Security and Operations

Security and Operations

Last updated: 19. juli 2026

Read about the technical and organisational measures that ensure stable operations and protect customer data.

This is an English translation provided for convenience. The Danish version is the legally binding document; in case of any discrepancy, the Danish text prevails.

Security is a top priority in everything Webits ApS ("Webits", "we", "us") delivers. This policy describes the technical and organisational measures we have implemented to ensure reliable operations and protection of our customers' data, as well as how we monitor, maintain and handle security incidents.

This policy must be read together with our terms of business (in particular clause 11 on security and operations), our cookie and privacy policy and our data processing agreement.

1. Security measures

Information security programme

We operate a structured information security programme (ISMS) that forms the framework for our work on information security. The programme follows the principles of the international standard ISO 27001, and our efforts are prioritised on the basis of a continuously updated risk assessment that forms the core of the programme. We have defined a set of policies, procedures and standards for how we run the business and safeguard our customers' data, and these documents are updated on an ongoing basis as the threat landscape changes.

Roles and responsibilities

Webits' responsibility. Webits is responsible for the security of the underlying platform and infrastructure on which the services are delivered, and for implementing and maintaining the technical and organisational measures described in this policy — including network and access security, monitoring, backup of our infrastructure, and the handling of security incidents. Overall responsibility for information security rests with Webits' management.

Responsibility is anchored internally through clear roles: a security officer is responsible for implementing and maintaining the information security programme, an internal audit function regularly reviews our security setup and reports to management, and internal legal expertise in personal data ensures that personal data is processed correctly — both internally and on behalf of our customers.

The customer's responsibility. The customer is responsible for the security of its own data, applications and user accesses, including for protecting passwords, keeping its own content and software up to date, and taking regular backups of its own data, cf. clauses 9 and 11.3 of the terms of business. The more detailed division of responsibility between Webits and the customer is otherwise set out in the terms of business.

Personnel security

All employees and consultants with access to systems and facilities are subject to our security policies and are bound by a duty of confidentiality. They undergo mandatory security and privacy training at the start of employment and on an ongoing basis throughout employment, so that they are equipped to withstand current threats. We also encourage employees to continuously maintain and expand their competencies within security and networking.

Physical security

Our production environment is located primarily in data centres in Denmark and otherwise within the EU/EEA. A few subcontractors process data outside Denmark — an overview of locations is set out in our data processing agreement. The data centre providers are responsible for the physical facilities such as power, cooling, fire suppression and access control, and we continuously verify that our subcontractors comply with the applicable security requirements.

Network

Our network is segmented so that customers are protected from one another and from threats moving laterally across the network. Next Generation firewalls limit attacks against customer environments, and DDoS protection reduces the impact of any attacks. Advanced network inspection detects patterns and attack attempts from known malicious IP addresses and alerts our operations department when necessary.

Logical accesses

We work according to the principle of least privilege and grant permissions only to the employees who need them. Accesses are reviewed on an ongoing basis, and only specially privileged employees have access to administer internal systems.

Backup

We take daily backups of all servers. Backup data is mirrored between two physically independent locations, so that an available copy always exists in the event of a critical failure, and at least one copy is kept in a data centre without production data. The daily backup safeguards data in the event of a full server failure and is not intended for restoring an individual customer's data — it is therefore incumbent on the customer to take regular backups of its own data. The specific backup level for each service is set out in the agreement entered into (SLA). Restoration or transmission of a backup may be carried out against payment.

2. Monitoring and maintenance

Monitoring and logging

We monitor our infrastructure and relevant services around the clock and have an associated 24/7 on-call arrangement. We log all accesses to management and customer environments, which ensures integrity and traceability and makes it possible to correlate events. A central log platform ensures that we can quickly correlate logs from many sources, and all anomalies are recorded in our incident management system.

Operational stability

We strive for the highest possible operational stability. Webits is, however, not liable for downtime or operational disruptions caused by factors outside our control, including power failures, equipment faults, and faults in internet and telecommunications connections. The services are provided as is and as available. In the event of downtime, we strive to restore normal operations as quickly as possible.

Planned maintenance

Planned interruptions are, as far as possible, placed within the time window 21:00–06:00 (CET). Necessary interruptions outside this time window are announced to the greatest extent possible.

Penetration testing and vulnerability management

We regularly perform penetration tests against critical components of our infrastructure to assess how the systems withstand external threats, and we handle identified vulnerabilities according to their severity. Customers may perform penetration tests against their own systems subject to prior written agreement with us.

Management of subcontractors

For selected services we use subcontractors. Where a subcontractor may affect our security environment, we ensure — through contracts, data processing agreements, audit reports, self-assessment and confidentiality agreements — that the subcontractor complies with the same strict requirements as we do ourselves, and we continuously verify that the requirements are met. An overview of our data processors is set out in our data processing agreement.

Compliance and standards

We work according to a compliance programme that supports our compliance with recognised standards, internal policies and relevant legislation. Our security and operations work is arranged so that it meets the principles of, among others:

  • ISO 27001 — international standard for information security management.
  • ISAE 3402 — recognised framework for the description and control of the services we deliver to customers.
  • PCI DSS — security requirements for handling payment card data in our payment card environment.
  • Danish Cloud Community (DCC) — minimum requirements for good hosting in terms of quality, stability, transparency and control.

3. Handling of security incidents

Contingency and disaster recovery

We have contingency plans that set out our procedures, routines and roles in the event of incidents with a critical or catastrophic impact on operations. Employees are trained in the contingency arrangements several times a year. To spread the risk of critical failures, we use several independent data centre providers and always keep at least one copy of backup data in a data centre where we hold no production data.

Incident management

Security incidents are recorded, categorised and handled in our incident management system. Our operations and security functions assess the severity of the incident, initiate the necessary measures to contain and remedy it, and subsequently carry out a follow-up with a view to preventing recurrence.

Notification of personal data breaches

If we identify a personal data breach affecting personal data we process on behalf of a customer, we notify the customer concerned without undue delay, so that the customer, as data controller, can fulfil its obligations under the GDPR — including any notification to the Danish Data Protection Agency (Datatilsynet) within 72 hours and notification of the affected data subjects. The more detailed terms in this regard are set out in our data processing agreement. For personal data where Webits is itself the data controller, we carry out the necessary assessments and notifications in accordance with the GDPR.

Publisher

The website is owned and published by:

Webits ApS CVR number: 41336404 Fadet 43 st. tv. 1799 København V

Telephone: +45 44 14 44 30 Email: info@webits.dk

Chief Executive Officer: Martin Bennetzen

Ready to make IT something you never have to think about?

Tell us about your challenge — we'll get back to you with a concrete proposal for a solution.