40 years of DESANResearch technology and delivery since 1986

Quality & security

Research data requires demonstrable care.

DESAN combines certified research processes, information security, Security & Privacy by Design and fully managed proprietary infrastructure.

ISO 20252ISO 27001Own infrastructurePeriodic penetration testing

Layered control

01
Research processDefined controls, roles and quality checkpoints
ISO 20252
02
Information securityPolicies, risks, access, monitoring and incidents
ISO 27001
03
ApplicationsSecurity & Privacy by Design, MFA and penetration testing
By design
04
InfrastructureTwo Dutch data centres and dedicated fibre
Managed in-house
ISO 20252Control of professional research processes
ISO 27001Certified information security management system
Hosting in the NetherlandsProprietary infrastructure in two Dutch data centres
MFASupported in all applications developed by DESAN
Penetration testingPeriodic testing of applications and office and data-centre networks

Research quality

Quality is monitored throughout the process.

Good research data is not created only during analysis. Quality is built from research design and questionnaire development through fieldwork, data validation and delivery.

02 · Configuration

Controlled programming

Routing, validations, quotas, invitations and reports are tested before fieldwork starts.

03 · Delivery

Active fieldwork management

Response, distribution, deviations and quality signals are monitored during delivery.

04 · Delivery of results

Auditable results

Data is validated and delivered according to agreed specifications, including reporting where required.

Protection of research data

Secure data exchange and controlled access.

Research files and personal data are exchanged through a secure transfer process. Receipt confirmation shows when files have been received safely. Within IT5 and custom applications, access is limited to users who need it.

Secure transferSensitive data is not exchanged as a standard email attachment.
Separated environmentsClient research data is logically separated within the dedicated tenant.
MFA and access managementMulti-factor authentication is supported in all applications developed by DESAN.
Monitoring and loggingSystems, availability and security signals are centrally monitored.
DesignPrivacy, data minimisation and access requirements are considered from the outset.
DevelopmentSecurity principles are part of the software architecture and code.
TestingFunctional testing, security testing and periodic external penetration testing.
ManagementChanges, monitoring, incidents and recovery are managed in a controlled manner.
Security &
Privacy by Design
IT5 and custom applications

By design

Security is not added as an afterthought.

IT5 and custom applications are designed from the outset with attention to security, privacy, access management and auditable processing.

  • Data minimisation and purpose limitation
  • Roles and permissions aligned with responsibilities
  • Secure defaults and MFA support
  • Security testing as part of development and management
  • Periodic penetration testing by external specialists

Own infrastructure

Full control without dependence on Big Tech.

DESAN’s core infrastructure runs on proprietary systems in two Dutch data centres. Dedicated fibre connections link the office and data centres and support redundancy, continuity and direct technical control.

01
Two Dutch data centresSystems and facilities are distributed across two locations.
02
Dedicated fibre infrastructureRedundant connections between the office and data centres.
03
In-house technical managementServers, networks, hosting and security layers are managed by DESAN.
04
Backup and recoveryBackups, recovery procedures and continuity measures are part of management.
DESANOffice, management and network control
Dutch data centre 1Applications, data and redundant facilities
Dutch data centre 2Continuity, backup and recovery facilities
Redundant dedicated fibre connections

Testing and continuity

Security is tested, monitored and improved.

Technical measures only have value when their operation and follow-up are also verified.

Periodic penetration testing

Applications and office and data-centre networks are periodically assessed by external specialists.

Backup and recovery

Backups, recovery procedures and continuity measures support recovery after technical or operational disruptions.

Certification and assessment

Demonstrable control, independently assessed.

DESAN operates according to certified standards for information security and research processes. External certification and assessments provide transparency for clients.

EcoVadis BronzeAn additional assessment of sustainable and responsible business. This is separate from information security certification but forms part of the broader quality policy.
ISO 27001 certified by CIIO

ISO 27001

Certified information security management system.

The certification covers the controlled organisation and continual improvement of information security within DESAN.

Frequently asked questions

Practical answers about data, hosting and access.

DESAN can provide targeted information on additional requirements during an introductory meeting or procurement procedure.

Where is research data hosted?

DESAN’s core infrastructure runs on proprietary systems in two Dutch data centres.

Does DESAN depend on a public Big Tech cloud?

No. Core hosting and technical infrastructure are managed by DESAN itself, giving DESAN direct control over systems, networks and data storage.

How are sensitive files transferred?

Sensitive data is exchanged through a secure transfer process, including receipt confirmation.

Do DESAN applications support MFA?

Yes. Multi-factor authentication is supported in all applications developed by DESAN.

Are applications and networks independently tested?

Yes. External penetration tests are periodically performed on applications and on office and data-centre networks.

Quality and security requirements

Discuss the requirements that apply to your research.

DESAN can explain how research processes, data transfer, hosting, access management and continuity will be organised for your project.

Discuss your requirements