SolvencyBridge
Security & Trust Centre
Review security controls, taxonomy coverage, deployment responsibilities, AI data flow, and import/export boundaries.
Üksikasjalik dokumentatsioon on praegu inglise keeles.
This public centre is a product-behavior summary for security, procurement, and reporting review. It describes controls in the current product release and the reference deployment. It is not a certification, penetration-test report, legal opinion, regulator endorsement, or promise that every authority rule is implemented.
For machine-readable detail, download the checksummed public taxonomy coverage catalog. Review the privacy notice and terms for the deployment-specific legal position. Draft legal notices are clearly labelled until their required production facts and approval evidence are configured.
Security control summary
| Area | Implemented product control | Boundary to verify |
|---|---|---|
| Tenant isolation | Organization-scoped authorization and PostgreSQL row-level security protect tenant records. | Infrastructure administrators and approved support access remain deployment responsibilities. |
| Access | Authenticated accounts, organization membership, role-controlled preparation and review, and explicit administrator actions. | Identity-provider, device, joiner/mover/leaver, and privileged-access policies must be agreed for the deployment. |
| Uploads | Extension and signature checks, bounded parsing, and fail-closed ClamAV scanning in the reference production profile. | Scanner availability, signature updates, capacity, and incident handling are operator responsibilities. |
| Integrity | Taxonomy sources, imports, attachments, snapshots, and exports use recorded SHA-256 checksums where their workflows require evidence. | A checksum proves byte identity, not regulatory correctness or authority acceptance. |
| Audit | Filing events use ordered per-filing sequences; imported cells retain source lineage and mappings where supported. | Import data, audit events, preview consumption, and external artifact work are not one end-to-end database transaction. |
| Recovery | Coordinated PostgreSQL and artifact backups, encrypted backup packages, restore checks, and clean-restore procedures are provided. | Backup destination, encryption keys, schedule, independent copies, and rehearsals must be operated and evidenced. |
| Network | The reference Compose profile keeps PostgreSQL, malware scanning, workers, and optional object storage on private service networks. | TLS termination, firewalling, host hardening, outbound policy, and high availability depend on the selected deployment. |
| Assurance | CI exercises authorization, row-level security, migration, import, validation, export, security, and browser contracts. | An independent penetration test is planned for Q4 2026, and the ISO/IEC 27001 certification process is planned to begin in Q2 2027. Neither is completed; no ISO, SOC, or regulatory certification is claimed. |
Taxonomy coverage matrix
| Taxonomy release | Product position | Templates | Deterministic rules | Effective-period treatment |
|---|---|---|---|---|
| EIOPA 2.8.2-hotfix | Current supported release | 599 | 6,116 | Selected through YE 2026 and reference periods ending 2026-12-31. |
| EIOPA 2.10.0 | Future-ready, bundled and structurally verified | 570 | 6,746 | Selected from Q1 2027 reporting; do not present it as applicable to YE 2026 or as the current filing release. |
The EIOPA 2.10.0 package revision 4 binds a checksum-pinned EU legal-source manifest covering Directive (EU) 2025/2, CELEX 32025L0002; Directive 2009/138/EC consolidated as of 30 January 2027; Commission Delegated Regulation (EU) 2026/269; the EIOPA 2.10.0 taxonomy; and revised reporting and disclosure materials. The consolidated Directive is a non-authentic documentation aid. Draft technical standards submitted to the European Commission remain status-labelled and are not treated as adopted binding instruments.
Directive (EU) 2025/2 applies from 30 January 2027. A separate checksum-bound national tracker covers all 30 supported profiles. It records EUR-Lex-notified Member State measures for EU profiles and EEA incorporation plus official national implementation evidence for Iceland, Liechtenstein, and Norway. Notification means only that an official measure is listed for the exact act and country; it does not establish completeness, correctness, Commission verification, legal compliance, regulator approval, or authority acceptance. Source changes require governed review and never promote runtime readiness automatically.
Country and authority coverage is not a single yes/no flag. The public catalog contains one entry per jurisdiction profile and taxonomy release, with source dates, checksums, national-form, export and transport states, known limitations, and separate evidence levels for implementation, structural verification, representative filing, package readiness, submission testing, and authority acceptance. Missing external evidence remains visibly unverified.
Download the live coverage JSON. It contains no customer or organization data and returns its catalog checksum in both the payload and the X-SolvencyBridge-Checksum response header.
