Loading...


Certifications and Transparency: The Autonoma Trust Center

Stefanie Gruber

Autonoma Trust Center (8)

Companies trust us with their valuable production and machine data. We take this responsibility very seriously and are committed to being transparent about it with our customers and their end customers.

That is why we created the Autonoma Trust Center: a single place where you can see exactly how we put security, data protection, and compliance into practice.

A Closer Look at the Trust Center

The Trust Center consolidates everything relevant to your own security review:

  • Certifications such as ISO 27001, ISO 27017, and GDPR compliance
  • Supplier assessment and proof of NIS2 compliance
  • Security documentation, including our Statement of Applicability (SoA), Data Processing Agreement (DPA), and a list of data subprocessors we use
  • A full breakdown of our technical and organizational measures - from access control to encryption to incident response
  • Answers to frequently asked questions (FAQs)


Overview: Autonoma Trust Center

Relevance to our customers

Connecting machine-, process-, or customer data to a platform carries a degree of business risk. This is precisely why IT and compliance teams review every new vendor before establishing that connection.

The Trust Center provides that proof directly and verifiably, without requiring a sales conversation. It accelerates your security review, shortens approval processes, and provides the documentation your internal audits or tenders require in any case. For companies that are themselves accountable to regulated customers, this represents a competitive advantage: If you can demonstrate that your own suppliers meet verifiable security standards, you save time and effort on your own customer and compliance inquiries.

In practice, that means: the Trust Center reduces time in the procurement process and lowers the risk of relying on a vendor whose security posture cannot be demonstrated.

Access to all Security documents

Customers can request access to the complete set of security documents, like certificates, contracts, evidence, through a single, one-time request. Once approved, access remains in place, and customers are notified automatically by email whenever new certifications or documents are added.


Request for Access to the Autonomous Trust Center

ISO 27001: The foundation of our security management

The certifications in the Trust Center are not standalone credentials. They form part of one connected security program, which starts with ISO/IEC 27001:2022.

ISO 27001 is the internationally recognized standard for an organization's Information Security Management System (ISMS). The certification confirms more than the existence of individual technical measures: it confirms that security is organized as an ongoing process. Risks are systematically identified, assessed, and treated, responsibilities are clearly assigned, and the effectiveness of these measures is audited externally on a regular basis.

For customers, this means Autonoma is reviewed not only internally, but by an independent, external body, on an annual basis. The certificate, along with the Statement of Applicability, which specifies exactly which controls from the ISO 27001 catalog have been implemented, is available in the Trust Center.

ISO 27017: Additional controls built specifically for cloud services

ISO/IEC 27001:2022 establishes the universal foundation for our security management. ISO/IEC 27017:2015 builds directly on this foundation, extending our ISMS with controls precisely tailored to modern cloud environments.

This addresses risks that classic security standards often overlook: clear separation of customer data in a multi-tenant environment, a clear division of responsibility between cloud provider and customer, and secure handling of administrative access to cloud infrastructure.

For customers, this means Autonoma meets not only general security requirements, but also additional controls that apply specifically to operating a cloud platform, including a clear delineation of which security tasks are Autonoma's responsibility and which belong to the customer. More on this below.

NIS2: Preparing for the EU's new cybersecurity directive

Starting October 1, 2026, NIS2 raises the EU's cybersecurity requirements for companies classified as essential or important. A considerably larger group than under the previous directive, and one that directly affects many OEMs and their suppliers for the first time.

We started preparing for NIS2 early on. Most of the required technical and organizational measures are already covered by our existing ISO 27001 ISMS. We have deliberately extended this foundation to meet NIS2's specific requirements, in particular its strict incident reporting obligations and its requirements for supply chain risk management.

For customers, this means: if NIS2 applies to your organization, you must also be able to classify and secure your own suppliers accordingly. Our Trust Center provides a detailed breakdown of how our ISO 27001 framework maps to NIS2 requirements, along with the "NIS2 Contract," available for direct download.

