SSO & MFA
Divako supports single sign-on (SSO) and multi-factor authentication (MFA). SCIM creates, updates and closes user accounts automatically, following your organisation's identity management.
Trust & security
Divako processes metering data for utilities, municipalities and housing associations across the Nordics – data that can include household consumption. That is why security and data protection are part of the platform itself. This page explains where data is stored, who can access it, and the standards and principles we follow.
Data ownership
The metering data, consumption data and customer records in Divako belong to you. We process them only to provide the Divako service, on your instructions. We don't sell your data, don't use it for advertising, and don't train AI models on it.
You can export your data at any time through standard interfaces and open formats – REST API, MQTT and SFTP – including a full export of your dataset when you need one. If you stop using Divako, you take your data with you and we delete it under the agreed terms.
Hosting & residency
Divako runs in Microsoft Azure's EU regions. The platform's metering data is stored and processed inside the EU.
Data is encrypted both in transit and at rest. Backups are encrypted as well, and restores are tested regularly.
Access & accountability
Access follows least privilege: a user sees only the projects, devices and functions they have been granted. Significant actions are recorded in the audit log, so you can always check who did what, and when.
Divako supports single sign-on (SSO) and multi-factor authentication (MFA). SCIM creates, updates and closes user accounts automatically, following your organisation's identity management.
Roles define which projects, devices, data and actions a user can see. Access can be limited to match each person's tasks and responsibilities.
Significant user and system actions are recorded with the actor and the time. The audit log supports internal control, security reviews and audits.
Standards & compliance
Divako's security processes are built on recognised information-security standards and EU requirements. Here is which frameworks we use and where each one stands today.
Divako's information security management system (ISMS) is built on ISO/IEC 27001:2022. The standard's controls are being applied today, and we are working toward certification. Divako is not yet ISO 27001 certified – and we won't claim to be until we are.
Many Divako customers operate in sectors covered by the NIS2 directive. Our security processes therefore take NIS2 principles into account – risk management, incident handling, supply-chain security and access control – so that Divako fits into your existing security and compliance framework.
Metering data can contain personal data – for example when consumption is tied to a specific household or user. In that case Divako processes it as a data processor under a data processing agreement (DPA), keeps the required records of processing activities, and supports you in fulfilling data subjects' rights.
Day-to-day practices map to the ISO/IEC 27002:2022 control set – access management, cryptography, change management, backups, logging and vendor risk – and each control's status is tracked as the programme matures.
Working through a procurement security review? We're happy to share our current control status, our DPA and sub-processor list. Get in touch and we'll send them over.
Reliability & incidents
Divako has a documented information-security incident process with named owners and a notification procedure. If an incident affects you, you hear about it through the agreed channels.
Incident handling with defined roles, responsibilities and escalation paths – prepared before it is needed.
Incidents with impact are communicated to affected customers according to the agreed process and applicable requirements.
Live uptime and incident history are public – no quiet outages.
Talk to us
We'll walk you through Divako's security measures, hosting and data handling – and share our DPA, sub-processor list and further security documentation on request.