generated: '2026-09-02' method: searched source: >- Certification badges published in the site footer of https://www.cadasto.com/ (HTTP 200, fetched 2026-09-02), the openEHR conformance statement at https://www.cadasto.com/wp-content/uploads/2026/06/Cadasto-CDR-openEHR-conformance-statement-June-2026.pdf (HTTP 200), and https://www.cadasto.com/privacy-and-cookie-statement/ (HTTP 200). description: >- Cadasto has NO dedicated trust center, security portal or compliance page. Its published compliance posture consists of three certification badges in the site footer, a privacy and cookie statement, and a security.txt contact. There is no downloadable SOC 2 report, no ISO certificate document, no subprocessor list, no DPA template and no uptime/status page on any anonymously reachable host. trust_center_url: null certifications: - name: ISO 9001 domain: Quality management systems status: displayed evidence: Badge image in the footer of https://www.cadasto.com/ certificate_document: null auditor: not published - name: ISO/IEC 27001 domain: Information security management systems status: displayed evidence: Badge image in the footer of https://www.cadasto.com/ certificate_document: null auditor: not published - name: NEN 7510 domain: Information security in Dutch healthcare (the NL sector extension of ISO 27001) status: displayed evidence: Badge image in the footer of https://www.cadasto.com/ certificate_document: null auditor: not published regulatory_context: jurisdiction: Netherlands / European Union regime: healthcare applicable: - GDPR / EU 2016/679 (Cadasto processes patient data on behalf of care providers) - NEN 7510 (mandated information-security norm for Dutch healthcare) - EHDS (European Health Data Space) — not referenced by Cadasto privacy_policy: https://www.cadasto.com/privacy-and-cookie-statement/ dpa_published: false subprocessors_published: false data_handling_claims: - claim: The FHIR facade does not persist FHIR messages detail: >- "Because it is a FHIR facade the FHIR messages are not stored" — openEHR conformance statement, Additional Cadasto CDR Features. - claim: Deletes in the EHR API are logical, not physical detail: >- "Deletions are logical — the data is marked as deleted but remains in the version history for audit purposes" — https://docs.cadasto.io/docs/quick-start. Physical deletion requires the separate Admin API. - claim: Credentials are isolated per environment detail: >- "Credentials for development, acceptation, and production are separate. Treat each set independently." — https://docs.cadasto.io/docs/faq. gaps: - No trust center or security page exists; the certifications are asserted only by a footer image. - No certificate numbers, issuing bodies or validity dates are published for any of the three certifications. - No SOC 2, PCI DSS, HIPAA or FedRAMP claim is made (none is expected for a Dutch care-data processor). - No status page, uptime history or SLA document was found on any Cadasto host.