GDPR: Data protection as a baseline, not an add-on

For any company handling European customer data, GDPR is not optional, it’s a legal requirement. For Autonoma, it forms a core part of our security program, not a compliance chapter added afterward.

In practice, this means personal data is processed only to the extent necessary, customers remain in control of the data under GDPR at all times, and the contractual basis for data processing is clearly defined.

For customers, this is especially relevant when an OEM must demonstrate to its own customers how the personal data collected through its platform is processed.

European Sovereignty: Your data stays in Europe

The choice of cloud services increasingly depends on where data is actually processed and stored. Autonoma made a deliberate choice here: a fully European setup, from hosting infrastructure to every data subprocessor we use.

This applies across the entire chain of services involved - the server environment, our development and collaboration tools, and our security and connectivity services. Put simply: not just the servers holding customer data, but the entire toolchain behind our digital customer platform, sits within the EU.

For customers, this removes an entire category of review work: as soon as data is hosted or transferred outside the EU, additional review steps become necessary, such as assessing standard contractual clauses or adequacy decisions. Work that typically falls to legal or data protection teams. With Autonoma, this step is eliminated entirely, which shortens your own security and privacy review.


An excerpt from our data subprocessors list

Security Whitepaper and Security Presentation

The sections above address individual certifications and topics on their own. For the complete picture of how security is designed across Autonoma's entire architecture, all detailed information is available in our Security Whitepaper.

It describes our complete security approach across the system architecture: from the edge layer on the machine, through the cloud platform, to the customer portal, covering network security, application and API security, and data protection. It is complemented by organizational topics such as supply chain security and internal security processes, along with an overview of the relevant standards and certifications.

For customers, this means the entire security approach is documented in a single source rather than assembled from multiple references - traceable from the hardware layer through to the application layer.

Depending on the level of detail required, we offer two formats: the full Security Whitepaper for detailed review, and a compact Security Presentation for a quick overview. Both are available for customers to download in the Trust Center.

Shared Responsibility: Security is a joint undertaking

A connected machine practically always involves three parties: Autonoma as the platform provider, the OEM as the machine builder, and the end customer as the operator of the equipment. The question is not whether responsibility is shared between them, but how clearly that allocation is defined.

Autonoma carries the larger share: cloud infrastructure, securing edge devices, ongoing updates, and continuous monitoring. OEMs and end customers are responsible for the smaller, but equally important, remainder: physical security on-site, local network segmentation, and, depending on the role, legal responsibility under GDPR. None of these elements function in isolation. Even the most robust cloud foundation cannot protect a machine if physical access on-site remains unsecured, and the strongest on-site security provides little benefit if the underlying platform can be compromised. Comprehensive, end-to-end security is achieved only when all three parties fulfill their respective responsibilities.

For customers, this means that when responsibilities are unclear, there is no need to determine them from scratch. The complete responsibility matrix is available for customers to download in the Trust Center.

Coming Next: The Cyber Resilience Act (CRA) and IEC 62443 Certifications

By December 2027, every connected product sold in the EU must be demonstrably developed with security in mind, in order to retain its CE mark. This is what the Cyber Resilience Act requires. It affects not only platform providers such as Autonoma, but also the machine builders who use our platform to connect their own products. Their connected machines fall under the CRA just as much as the underlying software.

This makes the choice of platform a matter that extends beyond functionality. Connecting machine data through an uncertified platform requires the customer to explain and demonstrate its security independently in their own audit, often without insight into the underlying development processes. Using a certified platform allows the customer to rely on an externally verified standard instead.

This is precisely what our ongoing certification to IEC 62443-4-1 (secure development process) and IEC 62443-4-2 (secure product) provides. These standards define how securely software must be developed and how secure the resulting product must ultimately be. They overlap substantially with the requirements of the CRA.

For our customers, this means the certification covers part of their own CRA preparation, which they do not have to handle themselves.

👉  Sign up for the Trust Center now, and don't miss any updates

Newsletter Icon

Don’t miss a single update!

Subscribe to our newsletter to receive latest updates to your inbox monthly.

Register now for the newsletter
Top Top