Since 1988The Axional family — ERP, WMS, HIS — engineered as a family on the Airtool platform underneath.Explore Axional
Set hero background image Click to upload — server adds <media type="image" src="…"/> as a child of <hero>, switching this page to the full-bleed dark variant. Recommended : 1920 × 1080 px (16:9)
Formats : PNG · JPEG · WebP · SVG
Off-spec uploads are rejected — aspect ratio outside 16:9 ±2 %, dimensions outside 800 × 450 … 3840 × 2160.
Trust

Independently certified. Continuously audited. Operationally accountable.

Two formal certifications — ISO/IEC 27001:2023 and the Spanish National Security Framework at MEDIUM level. Quarterly external infrastructure audits by an independent Spanish security operations centre. Customer data hosted in named EU facilities. The evidence behind every claim is on file and available under NDA.

ISO/IEC 27001:2023

Information Security Management System. Issued by ADOK Certificación. Certificate 044807, valid through 15 July 2028. Scope covers On-Premise, SaaS and Cloud hosting of Axional services.

ENS — National Security Framework, MEDIUM

Real Decreto 311/2022. Confidentiality, integrity, traceability, authenticity and availability all rated Medium. 63 distinct controls. Certificate 624807, valid through 12 January 2027.

Quarterly external audits

Independent infrastructure audit by mdtel / SECUNIT, a Spanish security operations centre. Network exposure, TLS posture, web surface and operational hygiene re-tested every quarter.

EU data residency

Production hosting in named Atlas Edge facilities in Barcelona and Madrid. Spain-only data residency available for public-sector and regulated healthcare workloads.

Compliance

The formal frameworks the certified scope operates under. The two certified standards link to the signed certificate; the two statutory regimes describe deister software's posture as data processor.

ISO/IEC 27001:2023

Certified. ADOK Certificación, certificate 044807, valid through 15 July 2028.

ENS Medio

Certified. Real Decreto 311/2022, certificate 624807, valid through 12 January 2027.

GDPR

Compliant. Regulation (EU) 2016/679. Customer personal data processed as a processor under contract. DPA available on request from dpo@deister.es.

Spanish LOPDGDD

Compliant. Organic Law 3/2018 on personal data protection and digital rights. Supervised by the Agencia Española de Protección de Datos (AEPD).

ISO/IEC 27001:2023 — Information Security Management

deister software operates an Information Security Management System certified against the current edition of the international standard, UNE-ISO/IEC 27001:2023. The certification was awarded by ADOK Certificación, S.L., a Spanish certification body accredited under ISO 17065.

Scope, as printed on the certificate (verbatim, Spanish): "Los sistemas de información que dan soporte a los servicios Axional de deister software en sus modalidades On Premise y Saas, así como la gestión del alojamiento Cloud según la declaración de aplicabilidad 2025_V6."

English translation: the information systems that support the Axional services in their on-premise and SaaS modalities, together with the management of the cloud hosting environment, in accordance with the 2025_V6 Statement of Applicability.

Coverage. Grupo deister software — six legal entities operating across Spain and Peru: deister software Consulting, deister software Tech Services, deister software S.A., deister software Cloud, deister software S.A. Sucursal Perú and deister software Software Perú. Operational sites under the certificate: Barcelona (Sant Pere Claver), Madrid (Edificio Baluarte), Girona (Bernat Boades) and Lima (Javier Prado Este).

Reference data. Certificate number 044807 · awarded 16 July 2025 · valid through 15 July 2028 · Statement of Applicability 2025_V6. The signed certificate and the annex listing every covered entity are available under NDA on request.

ENS Medium — Spanish National Security Framework

The same information systems are certified under the Spanish National Security Framework (Esquema Nacional de Seguridad) established by Real Decreto 311/2022. The certification is at MEDIUM level, awarded by ADOK Certificación under ENAC ISO 17065 accreditation nº 242 / C-PR473.

Security dimensions. All five ENS dimensions are rated Medium: confidentiality, integrity, traceability, authenticity and availability. Sixty-three distinct security controls are implemented and verified.

Scope. The same Axional service surface as the ISO 27001 certificate — on-premise, SaaS and managed cloud hosting — under the current Statement of Applicability.

Why this matters. ENS Medium is the qualifying threshold for Spanish public-sector procurement and for most autonomous-community healthcare and education buyers. Vendors who lack this certification do not pass intake.

Reference data. Certificate number 624807 · awarded 13 January 2025 · valid through 12 January 2027 · issued in Bilbao on 5 March 2025. The signed certificate is available under NDA on request.

External infrastructure audits

Quarterly external infrastructure audits are conducted by mdtel / SECUNIT, an independent Spanish security operations centre. Each cycle covers: external network exposure mapping, service and version fingerprinting, TLS configuration and certificate hygiene, HTTP security header review, web application surface analysis, web application firewall coverage, and inventory of information disclosure indicators.

Each finding is severity-rated against a published rubric. A remediation plan is produced, tracked and validated at the next quarterly cycle. The auditor and the cycle are public; the findings themselves are confidential to the audit relationship and available under NDA to qualified procurement and security teams conducting due diligence.

Data residency

Customer data for cloud-hosted Axional services resides in the European Union. Production hosting runs from two named Atlas Edge data centres on Spanish soil: Atlas Edge Barcelona (Carrer de l'Acer 9, Sants-Montjuïc, 08038) and Atlas Edge Madrid (Av. de Manoteras 42B, Hortaleza, 28050). Both facilities are referenced explicitly on the ENS certificate.

