Information security is central at Toolsfactory. As a developer of software for strategic planning and steering, we know what our customers’ data is worth. An OGSM is not just a document: it says what an organization is choosing and what it is giving up to do it.
So we take extensive measures to safeguard three things:
- Availability. Information and systems are available when you need them.
- Integrity. Information is accurate, complete and unaltered.
- Confidentiality. Only authorised people have access.
Toolsfactory is ISO 27001:2022 certified, the globally recognised standard for information security.

Risk management and continuous improvement
We take a structured approach to identifying, assessing and controlling risks:
- An annual risk assessment and evaluation
- Mitigating measures for the risks we find
- Continuous monitoring
We do that with our own method of doing, learning and adjusting: a monthly action review and a quarterly strategy review in which we evaluate progress and reset priorities. Security is not a project that finishes; it is one of the things on our own plan.
People: from weakest to strongest link
Technical measures are necessary. We use multi-factor authentication wherever we can, and everyone has a password manager with automatically generated, unique passwords.
But people are often the weakest link: someone clicks the wrong link or shares the wrong screen. So we invest heavily in awareness among staff, partners and users. That keeps us alert to the risks, and also to the chances to do better. Together we turn people into the strong link instead.
Secure software development
Security plays a large part in how we develop. We build with the OWASP Top 10 as our guide, the overview of the ten most critical security risks for web applications, and we have both automated and manual test procedures.
We apply updates to the systems and modules we use as quickly as we can. And we have external experts check the security with a penetration test on a regular basis.
Using it securely
Our software is protected with a unique username and password. We encourage customers to use multi-factor authentication or to connect the environment to Microsoft Entra ID (formerly Azure AD).
Clear roles are defined inside the platform, so you decide who may see and edit what. The connection is always encrypted.
Secure hosting
We host on servers in the Netherlands, with our supplier Tilaa B.V. They are certified to ISO/IEC 27001:2022, ISO/IEC 9001:2015, PCI-DSS 3.2, NEN 7510:2017 and ISAE 3402 Type I. The data on those servers is encrypted.
We continuously monitor availability and performance, and we get an automatic alert when something is wrong. Current availability is at status.ogsm.online.
Backup
Despite every measure, something can go wrong once. So we make daily backups. We store them on a different server, still within the EU, and keep them for thirty days. We check the backup procedure regularly.
Privacy and GDPR
We take the protection of personal data seriously and collect as little as we can. Take this website: it does not set a single cookie. Which is why you do not see a cookie banner here.
We comply with the General Data Protection Regulation. We have data processing agreements with suppliers that process personal data, and we make sure data is removed from our systems on time.
See also our privacy statement.
Questions
Do you have questions about our information security policy, or a security questionnaire that needs filling in? Email info@toolsfactory.nl. We fill those in properly rather than pointing you at a PDF.