal connection data is not visible by default to other users.
Emergency kill-switch (panic mode) — access can be blocked instantly, partially or fully, with automatic recovery after 2 hours.
Encryption in transit (HTTPS/TLS) and at rest; sensitive data (tokens, IBANs) additionally encrypted at the application level.
Continuous uptime and security monitoring, with an internal access dashboard (journal, threats, blocked IPs).
Security breach notification to clients within 48–72 hours (standard DPA contractual term).
GDPR & data protection
Data controller: CIBINNO CONSULTING S.R.L. Data protection contact point: contact@cibinno.ro.
Legal bases: legitimate interest (commercial outreach), contract performance (support), explicit consent (Open Banking / PSD2).
Data minimisation — we collect only what the purpose strictly requires. No profiling and no automated decisions with legal effects on individuals.
Processing within the European Economic Area. Banking data is NOT sent to external AI models.
Data subject rights: access, rectification, erasure, restriction, objection, portability, consent withdrawal — at contact@cibinno.ro. One-click unsubscribe.
Retention and erasure — data is kept until the purpose is met or objection; for Open Banking, limited consent (usually 90 days) with re-authorisation and irreversible deletion on request.
Traceability — every relevant operation (connect, sync, re-authorise, delete) is recorded in an audit journal.
Right to complain to the supervisory authority (ANSPDCP, dataprotection.ro).
AI governance
An internal AI policy applied uniformly across every platform — the same rules regardless of model provider, plus dedicated AI clauses in client contracts.
A defined role under the AI Act: for each AI-backed function we establish whether we act as provider or deployer, along with the obligations that follow.
Every conclusion carries its evidence — quote and source. Where data is missing the system answers "unknown" explicitly instead of estimating; we don't produce figures without a document behind them.
Authority limits per function: what the system decides on its own and what it must escalate to a responsible person are defined in advance, not left to the model's discretion.
Human in the loop for decisions with financial or legal effect — AI prepares, proposes and argues; a person always approves.
An audit trail on every AI operation: what was asked, which model answered, which source it relied on, who validated it.
The kill-switch covers AI components too — they can be stopped instantly, separately from the rest of the application.
Banking data and sensitive personal data are NOT sent to external models. AI processing runs in an EU region.
Continuous regulatory monitoring (AI Act, GDPR, NIS2, DORA) — legislative changes are tracked automatically and turned into tasks with deadlines.
EU hosting
Microsoft Azure infrastructure, in European Union data centres (West Europe / Sweden Central).
The AI component uses Azure OpenAI Service in an EU region — data stays within European jurisdiction.
Email and productivity via Microsoft 365 and Azure Communication Services, processed within the EEA.
Encryption at rest via Azure; TLS terminated at ingress (end-to-end HTTPS).
Regular off-site backup — daily copies, typical 30-day retention, plus an off-site copy of critical data.
Active Disaster Recovery — automated daily checks and periodic restore drills, with verified Azure restore points.
Fast rollback to a previous stable version in case of a deploy incident.
CIBINNO CONSULTING S.R.L. · VAT RO51836516 · J2025036544005 · Str. Vatra Dornei nr. 3, Pantelimon, Ilfov · data protection: contact@cibinno.ro · Supervisory authority: ANSPDCP (dataprotection.ro)
See your company as you've never seen it: live.
Enter the full demo or book a 15-minute scoping. No obligations — you leave with a concrete impact estimate.
EU hosting · GDPR · daily backup · role-based access