Trust

Security, privacy and where your data lives

Your strategic plan is one of the most confidential documents your organization owns. We treat it that way.

For most buyers this is not the last question. It is the first one.

A strategic plan says what an organization is betting on, what it is giving up, which numbers it is worried about, and who is accountable. There are few documents you would less like to see leak. So everything below applies on every plan, including the trial.

ISO 27001:2022 certified

ISO 27001:2022 certified, Brand Compliance, RvA C 548

Toolsfactory is certified against ISO 27001:2022, audited by Brand Compliance under accreditation from the Dutch Accreditation Council.

The distinction that matters: the certificate is issued by someone whose job is to find the gaps, and re-checked every year. Policies, risk assessments, access reviews, incident handling and supplier management all sit inside that scope.

Where your data lives

This is the question European buyers ask first, and the answer is short.

The platform runs in the Netherlands. Hosting is with Tilaa, a Dutch provider. All data is stored encrypted.

Backups stay in the EU. To survive a supplier failure rather than just a disk failure, backups are held with two separate providers, Azure and Scaleway, both on EU servers. They are stored encrypted, so neither supplier can read them.

The AI runs in the EU too. More on that below.

Every subprocessor that touches your data is named in the privacy statement, with what it does and on what basis.

Who can see what

Confidentiality inside an organization matters as much as confidentiality outside it. Not every plan should be visible to everyone, and the sensitive part is usually the reporting rather than the plan.

Access is controlled per team, with four roles:

  • Viewer. Can read the plan, and nothing else
  • Responder. Can read and comment
  • Participant. Can edit items in the plan
  • Administrator. Full control of that team’s OGSM

User groups carry those permissions for a set of people rather than one at a time, which is what keeps access management from decaying as the organization changes. Where someone holds both an individual and a group role, the one granting more permissions applies.

At environment level, an administrator reaches settings and user management; a user does not.

User groups in OGSM.online, each carrying permissions for a set of people across several teams
A group carries the permissions for a set of people, across as many teams as it needs to.

Signing in

Two-factor authentication is available on every plan, not held back for the enterprise tier. Security that costs extra tends not to get switched on.

Single sign-on with Microsoft Entra ID, formerly Azure AD, is included on every plan. For most organizations of any size this is the answer to onboarding and, more importantly, to offboarding: access ends when the account does.

Encryption

Data is encrypted in transit and at rest. The website and application are served over TLS. Email is protected with DKIM, SPF and DMARC, and the domain is signed with DNSSEC.

AI and confidentiality

The AI features are the ones people quite reasonably ask hardest about. Four things.

The provider is Mistral, a European company, and the data stays inside the EU. That is a deliberate choice and, in this market, an unusual one.

Your input is never used to train models.

You review before you send. You can remove confidential information from what goes to the AI, rather than discovering afterwards what was included.

An administrator can turn it off entirely for the whole environment. If your policy says no AI, the answer is a switch, not a support ticket.

How AI works in OGSM.online →

GDPR

Toolsfactory is a Dutch company operating under the GDPR. The privacy statement lists every subprocessor by name, what personal data is processed and on what legal basis, how long it is retained, and how to access, correct or delete it.

A data processing agreement is available. Ask, and you will get one.

This website

Worth stating because it is unusual: this site sets no cookies and shows no cookie banner.

Analytics run on Plausible, which is cookieless and collects no personal data. Video embeds load only when you click them, so nothing third-party runs until you ask for it. Fonts are served from this domain rather than from Google.

A company asking you to trust it with your strategy should not be quietly tracking you while it does so.

Transparency and reporting a problem

Live service status is at status.ogsm.online.

Found a vulnerability? Email help@toolsfactory.nl. We would much rather hear it from you.

Trusted by government organizations, pension administrators and international enterprises across 20 countries.

Frequently asked questions

Is OGSM.online ISO 27001 certified?

Yes. Toolsfactory is certified against ISO 27001:2022 and audited annually by Brand Compliance under RvA accreditation.

Where is our data stored?

On servers in the Netherlands, hosted by Tilaa. Backups are held encrypted with two separate providers, Azure and Scaleway, both inside the EU.

Which AI provider does OGSM.online use?

Mistral, a European provider, with data held inside the EU. AI input is never used to train models, and an administrator can switch the AI off for the whole environment.

Does OGSM.online support single sign-on?

Yes. Single sign-on with Microsoft Entra ID, formerly Azure AD, is included on every plan, as is two-factor authentication.

Where is our data processed?

The platform, its backups and its AI processing are all inside the EU. Every subprocessor is named in the privacy statement, with what it does and on what legal basis.

Does the website use cookies?

No. Analytics on this website run on Plausible, which is cookieless, so there is no cookie banner. The application itself uses functional cookies only, listed in the privacy statement.

Ready to turn your strategy into results?

Try OGSM.online free for 30 days. No credit card required, and the trial stops automatically.