Answers to the most common compliance questions about information security, data storage and operations
Reference: SEC-TOM-01
Organisation: The Selection Lab B.V.
Version: 2026.9
Address: Sint Pieterspoortsteeg 19, 1012 HM Amsterdam
Contact: [email protected] · www.selectionlab.com · +31 (0)20 - 2443212
This document answers the most common compliance questions and outlines the Technical and Organizational Measures taken by Selection Lab.
| EU | candidate and user data stored in the European Union (AWS Frankfurt, eu-central-1) |
| AES-256 | encryption at rest; TLS/HTTPS in transit |
| MFA | available for every user; required for staff access to the infrastructure |
| 0 | downtime while updates are applied |
Key measures at a glance. The full answers in Sections 1–2 below are leading.
| Question | Answer |
|---|---|
| 1.1 What underlying platform is used? | We use the following underlying platforms for our service: Heroku (PaaS), AWS (PaaS), Cloudflare (DNS, TLS termination and content delivery), Auth0 (SaaS), Typeform (SaaS), Brevo (SaaS), Sentry (application errors and logs, SaaS), Papertrail (application log storage, SaaS). |
| 1.2 What type of data is stored and/or used? (if personal data is processed, a processing agreement is mandatory) | A processing agreement for all data is included in our contracts. We process (store/use) the following types of data: personal data (assessment results), user data (accounts), application data (logs, settings), email-data. |
| 1.3 Where is the data stored (backups, logging, support data included)? Data may not be stored outside the European Union (EU). | Candidate and user data are stored in Frankfurt (AWS region eu-central-1). Backups are copied daily to a write-protected vault in Stockholm (AWS eu-north-1); recovery after loss of the Frankfurt region is from that vault. The application runs on Heroku in Dublin (eu-west-1). The staging application also runs on Heroku; its data stores are in Paris (eu-west-3) and hold no production data. Brevo stores e-mail data in the EU. Sentry stores application errors and logs in Frankfurt. Query results for internal reporting, which include user data, are held in Ireland (eu-west-1). Three of these platforms hold data outside the EEA: Typeform (assessment responses, United States), Papertrail (application logs, United States) and Cloudflare (request metadata, global network). The safeguards for each, and the full list of sub-processors, are in the Data Processing Agreement, Annex 1, item 4. |
| 1.4 Are data encrypted during storage and transfer? If so, which cryptography standards are used? | Yes, all data is encrypted during storage and transfer, using the following standards: DynamoDB (AWS) — Data in transit: all data in DynamoDB is encrypted in transit. By default, communications to and from DynamoDB use the HTTPS protocol, which protects network traffic by using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) encryption. Data is fully encrypted at rest, using the AWS owned CMK – Default encryption type. The key is owned by DynamoDB using the 256-bit Advanced Encryption Standard (AES-256). Typeform — Data in transit: end-to-end, including within the virtual private cloud at AWS, using secure TLS cryptographic protocols (TLS 1.2). Auth0 — Data-at-rest and in-motion is encrypted: all network communication uses transport layer security (TLS) with at least 128-bit advanced encryption standard (AES) encryption. The connection uses TLS, and it is encrypted and authenticated using AES_128_GCM and uses ECDHE_RSA as the key exchange mechanism. Brevo — Encrypted data during transmission via HTTPS, SSL and VPN. Data at rest is stored on secure servers in Tier 3 and PCI DSS certified data centers. Heroku — Does not store any (personal) data. All data connections in transit use HTTPS and TLS. Cloudflare — Terminates TLS for both domains on its edge network; the connection from Cloudflare to the origin is encrypted and the origin certificate is validated (encryption mode Full (strict)). Sentry — Application errors and logs are sent over TLS and stored encrypted at rest in Frankfurt. Papertrail — Logs are sent over TLS and stored by SolarWinds under its SOC 2 Type II and ISO 27001 controls. |
