Procurement trust

Trust begins with what can be checked.

A precise view of the evidence in the product and of the work that still needs verification, documentation or operational confirmation.

A Dossier Secure evidence library with governance records, controls and reconstructionEen Dossier Secure bewijsbibliotheek met governancestukken, controls en reconstructie

Product evidence

The evidence path is strongest where each condition stays visible.

01

Evidence integrity

Hash chain

The product evidence records an append-only, hash-chained trail and verifies divergence when a supplied hash changes.

Technical product evidence
02

RFC 3161

Timestamp verification

RFC 3161 timestamp verification is evidenced. It is not qualified under eIDAS until a QTSP upgrade is in place.

Technical evidence; eIDAS qualification not established
03

Identity structure

Roles and SAML

Application roles are evidenced. SAML 2.0 service-provider endpoints and assertion verification are evidenced in the application.

Implementation evidence; scope needs confirmation

Open status

A clear gap is more useful than a broad promise.

04

Access controls

MFA and least privilege

Server-enforced MFA for administration is not currently live-proven. Roles exist, but further separation of administrative responsibilities remains required; least privilege is not presented as complete.

Not established / partial
05

Operations

Recovery and response

Repository evidence describes backup-health checks and a historic restore test; this is not a current DR attestation. Current evidence does not establish an operational incident-response process with automated human alerting.

Evidence needs refresh / not established
06

Infrastructure and documents

Evidence to establish

This page does not claim a specific hosting location, data-residency commitment, AES-256 at-rest evidence, in-transit encryption evidence, DPA, subprocessor register, SLA or a current independent penetration-test report.

Not established

Published authority

Can Your Board Record Speak For Itself?

Adriana Coppelmans, founder Dossier Secure, author of Board Decisions Under Scrutiny

Published in The Corporate Board

THE CORPORATE BOARD, September/October 2026

On the reconstructability of board decisions and the personal accountability of directors under European cyber and operational-resilience rules.

Verschenen in een gevestigd Amerikaans vakblad over corporate governance voor bestuurders en senior executives, biedt het artikel lezers een bron buiten deze site om de analyse zelf te beoordelen.

Dit is geen certificering of aanbeveling van Dossier Secure. Het is een gepubliceerde bron die lezers zelf bij de uitgever kunnen verifiëren.

Adriana Coppelmans bracht 30 jaar door in governance, audit en institutionele verantwoordelijkheid in Nederland, met jarenlange ervaring in de Nederlandse zorgsector.

Request publication information

Roadmap, not ownership

ISO 27001 and SOC 2 are roadmap items, not held certifications.

No certification, compliance status or regulator approval is claimed here. A private evidence review can focus on the controls and documentation relevant to your procurement scope.

Request a private evidence review