Trust & security

Security built for critical infrastructure.

At HULO, security is fundamental to how we build and operate our platform. Water utilities rely on resilient, trustworthy digital infrastructure to protect an essential service, and we take our part in that seriously.

This page is the overview of the safeguards, the governance and the independent assurance behind our approach. We make our security practices transparent and verifiable, supported by recognised certification and continuous improvement, so you can assess HULO on evidence rather than on promises.

ISO/IEC · KIWA
27001:2022
Certified · information security management system · HULO B.V.
CertificateK-0222779
Issuing bodyKiwa
Certified since2025
NIS2 QUALITY MARK
SC30
Independently audited · the level written for suppliers to critical infrastructure
Audited18 March 2026
Valid until18 March 2029
NIS2 and ISO 27001 together
A recognised information-security management standard, next to a practical reading of what NIS2 expects of essential and important entities. That lets you assess organisational maturity and sector cyber-risk in one pass.
Security by design, from the start
Security is carried through product development rather than added at the end of delivery. Risk, access, privacy and resilience are part of how we design, build and operate the software.
Built for the water sector
Data, network insight and operational continuity are business-critical for a utility. Our approach is written to support dependable operations, not only information security.
Evidence over promises
Certification, a stated scope and a clear route to request further security and privacy information. You verify, rather than take our word for it.
Continuous improvement
Security is an ongoing responsibility. We review risks, improve controls, and keep our assurance information current as the product, the customers and the rules change.
Why this stopped being paperwork

Your suppliers are
now your risk.

NIS2 named drinking water supply as an essential entity, and 2026 is the year enforcement caught up with the text. Three consequences land directly on the people who buy software.

Supply chain is in scope
You are expected to assess the security of your direct suppliers and service providers. A vendor that cannot evidence its own controls becomes your finding, not theirs.
Management is accountable
Responsibility sits with the management body, not with IT. That is why procurement questions about vendor security now come from higher up the building than they used to.
Incidents are reportable, quickly
Early warning obligations are measured in hours. If a supplier is involved, you need their incident process to be compatible with yours before anything happens, not after.
What this means for a HULO deployment

We are read-only, we install nothing in your OT network, and we hold no operational control over your assets. That is a deliberate architectural choice, and it is the single largest reduction in the risk you take on by adding us as a supplier.

Full legal detail, per member state, is outside the scope of this page. Transposition differs by country. Your regulator is the authority. We are simply telling you what we can evidence.

ISO/IEC 27001:2022

Built on an organisation-wide
security foundation.

At HULO, information security is embedded in how we govern, develop, operate and improve the company. It is not a product feature added at the end. Since 2025, our information security management system has been certified to ISO/IEC 27001:2022.

The ISMS gives us a structured, risk-based way to protect the availability, integrity and confidentiality of the information and the services our customers rely on. It applies across the organisation, and connects leadership, people, processes, technology and supplier relationships.

Clear accountability
Information-security policies, defined roles and management responsibilities give ownership from leadership through to day-to-day operations.
Risk-led decisions
Security risks, assets and applicable obligations are assessed and addressed through the ISMS, rather than case by case.
Secure operations
Controls cover identity and access management, authentication, endpoint protection, encryption, logging and monitoring, backups, network security and vulnerability management.
Security throughout delivery
Source-code access, secure architecture, security testing, separation of development, test and production environments, and change management.
Resilience and incident readiness
Preparation, assessment, response and evidence collection for security incidents, alongside business-continuity and ICT-readiness measures.
Supplier and cloud assurance
Security requirements are addressed in supplier relationships, agreements, cloud services and the ICT supply chain.
People and physical safeguards
Security awareness, confidentiality, remote working, event reporting, physical entry controls and secure disposal are part of the management system.

Continuous improvement, independently checked

ISO 27001 is not a one-time milestone. HULO runs a cycle of monitoring, internal review, management oversight and improvement. The ISMS covers the requirements in chapters 4 to 10 of the standard, from organisational context and leadership through planning, support, operation, performance evaluation and improvement, and those chapters are recorded as implemented and reviewed every year.

We also maintain a documented set of controls, selected against risk and against legal and contractual requirements. Independent review and compliance controls are part of that, which is what turns an assurance into evidence.

A useful distinction

Many certificates cover a single product, a single service or one technical environment. HULO's ISO 27001 certification is based on a management system designed to run across the organisation and across the lifecycle of our services. For a utility assessing a supplier, that is a clearer view of how security is governed, delivered and improved.

Certification evidence: ISO/IEC 27001:2022, certified since 2025, certificate K-0222779 issued by Kiwa. The certificate itself carries the audited date and the validity period, and comes with the document pack at the foot of this page.

NIS2 Quality Mark · SC30

Security for critical
infrastructure, sorted.

