Table of Contents

Boltrics Security

At Boltrics we take security of your data very seriously. We are proud to have obtained the Data Pro Verified label. With this, Boltrics demonstrates its commitment to adhering to the highest standards of data protection and privacy; processing data according to NLdigital's officially approved AVG code of conduct; the Data Pro Code.

For more information about our security measures, including how we use encryption, access control, which data of our customers is processed, who has access to your data, data backup and recovery etc., please see Boltrics Data Pro Statement and Microsoft Business Central Security | Learn 3PL Dynamics.

Business Code of Conduct

Boltrics strives to conduct its business with integrity. As Microsoft Partner, Boltrics must comply with the Microsoft Partner Code of Conduct and the Anti-Corruption Policy for Microsoft Representatives, which are therefore part of its own Code of Conduct. Boltrics requires its relations to conduct their business under similar standards.

FAQ

Question Answer
Does Boltrics have a security and privacy program and policies? Yes, Boltrics has both internal and external security policies. Please refer to our Information Security & Cybersecurity Overview for more details. You can also find our external Privacy and Security policies via the following public link: Legal - Boltrics.
What does the Data Pro Verified label entail? As a Data Pro Verified organization, Boltrics follows the principles in the Data Pro Code. The Data Pro Code is a practical translation of the AVG for processors. The Code provides concrete rules of conduct. An external, independent supervisor monitors the quality and compliance with the Data Pro Statement. The Data Pro Code was approved by the Dutch DPA in 2020 and perpetuated in 2023 with the final accreditation of a supervisory body: SCOPE Europe. This makes the Data Pro Code the first Dutch and fifth European fully approved AVG code of conduct. Organizations that receive the Data Pro Verified label are included in the public registry of Data Pro Verified organizations. This registry can be found on SCOPE Europe's website: Public Register of the Data Pro Code.
Does Boltrics have a designated security/privacy lead who manages your security program? Yes, see Data Pro Statement for contact information. We often see clients asking for a generic ISO certification, thinking it covers all AVG obligations. However, it depends entirely on which certification an organization has and to what extent it covers AVG obligations. But in all cases the following applies: Data Pro Verified is an independent alternative to an ISO certification. An approved code of conduct, such as the Data Pro Code, has an official status in the AVG and can be used by the customer in his DPIA (data protection impact assessment), for example, to substantiate that he can use our product or service.
Does Boltrics' product 3PL Dynamics comply with ISO and SOC standards? Yes, in that Microsoft's Azure and Dynamics BC, which form the basis of 3PL Dynamics, have the ISO and SOC certifications as can be found at or through Certification | Boltrics.
Do you have a security awareness training program for organization members? Yes.
Do you have a data access control and a passwords policy? Yes.
Do you manage your own datacenter and servers? Boltrics makes use of the datacenters and/or servers of Microsoft, see Data Pro Statement. For more information on Microsoft's security measures see Microsoft Business Central Security | Learn 3PL Dynamics.
Do you have a server software update policy? Yes, as described in Data Pro Statement, Microsoft Business Central Security | Learn 3PL Dynamics and Boltrics lifecycle policy | Learn 3PL Dynamics.
Does Boltrics enable data subjects' rights of access, rectification, erasure, blocking and objection? Yes, as described in Data Pro Statement and Boltrics Privacy Statement as available on Legal - Boltrics.
Does Boltrics maintain a Code of Conduct? Yes.
Which matters are covered by the Code of Conduct? Among others, Business Practices, Ethics, and Compliance, including Anti-Corruption, antitrust and fair competition; Human Rights and Fair Labor Practices; Security of information; and Environmental Regulations and Protections. The information on this page is subject to change from time to time.
Does Boltrics perform data backups? Boltrics' solutions operate on Microsoft cloud services, where primary backup, database redundancy and disaster recovery for Business Central and relevant Azure services are performed by Microsoft in accordance with the applicable Microsoft service framework. For systems, configurations or data managed by Boltrics outside those Microsoft SaaS services, Boltrics maintains its own backup and recovery processes.
How is backup reliability ensured? Backup and recovery arrangements are aligned with service criticality. Boltrics relies on Microsoft's controls for the underlying cloud services and maintains internal monitoring, documentation and review for backup processes for which Boltrics itself is responsible.
Does Boltrics test disaster recovery and restore procedures? Boltrics maintains business continuity and disaster recovery arrangements as part of its ISMS. Microsoft provides resilience and recovery capabilities for the underlying cloud services, while Boltrics periodically tests and evaluates the continuity and recovery measures for processes and systems for which it is responsible.
