Our approach to compliance
Our approach is built around ISO 27005 and its risk assessment process, where our people, processes and technology are continuously prioritised and hardened based on the risk they pose.
Penetration tests
External cyber professionals regularly conduct penetration tests on Scalepoint’s networks and solutions. They analyse vulnerabilities related to the most critical attacks that occur at a specific time. Test results can be shared if requested.
Incident response 24/7
Our Incident Response Team monitors potential cyber security breaches 24/7. The team handles technical incidents as well as incidents where privacy legislation dictates that specific steps must be taken.
Employee training
All Scalepoint employees are continuously trained in data security and GDPR. Relevant functional areas also receive training in performing their controls correctly and designing solutions in a safe and GDPR-compliant manner.
ISAE 3402 and 3000
We prepare ISAE 3402 and ISAE 3000 audit reports through an independent audit firm. The reports provide security for the design, implementation, and administration of our internal controls regarding data security and privacy.
DORA compliance – integrated into your insurance solution
The DORA regulation has come into force – and we help insurance companies subject to the rules meet the requirements with our solutions. This includes enhanced security measures, incident response capabilities, support for customer reporting obligations, improved resilience in case of IT disruptions, and the ability to pass on compliance requirements to subcontractors. With Scalepoint, you get a solution where DORA compliance is built in from the ground up – not something added as an afterthought.

ISO 27001 and 27002
We have implemented an Information Security Management System in accordance with ISO/IEC 27001 to ensure that appropriate controls are in place to manage current and future risks. The controls are continuously reviewed by our internal second line of defense functions as well as external auditors.
Dedicated risk and compliance team
We have established clear lines of defense that meet industry requirements. We continuously train and certify our employees in all areas of defense. Our certifications include:

Our compliance partnerships

OneTrust
We have partnered with OneTrust, a leading provider of privacy management solutions.

EcoVadis
We use the world’s largest and most trusted provider of CSR ratings for our annual survey.

Got Ethics
We use Got Ethics, part of the EQS Integrity Line Group, one of the most popular whistleblower suppliers in Europe.
Explore our solutions

Scalepoint CORE
A complete and intuitive core system (PAS), which digitises all policy and claims processes and can easily be customised to your business.

Scalepoint ClaimShop
Settle content claims and help your customers replace, repair or valuate lost or damaged items within minutes.

Scalepoint HUB
Automate repair processes for motor, property, and clinical workflows for health. Leverage a robust ecosystem of claims suppliers and settlement tools, offering online access to service partners and end-customers.
See our solutions in action
Book a demo and discover how we can automate your insurance processes.