NIS2 is changing how essential services manage cyber risk. A water utility is now expected to understand, assess and manage the cybersecurity of its supply chain, not only of its own systems. That makes a supplier's security posture an operational and procurement decision.

What SC30 means for a HULO customer

HULO has been independently audited by an accredited auditor against the SC30 level of the NIS2 Quality Mark. SC30 is written for suppliers operating in the highest-risk context, which includes suppliers to critical infrastructure.

The assessment evidences that our approach addresses the governance, organisational, people, physical and technical measures expected of a security-conscious supplier. It sits next to our ISO/IEC 27001:2022 certified ISMS, and it gives you a practical starting point for your own supplier-security assessment.

Ready for a changing supply chain

The directive raises the bar for essential and important entities across the EU. For a drinking-water utility, that means cybersecurity and resilience have to be weighed when selecting and managing suppliers, too.

We chose to meet that expectation before we were asked. Rather than treating assurance as a contractual afterthought, we publish independent evidence and a clear route to request the detail, which takes friction out of procurement, vendor due diligence and ongoing supplier management.

Who it affects
Essential and important entities in sectors such as water, energy, transport, health, digital infrastructure and public administration.
What it requires
Appropriate cybersecurity risk-management measures, incident reporting, and accountability at management level.
Why suppliers matter
Regulated organisations must consider cybersecurity risk in their direct suppliers and service providers, not only in their own systems.
Why it matters to a water utility
The continuity and security of an essential service increasingly depend on the resilience of the wider digital supply chain.
NIS2 does not require this of us. We required it of ourselves.

The directive is an EU instrument, but resilient security should not stop at a regulatory boundary. We apply the same principles to how we build and operate the service, wherever a customer uses it. EU regulation, global security mindset.

What we hold

The evidence,
published.

Same rule as the Proofroom: no proof means no claim. Every line below either links to a document or says plainly that it does not yet.

ISO/IEC 27001:2022 certificate
Certificate K-0222779, issued to HULO B.V. by Kiwa. The PDF is shared on request rather than published, per our certification body's publication rules.
NIS2 Supply Chain mark
NIS2 Quality Mark SC30, the level written for suppliers to critical infrastructure. Audited 18 March 2026, valid to 18 March 2029, registered at Zuiderplein 4–6, Leeuwarden. Verifiable in the public registry without contacting us.
What the mark is not
It is not an EU regulatory certification, because none exists for NIS2. It is an independently audited supply-chain attestation. Your own NIS2 obligations remain yours; this evidences the supplier side of them.
The comparison

Check it
yourself.

Every vendor a water utility might shortlist, against the five certifications that come up in procurement. We lose three of these five columns. They are on the page anyway, because a comparison table that its author always wins is not a comparison table. Every name links to where we read the claim.

VendorISO/IEC 27001NIS2 Quality MarkISO/IEC 42001SOC 2Cyber Essentials Plus
HULO
Qatium
Flowless
Hydroscan
TaKaDu
Asterra
AGANOVA
FIDO
Baseform
Bentley
Xylem
SUEZ

COMPILED FROM PUBLIC SOURCES · LAST CHECKED 21 AUGUST 2026
FOUND AN ERROR? TELL US AND WE WILL CORRECT THIS TABLE.

Bentley. Its ISO 27001 covers an information security and a privacy management system together (27001:2022 with 27701:2019), across Bentley global corporate systems and the Bentley and Seequent commercial product infrastructure, including managed services, Eagle.io, and DataConnect and ComplyPro hosting.

Xylem. Also holds ENS, the Spanish national scheme that maps onto GDPR, NIS2 and ISO 27001 for public-sector suppliers, and ISO 9001, ISO 14001 and ISO 45001 for quality, environment and health and safety.

FIDO. Also holds ISO 9001 for quality management.

What we do not hold, and why we say so

Nobody in this market holds ISO/IEC 42001 for AI management systems yet, including us. Bentley holds SOC 2 and we do not. Bentley, Xylem and FIDO hold UK Cyber Essentials Plus and we do not. All of that is on this page because you would find it anyway, and a supplier who tells you only the flattering half of a comparison has told you something about themselves.

A badge is a picture.
A registry entry is a fact.

Which is why the certificate number and the public registry link are on this page, and the logo is not the point.

Architecture

Why HULO is a
small risk to add.

Most of a vendor's risk profile is decided by how it connects, not by which certificate it holds. Ours connects in the least invasive way the job allows.

No hardware in your network
Nothing is installed, racked or cabled. There is no HULO device inside your OT perimeter that could be compromised or that you would have to patch.
Read-only by design
HULO consumes data. It does not write to SCADA and cannot actuate a valve, a pump or a setpoint. Even a fully compromised HULO account cannot operate your network.
Data residency
Your data is processed and stored in your region.
Personal data
Network telemetry is not personal data. Where any personal data is involved, it is limited to named users of the software.
Your security officer will ask

The awkward
questions.