| 1.5 Are suitable security measures in place, and are state-of-the-art and proportional measures incorporated in the information security policy in view of the data to be protected? | Yes, there is a high level of information security awareness, given the personal data that is processed. Periodically employees are made aware of potential risks and measures they need to take. In addition to that we make use of automated vulnerability checks via GitHub. An independent, qualified external party performs a penetration test at least once every 12 months. Backups are automated via AWS and copied daily to a write-protected vault in a separate region; after loss of the primary region, the service is recovered from that vault under the Disaster Recovery and Business Continuity Plan. Staff confidentiality is incorporated in employee contracts. |
| 1.6 How is the synchronization of the admin accounts arranged? | (Application) admin accounts can be created via support. |
| 1.7 How can authorisation be managed using an external identity management solution? | Authorization is managed via Auth0. Authorization (levels) can only be altered via support. |
| 1.8 Are there any supplier accounts which have access to the data, and if so, which? | For security and support matters, the supplier accounts with administrator or developer access to the production environment have access to data: Joeri Everaers-Welten (COO), Jordi Wippert (CTO), Beau Mosterd, Aylon Pinto and Ondřej Sloup (IT & Security). The list is confirmed in the six-monthly access review. |
| 1.9 Does the application support multi-factor authentication (MFA/2FA)? If so, please explain in more detail. | Yes. MFA is available for every user. Selection Lab switches it on for a client's users on request; the default factor is a code sent by SMS after the login with username and password. Clients that sign in through their own single sign-on apply the MFA of their own identity provider. |
| 1.10 Is it possible to audit the security measures? | All security measures can be audited. |
| 1.11 What type of data is stored and/or used? (if personal data is processed, a processing agreement is mandatory) | Same question as 1.2; see the answer there. |
| 1.12 If COMPANY data is stored in the service, an exit strategy must be described. Is an exit strategy available detailing steps and arrangements on how to switch to an alternative for this product from this supplier while retaining continuity and all data? | Yes, an exit strategy is available detailing all steps that will be taken when COMPANY wants to stop using Selection Lab as a supplier, including data deletion. Due to product-specific data formats, data can not be transferred into alternative suppliers. |
| 1.13 Is installation on a local server needed? | No. |
| Question | Answer |
|---|---|
| 2.1 Are there backup arrangements, and if so, which? | Yes. Continuous point-in-time recovery on the primary database with a 35-day window, and a daily backup copied to a write-protected vault in a separate region, retained 35 days. |
| 2.2 Is there an SLA? | Yes. |
| 2.3 How are updates implemented? | In a continuous process of code development, reviews, automated testing, test/staging application and deployments. |
| 2.4 Who approves updates? | At Selection Lab: Jordi Wippert (CTO), [email protected] |
| 2.5 Who monitors updates? | At Selection Lab: Jordi Wippert (CTO), [email protected] |
| 2.6 Contact data of the supplier's helpdesk | [email protected] |
| 2.7 Who will manage the user accounts of the SaaS service? | Each client manages the user accounts of its own organisation in the platform. Selection Lab staff with the platform's administrator role can also create and manage them, for example at onboarding, and sales staff can do so for the organisations assigned to them. |
| 2.8 Is there limited availability during updates? | No, there is no downtime while updates are applied. |
| Document | Version used |
|---|---|
| Data Protection Impact Assessment (DPIA), PRIV-DPIA-01 | 2026.9 |
| Security Measures, SEC-MEAS-01 | 2026.9 |
| Data Processing Agreement, PRIV-DPA-01 | 2026.9 |
| Data Backup and Recovery Policy | 1.4 |
| Disaster Recovery and Business Continuity Plan, DRBC-PLAN-01 | 2.4 |
| Vendor register, VEN-REG-01 | 1.0 |
© The Selection Lab B.V. · Sint Pieterspoortsteeg 19 · 1012 HM Amsterdam · [email protected] · +31 (0)20 - 2443212