Security & compliance

Security and compliance

How Testnik handles data, and the frameworks we work to.

Testnik measures networks, which means it touches operational data about infrastructure our customers depend on. The commitments below describe how that data is protected and which obligations we hold ourselves to.

GDPR and ZVOP-2

Personal data is processed under Regulation (EU) 2016/679 and the Slovenian Personal Data Protection Act (ZVOP-2). We collect only what is needed for the stated purpose, keep it no longer than necessary, and support the full set of data subject rights. Details are in the Privacy Policy.

ISO/IEC 27001 alignment

Our information security practices are structured around the ISO/IEC 27001:2022 control set: access control and least privilege, cryptography in transit and at rest, logging and monitoring of administrative actions, change and configuration management, supplier assessment, and documented incident response.

NIS2

Directive (EU) 2022/2555 raises the bar for risk management and incident reporting across essential and important entities. Testnik supports that work directly — continuous measurement, alarm history and scheduled reports give you the evidence a supervisory authority expects — and our own practices follow the Article 21 measures.

ZEPT-1 and electronic commerce

Information about the provider, the service and the terms of contracting is published as required by the Slovenian Electronic Commerce Market Act (ZEPT-1) and the Consumer Protection Act. See the Impressum and the Terms of Use.

Where data lives

All Testnik infrastructure and data storage is located within the European Union. There is no transfer of personal data to third countries in the normal operation of the service.

Reporting a security issue

If you believe you have found a vulnerability in Testnik, write to tech@irnas.eu. We will acknowledge your report and keep you informed while we investigate. Please give us reasonable time to remediate before any public disclosure.

Technical and organisational measures

  • TLS for all traffic between probes, dashboard and this website
  • Encryption at rest for stored credentials and secrets
  • Role-based access control with least-privilege defaults
  • Two-factor authentication available on administrative accounts
  • Audit logging of administrative actions
  • Defined retention periods with automatic deletion
  • Regular patching of operating systems, firmware and dependencies
  • Documented incident response and notification procedure

Privacy Terms of use