At HULO, security is fundamental to how we build and operate our platform. Water utilities rely on resilient, trustworthy digital infrastructure to protect an essential service, and we take our part in that seriously.
This page is the overview of the safeguards, the governance and the independent assurance behind our approach. We make our security practices transparent and verifiable, supported by recognised certification and continuous improvement, so you can assess HULO on evidence rather than on promises.
NIS2 named drinking water supply as an essential entity, and 2026 is the year enforcement caught up with the text. Three consequences land directly on the people who buy software.
We are read-only, we install nothing in your OT network, and we hold no operational control over your assets. That is a deliberate architectural choice, and it is the single largest reduction in the risk you take on by adding us as a supplier.
Full legal detail, per member state, is outside the scope of this page. Transposition differs by country. Your regulator is the authority. We are simply telling you what we can evidence.
At HULO, information security is embedded in how we govern, develop, operate and improve the company. It is not a product feature added at the end. Since 2025, our information security management system has been certified to ISO/IEC 27001:2022.
The ISMS gives us a structured, risk-based way to protect the availability, integrity and confidentiality of the information and the services our customers rely on. It applies across the organisation, and connects leadership, people, processes, technology and supplier relationships.
ISO 27001 is not a one-time milestone. HULO runs a cycle of monitoring, internal review, management oversight and improvement. The ISMS covers the requirements in chapters 4 to 10 of the standard, from organisational context and leadership through planning, support, operation, performance evaluation and improvement, and those chapters are recorded as implemented and reviewed every year.
We also maintain a documented set of controls, selected against risk and against legal and contractual requirements. Independent review and compliance controls are part of that, which is what turns an assurance into evidence.
Many certificates cover a single product, a single service or one technical environment. HULO's ISO 27001 certification is based on a management system designed to run across the organisation and across the lifecycle of our services. For a utility assessing a supplier, that is a clearer view of how security is governed, delivered and improved.
Certification evidence: ISO/IEC 27001:2022, certified since 2025, certificate K-0222779 issued by Kiwa. The certificate itself carries the audited date and the validity period, and comes with the document pack at the foot of this page.
NIS2 is changing how essential services manage cyber risk. A water utility is now expected to understand, assess and manage the cybersecurity of its supply chain, not only of its own systems. That makes a supplier's security posture an operational and procurement decision.
HULO has been independently audited by an accredited auditor against the SC30 level of the NIS2 Quality Mark. SC30 is written for suppliers operating in the highest-risk context, which includes suppliers to critical infrastructure.
The assessment evidences that our approach addresses the governance, organisational, people, physical and technical measures expected of a security-conscious supplier. It sits next to our ISO/IEC 27001:2022 certified ISMS, and it gives you a practical starting point for your own supplier-security assessment.
The directive raises the bar for essential and important entities across the EU. For a drinking-water utility, that means cybersecurity and resilience have to be weighed when selecting and managing suppliers, too.
We chose to meet that expectation before we were asked. Rather than treating assurance as a contractual afterthought, we publish independent evidence and a clear route to request the detail, which takes friction out of procurement, vendor due diligence and ongoing supplier management.
The directive is an EU instrument, but resilient security should not stop at a regulatory boundary. We apply the same principles to how we build and operate the service, wherever a customer uses it. EU regulation, global security mindset.
Same rule as the Proofroom: no proof means no claim. Every line below either links to a document or says plainly that it does not yet.
Every vendor a water utility might shortlist, against the five certifications that come up in procurement. We lose three of these five columns. They are on the page anyway, because a comparison table that its author always wins is not a comparison table. Every name links to where we read the claim.
| Vendor | ISO/IEC 27001 | NIS2 Quality Mark | ISO/IEC 42001 | SOC 2 | Cyber Essentials Plus |
|---|---|---|---|---|---|
| HULO | ● | ● | ○ | ○ | ○ |
| Qatium | ● | ○ | ○ | ○ | ○ |
| Flowless | ○ | ○ | ○ | ○ | ○ |
| Hydroscan | ○ | ○ | ○ | ○ | ○ |
| TaKaDu | ○ | ○ | ○ | ○ | ○ |
| Asterra | ○ | ○ | ○ | ○ | ○ |
| AGANOVA | ○ | ○ | ○ | ○ | ○ |
| FIDO | ● | ○ | ○ | ○ | ● |
| Baseform | ○ | ○ | ○ | ○ | ○ |
| Bentley | ● | ○ | ○ | ● | ● |
| Xylem | ● | ○ | ○ | ○ | ● |
| SUEZ | ○ | ○ | ○ | ○ | ○ |
COMPILED FROM PUBLIC SOURCES · LAST CHECKED 21 AUGUST 2026
FOUND AN ERROR? TELL US AND WE WILL CORRECT THIS TABLE.
