Security & supply-chain information

For organisations covered by the Dutch Cybersecurity Act (NIS2) assessing Hoeray as a supplier.

Our position under the Dutch Cybersecurity Act

Hoeray (trade name of The Circle of 10 B.V., Dutch Chamber of Commerce no. 92475809) does not itself fall under the Dutch Cybersecurity Act. We established this on 31 August 2026 using the official NIS2 self-assessment of the Dutch Authority for Digital Infrastructure (RDI), deliberately filled in conservatively: even when Hoeray is regarded as a provider of a cloud computing service, the organisation falls outside the Act due to the size criteria, and none of the size-independent exceptions apply.

Outcome of the self-assessment: “The NIS2 directive does not apply to the organisation in the Netherlands.”

If your organisation is covered by the Act, Hoeray is one of the suppliers you assess as part of your duty of care. This page contains the relevant information. We reassess our own position upon relevant growth or changes to our services.

Technical and organisational measures

  • Multi-tenant isolation at the database level: row-level security, enforced (FORCE) on all tables holding customer data — even administrative code cannot bypass the isolation regime.
  • Daily automated verification of that isolation regime and of the processing chain, with immediate alerting on deviations.
  • Separated database roles with minimal privileges for application, platform and administrative tasks.
  • HR integrations are read-only; integration credentials are stored encrypted (AES-256-GCM).
  • Hosting and data storage entirely within the EU (Frankfurt, Germany) — both the application and the database.
  • Encrypted connections (TLS) for all traffic.
  • Two-factor authentication available for all user accounts.

Incidents and data breaches

Processing is verified automatically every day. In the event of a data breach affecting your organisation, we inform you in accordance with the data processing agreement without undue delay and at the latest within 72 hours of discovery, including the nature of the incident, the data affected and the measures taken.

Documents

The full agreements — including the sub-processor list and the security annex — are set out in our legal documents (version 30 August 2026):

Supplier assessment or questionnaire?

Does your organisation use its own supplier questionnaire or assessment format? Send it to hello@hoeray.com — we are happy to complete it for you.

Last updated: 31 August 2026