Trust Center

    Security, compliance, and data protection.

    VLMcare is built for regulated environments. This page documents the security controls, certifications, and operational safeguards in place to protect your data and support your regulatory obligations.

    ISO/IEC 27001:2022 — CertifiedISO 9001:2015 — CertifiedMicrosoft Azure — HostedGDPR — Compliant21 CFR Part 11 — AlignedEU Annex 11 — Aligned
    Overview

    Security at a glance

    Hosting Platform
    Microsoft Azure
    Information Security
    ISO/IEC 27001:2022 Certified
    Quality Management
    ISO 9001:2015 Certified
    Cloud Deployment
    Secure SaaS
    Compliance
    GDPR, GAMP 5, EU Annex 11, FDA 21 CFR Part 11
    Encryption
    At Rest & In Transit
    Identity Management
    Role-Based Access Control (RBAC)
    Security Monitoring
    24/7 SIEM Monitoring
    Security Testing
    Independent Penetration Testing
    Business Continuity
    Business Continuity & Disaster Recovery Plans
    Foundations

    Cloud, certifications, and GxP

    Microsoft Azure

    VLMcare is hosted on Microsoft Azure and delivered as a validated SaaS platform. Microsoft secures the cloud infrastructure; VLMcare manages application security, customer data protection, and operational controls under a Shared Responsibility Model. Azure provides high availability, multi-layered physical and logical security, enterprise-grade scalability, and continuous infrastructure monitoring.

    Independently certified

    VLMcare maintains two independent management system certifications, both issued by LRQA: ISO/IEC 27001:2022 (Information Security Management System) and ISO 9001:2015 (Quality Management System). These certifications confirm that VLMcare operates according to internationally recognised standards for governance, risk management, and continual improvement. Both certificates are available for download below.

    Built for GxP

    VLMcare is designed, developed, and maintained to support regulated organisations operating under GxP requirements. The platform supports GLP, GCP, GMP, and GDP. Through validated processes, controlled change management, and comprehensive audit trails, VLMcare helps organisations maintain continuous inspection readiness throughout the system lifecycle.

    Controls

    Security and data protection

    Information security and data protection

    VLMcare implements multiple layers of technical and organisational controls to ensure the confidentiality, integrity, and availability of customer data.

    • Encryption of customer data at rest
    • Encryption of data in transit using secure protocols
    • Encrypted database storage
    • Centralised identity and access management
    • Security logging and audit trails
    • Controlled change management
    • Periodic security reviews

    Access is granted according to the principles of Least Privilege and Need-to-Know.

    Operations and access control

    Access to VLMcare and supporting systems is governed through documented security procedures and centralised identity management.

    • Role-Based Access Control (RBAC)
    • Segregation of Duties (SoD)
    • Least Privilege Principle
    • Multi-layer security architecture
    • Periodic access reviews
    • Internal compliance audits

    24/7 Security Monitoring

    Security events are centrally monitored using SIEM technology with real-time alerting, prioritisation, and escalation procedures. Monitored events include failed authentication attempts, anomalous login locations, off-hours access activity, and privilege escalation attempts.

    Privacy

    Privacy and GDPR

    VLMcare acts as a data processor and processes personal data in accordance with the General Data Protection Regulation (GDPR). Privacy is integrated into the design and operation of the platform through technical and organisational measures.

    No marketing use

    Customer data is never used for marketing purposes without explicit consent.

    Transparent processing

    Data processing is transparent and contractually governed.

    Data minimisation

    Personal data collection is limited to operational and security requirements.

    Security logging

    Logging is performed solely to protect systems and customer environments.

    Documentation

    Available documentation

    Public — available for immediate download

    ISO/IEC 27001:2022 Certificate

    Issued by LRQA. Valid until 23 July 2027. Scope: developing and delivering GxP compliance Quality Management SaaS.

    Download PDF

    ISO 9001:2015 Certificate

    Issued by LRQA. Valid until 20 March 2028. Scope: providing GxP compliance services and solutions.

    Download PDF

    RC-QMS / VLMcare Trust Center

    Comprehensive overview of VLMcare's security, quality, and compliance posture for customers and auditors.

    Download PDF

    Certificates are issued to Rescop Corporate B.V., the legal entity behind VLMcare.

    Upon request — qualified prospects and customers

    Security Whitepaper

    Detailed overview of VLMcare's security architecture and controls.

    Data Processing Agreement (DPA)

    Standard GDPR data processing terms for enterprise customers.

    Penetration Test Executive Summary

    Summary of findings from independent penetration testing.

    Security Questionnaire

    Completed vendor security assessment, available under NDA.

    Request documentation
    Our commitment

    Trust, by design.

    Security, quality, and regulatory compliance form the foundation of every VLMcare service. VLMcare is committed to information security, regulatory compliance, data protection, business continuity, customer trust, and continuous improvement.

    Maurice Kerens
    Managing Director Software Development and Implementation
    Ismail Barug
    Chief Information Security Officer (CISO)