How does Boltrics manage changes to its software? Boltrics applies a structured change management process under which changes are documented, reviewed, tested and assessed before implementation in production environments.
How are systems monitored for security incidents? Boltrics applies monitoring and logging measures at both application and platform level, supported by internal incident response and review processes. For underlying cloud and platform services, Boltrics also relies on relevant Microsoft security capabilities.
Does Boltrics perform vulnerability management? Yes. Boltrics maintains processes to identify, assess and address vulnerabilities for its own applications, integrations and extensions, including identification, assessment, prioritisation and remediation of vulnerabilities. For the underlying Microsoft platform services, Boltrics relies on Microsoft's responsibilities and assurance framework.
Are penetration tests performed? Yes. Boltrics conducts periodic security testing as part of its security practices, including independent testing where appropriate. Further details are not publicly disclosed for security reasons but may be shared under appropriate conditions.
Does Boltrics maintain a cybersecurity risk management framework? Yes. Boltrics maintains a structured, risk-based information security and cybersecurity framework as part of its ISMS. Risks are identified, assessed, documented and treated, and are periodically reviewed by management.
Can Boltrics support customers in audits or third-party risk assessments? Boltrics can provide relevant information to support customer audits or risk assessments. Additional documentation may be shared upon request and subject to appropriate confidentiality arrangements.
Does Boltrics provide detailed security documentation (e.g. backup configurations, monitoring logs)? Boltrics provides high-level information publicly. More detailed or sensitive information may be shared on a case-by-case basis where appropriate and proportionate.
Which security responsibilities are covered by Microsoft? Boltrics solutions are built on Microsoft Azure and Dynamics 365 Business Central. These Microsoft services provide the underlying cloud infrastructure and platform on which the Boltrics solution operates. Microsoft is responsible for the security measures within its cloud services, including areas such as physical datacenters, network infrastructure, and platform-level controls, as described in Microsoft's own documentation.
How does Boltrics maintain and improve its security posture? Boltrics continuously evaluates and improves its security measures, taking into account industry standards, customer requirements, and regulatory developments such as NIS2.
Does Boltrics complete and sign customer security questionnaires? Boltrics does not generally complete or sign individual customer-specific security questionnaires or statements. Instead, Boltrics provides a standardized Security Documentation Package, which contains relevant and up-to-date information about its governance, security, and compliance framework. This approach ensures consistency, accuracy, and efficiency across all customer engagements.
What is included in the Boltrics Security Documentation Package? The Security Documentation Package typically includes: governance and security framework documentation (external overview); data processing and data protection documentation (including Data Pro materials); certifications and compliance-related documentation; privacy and code of conduct documentation; support and SLA-related governance documentation; and relevant information regarding underlying platform providers (e.g. Microsoft). The exact contents may be updated from time to time to reflect changes in Boltrics' services, regulatory requirements, or security practices.
Why does Boltrics not complete individual questionnaires or statements, including acceptance of third-party codes of conduct? Customer-specific questionnaires often vary in scope and format. By providing a standardized documentation package, Boltrics ensures that: information is consistent and aligned with Boltrics' policies, contractual framework, and applicable legal and contractual obligations; Boltrics does not assume obligations that may conflict with its own policies or applicable frameworks; sensitive security details are not unnecessarily disclosed; and customers receive validated and up-to-date information. Where appropriate, Boltrics may clarify or supplement the provided documentation.
Can additional information be shared if required for audits or NIS2 compliance? Yes. Boltrics understands that customers may be subject to regulatory requirements such as NIS2 or third-party risk management obligations. Additional information may, where appropriate, be shared on a case-by-case basis, subject to relevance, proportionality, appropriate confidentiality arrangements, and other applicable conditions.
Does the documentation package include detailed technical configurations or evidence (e.g. backup logs, monitoring outputs)? No. The publicly shared documentation provides a high-level overview of Boltrics' security and governance framework. Detailed internal configurations and operational controls are intentionally not disclosed for security reasons. Where necessary, additional information may be shared under appropriate conditions.