Bentley. Its ISO 27001 covers an information security and a privacy management system together (27001:2022 with 27701:2019), across Bentley global corporate systems and the Bentley and Seequent commercial product infrastructure, including managed services, Eagle.io, and DataConnect and ComplyPro hosting.
Xylem. Also holds ENS, the Spanish national scheme that maps onto GDPR, NIS2 and ISO 27001 for public-sector suppliers, and ISO 9001, ISO 14001 and ISO 45001 for quality, environment and health and safety.
FIDO. Also holds ISO 9001 for quality management.
Nobody in this market holds ISO/IEC 42001 for AI management systems yet, including us. Bentley holds SOC 2 and we do not. Bentley, Xylem and FIDO hold UK Cyber Essentials Plus and we do not. All of that is on this page because you would find it anyway, and a supplier who tells you only the flattering half of a comparison has told you something about themselves.
Which is why the certificate number and the public registry link are on this page, and the logo is not the point.
Most of a vendor's risk profile is decided by how it connects, not by which certificate it holds. Ours connects in the least invasive way the job allows.
Written for the person whose job it is to say no. Answering these badly is how a good product loses a procurement round it should have won.
Not in the regulatory sense, and no vendor is. NIS2 is a directive, and no EU body issues a compliance certificate against it. Anyone telling you otherwise is selling something. What we hold is the NIS2 Quality Mark at SC30, independently audited by an accredited auditor and listed in a public registry you can check without asking us. Alongside ISO/IEC 27001:2022 from Kiwa, that covers the supplier-side evidence your own NIS2 assessment needs.
HULO is certified to ISO/IEC 27001:2022. Our information security management system helps us manage security across our people, processes, technology and suppliers, and improve it continuously. It is an organisation-wide system, not a certificate scoped to one product or one environment.
NIS2 is an EU directive that requires covered organisations to manage cybersecurity risks, including risks in their supply chain. HULO has been assessed against the NIS2 Quality Mark SC30, the level written for suppliers operating in the highest-risk context, including suppliers to critical infrastructure. The assessment and the certificate reference are on this page, for transparency.
On its own, do not. Trust the audit behind it and the registry entry that makes it checkable. That is precisely why we publish the registry link rather than a badge image. A badge is a picture. A registry entry is a fact.
We use a risk-based, layered approach that includes controlled access, strong authentication, encryption, secure development practices, monitoring, backup and recovery measures, and security awareness.
Access is limited to authorised people who need it for their role. We apply least-privilege principles and manage access throughout the employee lifecycle.
Security is built into the way we develop and operate our services, through secure design, code review, controlled changes, security testing, and separated environments for development, testing and production.
We take a risk-based approach to suppliers and cloud services. Security, privacy and continuity are considered when selecting and managing the providers that support our services.
HULO maintains documented processes for security incidents, continuity and recovery. We review and test these arrangements to support a timely, coordinated response and continual improvement.
It adds an outbound data path and nothing else. No inbound control channel, no installed device, no write access. The realistic worst case is disclosure of network telemetry, not loss of operational control.
We are committed to protecting personal data and apply appropriate organisational and technical measures. Privacy is considered in our policies, processes and supplier arrangements. Network telemetry is not personal data; where personal data is involved, it is limited to named users of the software.
Security is an ongoing process. We monitor relevant risks, review our controls, train our people, and use findings from reviews and tests to improve our approach.
Yes. Customers and prospective customers can request further security and privacy information through our due-diligence process. Ask us by e-mail and you get access to the trust centre, with the documents listed at the foot of this page.
Send us an e-mail and we open the trust centre to you: one request, one reply, everything a supplier assessment needs. No sales call in between, and no discovery workshop before you are allowed to read a certificate. Customers and prospective customers can ask at any point in a due-diligence process.
What we found, on which network, and what it cost to find it. Roughly monthly, and never a figure we cannot show you the working for.







HULO’s project Lekker (tegen lekken) is co-financed by the European Union, by SNN and by the Dutch Ministry of Economic Affairs.