Spain-only data residency is available for public-sector customers and for healthcare workloads subject to autonomous-community data protection regulation. On-premise deployments place customer data at the customer's nominated location, with no operational access from deister software beyond the contractually defined support paths.

Sub-processors and infrastructure partners

Every external vendor that processes customer data, or that runs operational infrastructure under the certified scope, is named here. Procurement teams subscribe to changes through the security mailbox below; customers under contract receive thirty days' notice of any material addition.

Production hosting

Atlas Edge. Two named EU facilities: Barcelona (Carrer de l'Acer 9, 08038 Sants-Montjuïc) and Madrid (Av. de Manoteras 42B, 28050 Hortaleza). Both facilities listed on the ENS certificate. Atlas Edge holds ISO 27001 and ISO 50001 across the Iberian estate.

External security audit

mdtel / SECUNIT — Spanish security operations centre. Quarterly external infrastructure audit of the production estate. Audit firm declaration is part of the evidence pack.

Certification body

ADOK Certificación, S.L. ENAC ISO 17065 accreditation number 242 / C-PR473. Awards and maintains the ISO 27001 and ENS Medium certifications. Acts on the management system, not on customer data.

Email and identity transport

Operational mail and SSO transport vendors are named in the consolidated sub-processor register, available under NDA with the evidence pack. Public summary lands on this page when the legal-function review completes.

Observability and monitoring

Logging, metrics and trace ingestion vendors process operational telemetry only. Customer business records never leave the certified hosting boundary. Specific vendor names are part of the consolidated sub-processor register.

Customer support tooling

Helpdesk and ticketing tooling carries the metadata of support engagements (subject lines, attachments at the customer's discretion), not production business data. Vendor names disclosed under NDA.

Privacy and data protection

deister software processes customer personal data as a processor under contract, in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation) and Spanish Organic Law 3/2018 on personal data protection and digital rights.

The Data Processing Addendum reflecting GDPR Article 28 obligations is incorporated into the master service agreement signed with every cloud and SaaS customer. A standalone template, suitable for procurement review ahead of contract, is included in the evidence pack available under NDA.

The Data Protection Officer function is reachable at dpo@deister.es. Subject-access, rectification, erasure and portability requests routed through this mailbox are acknowledged within seventy-two hours and resolved within thirty calendar days, in line with GDPR Article 12.

The data controllers for Grupo deister software are the six legal entities named on the ISO 27001 certificate (Spain and Peru). The registration data of each entity is published in the corresponding national commercial register and is referenced in the master service agreement at signature.

Vulnerability disclosure

Coordinated security disclosures are welcome from researchers, customers and partners. The published security contact is security@deister.es. A signed PGP key is published at the canonical security.txt location, /.well-known/security.txt, in line with RFC 9116.

Service-level commitments. New reports are acknowledged within one working day. Triage and severity assignment complete within five working days. Critical-severity findings under active exploitation are routed to incident response immediately and the customer base is notified within seventy-two hours of confirmation, in line with GDPR Article 33.

Safe-harbour. Good-faith research conducted under the published disclosure policy — proportionate testing, no data exfiltration, no service disruption, no third-party impact — will not be pursued. Researchers acting in good faith are credited in the disclosure record at their election.

Public documents

The signed certificates and the public-version policies are downloadable directly. No NDA required.

ISO/IEC 27001:2023 certificate (PDF)

Signed certificate 044807 issued by ADOK Certificación. Valid through 15 July 2028. Covers the Axional services in their On-Premise, SaaS and Cloud hosting modalities.

ENS Medium certificate (PDF)

Signed certificate 624807 issued by ADOK Certificación. Valid through 12 January 2027. Sixty-three controls across the five ENS dimensions at Medium level.

Privacy policy

Public privacy notice covering personal data processed in the course of pre-contract enquiry, customer support and the operation of the deister.es and airtool.io surfaces. PDF available on request from dpo@deister.es while the public version is finalised.

Data Processing Addendum — template

Standalone GDPR Article 28 template for procurement review ahead of contract. Available on request from dpo@deister.es; the version signed with each customer incorporates customer-specific scope and sub-processor list.

Confidential evidence — available under NDA

One mutually executed non-disclosure agreement unlocks the full confidential pack. Reply within forty-eight hours of NDA receipt.

Statement of Applicability summary

Mapping of the ISO 27001:2022 Annex A controls implemented under the certified scope, with the exclusions justified per Statement of Applicability 2025_V6.

External audit summary — current cycle

mdtel / SECUNIT quarterly audit report. Scope, methodology, severity rubric, summary findings, remediation status.

Sub-processor register — full

Consolidated register naming every vendor that processes customer data: name, purpose, data categories, region of processing, certification posture, contract reference.

Architecture and security overview

Engineering-detail description of the security model: encryption in transit and at rest, key management, network segregation, identity and access management, audit logging, customer-controllable settings.

Request the evidence pack

One mutually executed NDA unlocks the full pack — signed certificates and annex, auditor declarations, Statement of Applicability summary, current DPA template, sub-processor register and architecture overview. Reply within forty-eight hours to security@deister.es.

Page status

This page is reviewed quarterly and after any material change to the certified scope, the sub-processor register or the disclosure programme. Page last reviewed 14 May 2026. Next scheduled review 14 August 2026.

Machine-readable security contact: /.well-known/security.txt (RFC 9116). Security mailbox: security@deister.es. Data protection mailbox: dpo@deister.es.