For most buyers this is not the last question. It is the first one.
A strategic plan says what an organization is betting on, what it is giving up, which numbers it is worried about, and who is accountable. There are few documents you would less like to see leak. So everything below applies on every plan, including the trial.
ISO 27001:2022 certified
Toolsfactory is certified against ISO 27001:2022, audited by Brand Compliance under accreditation from the Dutch Accreditation Council.
The distinction that matters: the certificate is issued by someone whose job is to find the gaps, and re-checked every year. Policies, risk assessments, access reviews, incident handling and supplier management all sit inside that scope.
Where your data lives
This is the question European buyers ask first, and the answer is short.
The platform runs in the Netherlands. Hosting is with Tilaa, a Dutch provider. All data is stored encrypted.
Backups stay in the EU. To survive a supplier failure rather than just a disk failure, backups are held with two separate providers, Azure and Scaleway, both on EU servers. They are stored encrypted, so neither supplier can read them.
The AI runs in the EU too. More on that below.
Every subprocessor that touches your data is named in the privacy statement, with what it does and on what basis.
Who can see what
Confidentiality inside an organization matters as much as confidentiality outside it. Not every plan should be visible to everyone, and the sensitive part is usually the reporting rather than the plan.
Access is controlled per team, with four roles:
- Viewer. Can read the plan, and nothing else
- Responder. Can read and comment
- Participant. Can edit items in the plan
- Administrator. Full control of that team’s OGSM
User groups carry those permissions for a set of people rather than one at a time, which is what keeps access management from decaying as the organization changes. Where someone holds both an individual and a group role, the one granting more permissions applies.
At environment level, an administrator reaches settings and user management; a user does not.
Signing in
Two-factor authentication is available on every plan, not held back for the enterprise tier. Security that costs extra tends not to get switched on.
Single sign-on with Microsoft Entra ID, formerly Azure AD, is included on every plan. For most organizations of any size this is the answer to onboarding and, more importantly, to offboarding: access ends when the account does.
Encryption
Data is encrypted in transit and at rest. The website and application are served over TLS. Email is protected with DKIM, SPF and DMARC, and the domain is signed with DNSSEC.
AI and confidentiality
The AI features are the ones people quite reasonably ask hardest about. Four things.
The provider is Mistral, a European company, and the data stays inside the EU. That is a deliberate choice and, in this market, an unusual one.
Your input is never used to train models.
You review before you send. You can remove confidential information from what goes to the AI, rather than discovering afterwards what was included.
An administrator can turn it off entirely for the whole environment. If your policy says no AI, the answer is a switch, not a support ticket.
GDPR
Toolsfactory is a Dutch company operating under the GDPR. The privacy statement lists every subprocessor by name, what personal data is processed and on what legal basis, how long it is retained, and how to access, correct or delete it.
A data processing agreement is available. Ask, and you will get one.
This website
Worth stating because it is unusual: this site sets no cookies and shows no cookie banner.
Analytics run on Plausible, which is cookieless and collects no personal data. Video embeds load only when you click them, so nothing third-party runs until you ask for it. Fonts are served from this domain rather than from Google.
A company asking you to trust it with your strategy should not be quietly tracking you while it does so.
Transparency and reporting a problem
Live service status is at status.ogsm.online.
Found a vulnerability? Email help@toolsfactory.nl. We would much rather hear it from you.
Trusted by government organizations, pension administrators and international enterprises across 20 countries.