Deployment and shared responsibility
| Responsibility | Shared cloud | Customer private cloud |
|---|---|---|
| Application release | SolvencyBridge operator builds, deploys, and monitors the agreed release. | SolvencyBridge supplies and verifies the agreed release; deployment authority and change windows are coordinated with the customer. |
| Cloud account and host | Operator-managed infrastructure under the selected production configuration. | Customer owns the cloud account, network boundary, host baseline, and infrastructure access. |
| Tenant and reporting access | Operator runs the service controls; customer administrators manage memberships, invitations, and filing roles. | Customer administrators manage memberships and roles; infrastructure administrators remain customer-controlled. |
| PostgreSQL and artifact durability | Operator executes the approved backup and restore process and maintains independent copies. | Customer provides durable storage, backup destinations, keys, schedules, independent copies, and restore access; responsibilities are agreed before go-live. |
| Secrets and encryption keys | Operator manages production service secrets according to the approved process. | Customer controls infrastructure and customer-managed keys; application-secret custody is agreed during implementation. |
| Monitoring and incident response | Operator monitors the service and follows the approved incident and notification process. | Customer monitors infrastructure; application monitoring, escalation, evidence preservation, and notifications are coordinated under the agreed runbook. |
| Upgrades and migrations | Operator schedules tested forward migrations and maintains rollback backups. | Upgrade windows and rollback evidence are jointly agreed; the customer authorizes the infrastructure change. |
| Regulatory decisions and submission | Customer selects scope, reviews outputs, submits through external authority channels, and retains authority receipts. | Same customer responsibility. Deployment choice does not transfer regulatory accountability. |
The contract, data-processing agreement, production runbook, and configured legal notice remain authoritative for a specific customer. This matrix is a product overview, not a substitute for those documents.
Optional AI data flow
AI features are disabled when no provider key is configured. Production AI mapping and filing-assistant access is also allowlisted per organization. A suggestion never changes filing data automatically.
- The user chooses an AI action and an explicit sharing mode.
- The application checks organization policy and the current consent contract.
- Tenant IDs, filing IDs, form IDs, cell IDs, and unrelated filing values are removed before an assistant request leaves the application.
- Only the selected projection is sent to the OpenAI Responses API with
store: false. - The structured response returns as advice or a mapping proposal. The user must review it and use the normal preview, validation, and apply controls.
- SolvencyBridge retains the provider, model, prompt-contract version, privacy mode, and suggestion time where the workflow requires evidence.
| Mode | Sent to the external provider | Not sent |
|---|---|---|
| Disabled/local | Nothing. | All filing and workbook data remain in the application. |
| Assistant metadata only | User question, filing taxonomy/jurisdiction/period/status, table and field labels/types, redacted validation diagnostics, and retrieved product evidence. | Tenant and record IDs, other filing values, and the selected current value. |
| Assistant selected value | Metadata-only projection plus the current selected field value after explicit consent. | Other filing values and tenant/record IDs. |
| Import headers only | Sheet names, headers, taxonomy structure, and deterministic candidate mappings. | Raw sample values. |
| Import types only | Headers plus structural value shapes such as number, date, blank, or text length. | Raw sample values. |
| Import sample rows | Headers plus at most five raw sample rows, only when the organization separately permits value sharing. | The complete workbook and unrelated filing data. |
Under the current standard API controls, OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, unless different approved data controls apply. API data is not used for model training by default unless the customer opts in. Confirm the selected OpenAI project controls, region, subprocessor terms, and the current OpenAI API data-controls documentation before enabling production use.
Import and export capability matrix
| Path | Current capability | Evidence and control | Important boundary |
|---|---|---|---|
| CSV | UTF-8 canonical or mapped tabular import. | Non-mutating preview, mapping revision, source SHA-256 reference, and per-cell lineage. | The original CSV is not retained as a filing attachment. Blank values do not clear cells. |
Excel .xlsx | Filing-specific templates and mapped workbook import. | Sheet inventory, bounded parsing, preview, mapping revision, source reference, and workbook cell address lineage. | Formulas are not calculated during import; review values in the preview. |
ODS .ods | Value-only tabular import with decimal-text preservation. | Bounded XML parsing, formula refusal, preview, mapping, and lineage. | Styling, charts, macros, and external calculations are not import inputs. |
| EIOPA XBRL | Offline validation against the filing's pinned supported release, then preview and apply. | Source attachment, source checksum, validation-log checksum, changed cells, actor, and time are retained for the EIOPA path. | Instance identity, contexts, units, dimensions, filing indicators, and supported release must match. |
| Supported national XBRL | Profile-specific validation and complete-form replacement for implemented profiles. | Revision checks and an ordered import audit event. | Support is profile-specific; the source is not retained as permanent filing evidence in the current national path. |
| EIOPA XBRL export | Generated from an approved immutable snapshot against the pinned taxonomy. | Export artifact checksum, manifest, snapshot identity, actor, and audit history. | Portal submission, receipt, and authority acceptance remain external. |
| Supported national exports | Profile-specific XBRL, workbook, JSON, XML, ZIP, or portal-package artifacts where explicitly implemented. | Snapshot-bound generation and profile-specific checks. | A generated artifact does not prove authenticated transport or authority acceptance. Consult the coverage catalog. |
| Portable filing bundle | Encrypted filing transfer and recovery package. | Scrypt, AES-256-GCM, payload and attachment checksums, and revision conflict protection. | It is a recovery/transfer format, not an authority submission. |
Synthetic example export
Download the synthetic EIOPA XBRL example and its SHA-256 sidecar. The example shows a minimal XBRL document, schema reference, reporting entity, period, filing indicator, reporting currency, and deterministic bytes. It uses only synthetic demonstration data and is intentionally small enough to inspect. It is not a complete filing, validation report, submission package, receipt, or regulator-accepted artifact.
For the detailed import contract, continue to Import formats and canonical headers. For the export and checksum workflow, see Generate and verify an export.