ssm.ro Docs
Compliance & Data ProtectionCompliance & Audit

Compliance Framework

The platform's compliance framework and compliance register

The SSM.ro compliance framework brings together the applicable legal and security requirements and maps them to the implemented controls.

Compliance Domains

DomainRequirementControls / Reference
Data ProtectionGDPR, Law 190/2018GDPR Section; DPO; ROPA
Electronic SignatureeIDAS Regulation (910/2014)Qualified Trust Service Provider (QTSP) for electronic signatures
Information SecurityISO/IEC 27001 (certified); SOC 2 alignmentCertifications and Standards; Trust Center
SSM / PSI (Occupational Health & Safety / Fire Prevention and Firefighting)Labor and fire safety legislationCore platform functionality
Security in the Absence of a WAFApproved compensating controlsNetwork Security

Compliance Register

Compliance is supported by a set of versioned documents v1.0 (2026-04-29), reviewed annually:

DocumentRole
Data Flow Diagram (DFD)Mapping of data flows
Architecture DiagramComponents and network flows
Risk Register12 risks, controls, residual risk
Roles CatalogRoles and authorized operations
WAF Compensating Controls MemoApproved substitution for the WAF
Operational SOPBackup, DR, and patching

These documents are provided to clients upon request — see Reports Available to Clients.

Governance

  • Owner: SSM.ro security / compliance team, with DPO support
  • Review: annually or upon significant architectural changes
  • Applicable Legislation: see Applicable Legislation