Skip to content
Toasty
Trust brief

Security you can verify, claims we can defend.

This page is written for the people who actually block offshore deals: your DPO, your CISO and your procurement lead. Where the answer is uncomfortable, it is still the answer we give.

01. Architecture

Remote-access delivery, not data export

Client data stays in the client's own cloud tenancy, in the client's chosen EU region. Toasty engineers reach it through hardened virtual desktops and zero-trust access with device posture checks, MFA and session logging.

No client data is stored at rest on engineer endpoints or on infrastructure in Pakistan. Source code, secrets and datasets live in your repositories, your key vaults and your storage accounts. We work inside your perimeter, under your identity provider.

02. Transfers

We call remote access what it legally is: a transfer

Under EDPB Guidelines 05/2021, remote access from a third country counts as a transfer of personal data, even when nothing is copied or downloaded. Pakistan has no adequacy decision, so we do not pretend the question goes away.

Every engagement that touches personal data ships with the 2021 Standard Contractual Clauses, a written Transfer Impact Assessment, an Art. 27 EU representative and documented supplementary technical and organisational measures. Our zero-trust and EU-residency architecture is exactly the kind of supplementary measure the EDPB contemplates. It materially reduces risk, and we document why.

Note also that EU law does not mandate data residency in itself. We default to it because European buyers and their DPOs prefer it, not because we are quoting a rule that does not exist.

03. Certifications

ISO/IEC 27001-aligned, certification underway

Our information security management system is built to the ISO/IEC 27001 control set: risk register, asset inventory, access control policy, secure SDLC, supplier management, incident response and business continuity, each with a named owner and a review cadence.

Independent certification is in progress. Until the certificate is issued we say 'aligned', not 'certified'. The full control documentation, policy set and our current gap assessment are available under NDA so your security team can judge for themselves.

04. EU AI Act

Readiness that means artefacts, not a badge

Art. 5 prohibitions and Art. 4 AI literacy obligations have applied since February 2025, GPAI model obligations since August 2025, and Art. 50 transparency duties (AI-interaction disclosure and machine-readable marking of synthetic content) apply from 2 August 2026. High-risk obligations for Annex III stand-alone systems now run to December 2027 following the Digital Omnibus on AI.

For a delivery partner that translates into four concrete things, and we ship all four: prohibited-practice screening at use-case intake; Art. 50 marking and disclosure capability in every GenAI deliverable; Annex IV-mapped documentation packages including model cards, logging design and human-oversight design; and MSA clauses ready for the Art. 25(4) information and assistance duties your legal team will need to pass down to us.

05. Regulated sectors

DORA-aware, and honest about sequencing

Since January 2025, EU financial entities must register every ICT third-party arrangement with their supervisor. Any offshore vendor to a DACH bank or insurer is regulator-visible from day one, and we build our documentation to survive that.

We will still tell a financial-services prospect plainly that they should not be our first reference in Europe. Regulated onboarding goes faster once our ISMS is certified and non-regulated references exist, and we would rather sequence that correctly than sell into a review we would fail.

06. People and premises

The controls behind the architecture

Background-checked staff, individual NDAs, least-privilege role-based access reviewed quarterly, mandatory annual security training and same-day offboarding with credential revocation.

Access-controlled delivery centres in Lahore and Islamabad with centrally managed hardened endpoints, full-disk encryption, DLP, no removable media and monitored network egress.

Document requests

Ask for the paperwork before you ask for a proposal.

Under NDA we share the ISMS policy set and current gap assessment, our standard DPA with SCC annexes, a sample Transfer Impact Assessment, the sub-processor list, our secure SDLC and incident-response runbooks, and a sample Annex IV documentation pack from a GenAI deliverable.