Written for the person whose job it is to say no. Answering these badly is how a good product loses a procurement round it should have won.

Are you actually NIS2 certified?

Not in the regulatory sense, and no vendor is. NIS2 is a directive, and no EU body issues a compliance certificate against it. Anyone telling you otherwise is selling something. What we hold is the NIS2 Quality Mark at SC30, independently audited by an accredited auditor and listed in a public registry you can check without asking us. Alongside ISO/IEC 27001:2022 from Kiwa, that covers the supplier-side evidence your own NIS2 assessment needs.

What does ISO 27001 mean for customers?

HULO is certified to ISO/IEC 27001:2022. Our information security management system helps us manage security across our people, processes, technology and suppliers, and improve it continuously. It is an organisation-wide system, not a certificate scoped to one product or one environment.

What is NIS2 SC30?

NIS2 is an EU directive that requires covered organisations to manage cybersecurity risks, including risks in their supply chain. HULO has been assessed against the NIS2 Quality Mark SC30, the level written for suppliers operating in the highest-risk context, including suppliers to critical infrastructure. The assessment and the certificate reference are on this page, for transparency.

Why should we trust a private mark?

On its own, do not. Trust the audit behind it and the registry entry that makes it checkable. That is precisely why we publish the registry link rather than a badge image. A badge is a picture. A registry entry is a fact.

How do you protect customer information?

We use a risk-based, layered approach that includes controlled access, strong authentication, encryption, secure development practices, monitoring, backup and recovery measures, and security awareness.

Who can access customer information?

Access is limited to authorised people who need it for their role. We apply least-privilege principles and manage access throughout the employee lifecycle.

How do you keep the platform secure?

Security is built into the way we develop and operate our services, through secure design, code review, controlled changes, security testing, and separated environments for development, testing and production.

How do you manage cloud services and suppliers?

We take a risk-based approach to suppliers and cloud services. Security, privacy and continuity are considered when selecting and managing the providers that support our services.

How do you respond to security incidents or disruption?

HULO maintains documented processes for security incidents, continuity and recovery. We review and test these arrangements to support a timely, coordinated response and continual improvement.

Does connecting HULO expand our attack surface?

It adds an outbound data path and nothing else. No inbound control channel, no installed device, no write access. The realistic worst case is disclosure of network telemetry, not loss of operational control.

How do you approach privacy?

We are committed to protecting personal data and apply appropriate organisational and technical measures. Privacy is considered in our policies, processes and supplier arrangements. Network telemetry is not personal data; where personal data is involved, it is limited to named users of the software.

How do you keep security up to date?

Security is an ongoing process. We monitor relevant risks, review our controls, train our people, and use findings from reviews and tests to improve our approach.

Can I request more security information?

Yes. Customers and prospective customers can request further security and privacy information through our due-diligence process. Ask us by e-mail and you get access to the trust centre, with the documents listed at the foot of this page.

Document pack

Ask once.
Get everything.

Send us an e-mail and we open the trust centre to you: one request, one reply, everything a supplier assessment needs. No sales call in between, and no discovery workshop before you are allowed to read a certificate. Customers and prospective customers can ask at any point in a due-diligence process.

01
ISO/IEC 27001:2022 certificate
The certificate itself, with the audited date and the validity period.
02
NIS2 mapping
Which obligations we meet and how they are evidenced.
03
Architecture & data flow
What crosses which boundary, and in which direction.
04
Pen test summary
Most recent, under NDA where required.
05
Sub-processor list
Current, with hosting regions.
06
Pre-filled questionnaire
Our answers to the standard supplier security set, ready to paste.

Sign up for our newsletter

What we found, on which network, and what it cost to find it. Roughly monthly, and never a figure we cannot show you the working for.

Backed by our partners

  • LUMO Labs
  • NEW, Netherlands Enabling Watertechnology
  • Vanagon
  • VP Capital
  • FOM, Friese Ontwikkelings Maatschappij
  • Co-financed by the European Union

Part of the ecosystem

  • SWAN Asia-Pacific Alliance
  • Water Alliance
  • Isle
  • Partners for Water
  • NWP, Netherlands Water Partnership
  • Water Positive
  • BMW Foundation Herbert Quandt

HULO’s project Lekker (tegen lekken) is co-financed by the European Union, by SNN and by the Dutch Ministry of Economic Affairs.

Medegefinancierd door de Europese Unie SNN, Samenwerkingsverband Noord-Nederland Ministerie van Economische Zaken, the Dutch Ministry of Economic Affairs