Compliance & privacy
Client data. Handled with intent.
Ermetia designs every platform deployment around how your data is collected, routed, stored, and protected — not around badge lists on a landing page.
Data handling
Cloud where needed. Private where it matters.
Only what the platform must run in cloud stays there. The rest is classified and routed automatically to Ermetia-owned private servers — encrypted, controlled, and never left on generic paths by default.
- Cloud for edge, orchestration, and shared services — not your full operational record
- Sensitive workloads moved to private infrastructure without manual handoffs
- TLS on every connection. Security built in, not added at go-live
Infrastructure
Cloudflare Deal — May 2026
Since May 2026, Ermetia partners with Cloudflare. Every deployment — live today, in release, or on the roadmap — runs behind the same edge: DDoS protection, encrypted routing, and a unified security layer you do not have to configure yourself.
- Edge protection on all Ermetia-managed services
- One standard from production through what we ship next
Regional frameworks
Compliance reference.
Select a framework to see how Ermetia applies it in client deployments and links to official guidance and consumer rights resources.
Ermetia documents lawful basis, supports data processing agreements, and implements access, rectification, erasure, restriction, and portability workflows for platforms serving EU and UK clients.
Official guidance & rights
As a Swiss-headquartered software house, Ermetia aligns client deployments with the revised FADP (nDSG): transparency, purpose limitation, data security, and documented cross-border transfer mechanisms.
Official guidance & rights
For US enterprise accounts, Ermetia supports CCPA/CPRA readiness: disclosure of categories processed, consumer access and deletion requests, and opt-out of sale/sharing where applicable in platform design.
Official guidance & rights
Ermetia applies PIPEDA-aligned practices for Canadian clients: consent where required, limited collection, safeguards, openness, and individual access — documented in deployment architecture and support runbooks.
Official guidance & rights
Deployments for Australian organizations follow APP obligations: transparent handling, secure storage, access and correction rights, and procedures aligned with the Notifiable Data Breaches scheme.
Official guidance & rights
For Japan-market deployments, Ermetia addresses APPI requirements on purpose specification, security control measures, and cross-border transfer rules — integrated into platform architecture and client documentation.
Official guidance & rights
Clinical & Pharma modules are designed with HIPAA-ready controls: access logging, encryption, minimum necessary access patterns, and audit trails. Business associate agreements and environment isolation are scoped per engagement.
Official guidance & rights
Ermetia engineering follows SOC 2 aligned practices across security, availability, and confidentiality — change control, monitoring, incident response, and vendor review — even where formal attestation is scoped to specific client environments.
Official guidance & rights