Security built into the platform — not bolted on top
THE LAYERS
Five layers that each have to hold on their own
Physical
Network
Platform
Access
Jurisdiction
DEFENCE IN DEPTH
Security at every layer, not only at the perimeter
A single control point is not security. Edora Cloud is protected in layers: physical access to the sites, a closed optical network with no transit across the public internet, the platform’s own access control and logging, and a European jurisdiction that determines who can demand access to data at all.
AUDIT
Audited today — and moving towards more
Edora Cloud is audited under ISAE 3402 Type 2 and ISAE 3000, and the platform is built to the principles of ISO 27017, ISO 27018 and ISO 22301. ISO 27001 certification is planned for the fourth quarter of 2026.
NIS2 · DORA · GDPR
We deliver the foundation — not a rubber stamp
No supplier can make an organisation NIS2-, DORA- or GDPR-compliant; the responsibility belongs to the organisation itself. What Edora delivers is the technical foundation and the documentation that supports your work: European jurisdiction, access control, logging, an audit basis and the option to audit us. That makes the requirements easier to meet and to document.
JURISDICTION
The most important access control is legal
Technical security protects against unauthorised access. But who can lawfully demand access to data is determined by jurisdiction. Because Edora is European-owned and European-operated — 100% Danish-owned and subject to Danish and EU law — and does not rest on infrastructure governed by non-EU legislation, your data is not exposed to access by non-EU authorities. That is a security guarantee technology alone cannot provide.
CONTINUITY
Resilience from distribution, not from one hardened point
Edora’s infrastructure is distributed across several locations, and workloads can run across them. If one location fails, operations can continue elsewhere. The resilience comes from the distribution, not from concentrating everything in one strong place that then becomes a single point of failure.
QUESTIONS & ANSWERS
What security and compliance leads ask about
Is Edora Cloud ISO 27001 certified?
ISO 27001 certification is planned for the fourth quarter of 2026. Today the platform is audited under ISAE 3402 Type 2 and ISAE 3000, and it is built to the principles of ISO 27017, 27018 and 22301.
Where is our data held?
Under European jurisdiction, in Danish facilities, connected via Edora's own closed fibre network. Data does not leave the network in transit.
Who can access our data?
Access is controlled and traceable at platform level. And because Edora is European-owned and European-operated, your data is not subject to access demands under non-EU legislation.
Can you support NIS2 and DORA?
We deliver the technical foundation and the documentation that supports your work. Compliance itself is your responsibility, but we make it easier to meet and to document.
How can public-sector organisations procure Edora?
In Denmark, Edora is available via the SKI framework agreements — SKI 02.22 and SKI 02.17, depending on the organisation and the procurement need. Outside Denmark we contract directly or through local partners.