Skip to main content

Trust Centre · Public supplier information

Everything needed to evaluate Summa.

A current, structured source for legal, privacy, security, architecture, AI governance and operational due diligence.

This selection controls downloaded files only. It is independent from the website language.

Catalogue version
2026.08-nl
Last updated
31 August 2026
Access
Public · No account required

Document catalogue

Current supplier information, with its history intact.

Each published document remains available in PDF and Word. When a document changes, the previous version and a plain-language change summary stay visible here.

02

Security & sovereignty

The safeguards behind the service, who is involved in running it, where the data physically sits, and how government requests are handled.

Published

Supplier statement

Subprocessors, Integrations and Data Locations

Which parties are involved, for what, and which country the data sits in.

Version history (1)
  1. Version 1.0 · Current

    31 Aug 2026 · Nederlandse uitgave. Vervangt de ingetrokken Engelse set van juli 2026, die verouderd was op het punt van e-maildienst, serviceniveaus en infrastructuurprofiel.

Published

Supplier statement

Technical and Organisational Measures

The safeguards behind the service, at the level of detail a customer needs to form their own judgement.

Version history (1)
  1. Version 1.0 · Current

    31 Aug 2026 · Nederlandse uitgave. Vervangt de ingetrokken Engelse set van juli 2026, die verouderd was op het punt van e-maildienst, serviceniveaus en infrastructuurprofiel.

Published

Supplier statement

Architecture, Data Flows and Sovereignty

Where the service runs, how data moves through it, and how government requests are handled.

Version history (1)
  1. Version 1.0 · Current

    31 Aug 2026 · Nederlandse uitgave. Vervangt de ingetrokken Engelse set van juli 2026, die verouderd was op het punt van e-maildienst, serviceniveaus en infrastructuurprofiel.

Published

Supplier statement

Security, Trust and Compliance Statement

The state of certification, audits and compliance — including what has not been demonstrated yet.

Version history (1)
  1. Version 1.0 · Current

    31 Aug 2026 · Nederlandse uitgave. Vervangt de ingetrokken Engelse set van juli 2026, die verouderd was op het punt van e-maildienst, serviceniveaus en infrastructuurprofiel.

03

AI governance

What the AI system may be used for, and the limits it operates under.

Published

Supplier statement

Acceptable Use Policy and AI Restrictions

What the service may be used for, and what the AI system explicitly cannot or must not decide.

Version history (1)
  1. Version 1.0 · Current

    31 Aug 2026 · Nederlandse uitgave. Vervangt de ingetrokken Engelse set van juli 2026, die verouderd was op het punt van e-maildienst, serviceniveaus en infrastructuurprofiel.

04

Continuity & exit

Retention and deletion, the formats your data comes back in, and how leaving works.

Published

Supplier statement

Retention, Deletion, Export and Switching (Data Act)

Retention periods, deletion, export formats and the switching arrangement under the Data Act.

Version history (1)
  1. Version 1.0 · Current

    31 Aug 2026 · Nederlandse uitgave. Vervangt de ingetrokken Engelse set van juli 2026, die verouderd was op het punt van e-maildienst, serviceniveaus en infrastructuurprofiel.

Public sector & procurement

Municipality documentation, on request

GIBIT 2025, BIO2, AI Act, DPIA support, archiving and procurement documentation exists and is shared for customer due diligence. It is not published here: it is written for one buyer’s assessment, and some of it would tell an attacker more than it tells you.

  • AI Governance en AI Act technisch dossier

    Het volledige technische dossier: systeembeschrijving, risicoclassificatie, menselijk toezicht en conformiteitsonderbouwing.

  • Regelgevingsanalyse Cbw, NIS2, CRA en DSA

    Analyse van de toepasselijkheid van elk kader en de gevolgen voor de dienst.

  • GIBIT 2025 compliance- en afwijkingenmatrix

    Artikel-voor-artikel beoordeling tegen de GIBIT 2025-voorwaarden, inclusief de afwijkingen en de onderbouwing daarvan.

  • BIO2, ICT-kwaliteitsnormen en open standaarden

    Beoordeling tegen BIO2, de gemeentelijke ICT-kwaliteitsnormen en de pas-toe-of-leg-uit-lijst.

  • Gemeentelijk privacy-, AI- en inkoopondersteuningsdossier

    Ondersteunend materiaal voor een gemeentelijke DPIA, AI-toets en inkooptraject.

  • Informatiebeheer, archivering, Woo, DUTO en exit

    Archiefwet- en Woo-implicaties, DUTO-conformiteit en het exitdossier.

  • GEMMA Softwarecatalogus product- en standaardenverklaring

    Productverklaring en ondersteunde standaarden voor de GEMMA Softwarecatalogus.

  • Software Bill of Materials (CycloneDX)

    De volledige componenteninventaris van de dienst. Op verzoek, omdat een publieke componentenlijst vooral aanvallers helpt.

Request security & procurement documentation

Use of these materials

Supplier facts, clearly labelled.

These materials help security, privacy, legal, procurement and IT teams evaluate Summa. They do not complete a customer's DPIA, AI Act assessment or internal approval. Each organisation remains responsible for its own use case, risks and decisions.

Contact us about due diligence