Where Covve operates
Covve Visual Network Limited is registered and operates in the European Union, at 8 Michalaki Karaoli str., Nicosia, Cyprus.
The Covve Scan Data Processing Agreement is governed by the law of the Republic of Cyprus.
Where your data is processed
The entire solution is hosted in Microsoft Azure Europe and in Google data centres in Europe, in Germany and the Netherlands. There is no transfer of customer data outside the EEA.
Data is stored redundantly across separate geographic locations, all of them within Europe.
ISO/IEC 27001 certification
Covve's information security management system is certified to ISO/IEC 27001:2022 by GCERT.
Certified entity | Covve Visual Network Limited |
Standard | ISO/IEC 27001:2022 |
Certificate number | 26159IT |
Scope of registration | Software engineering and application development |
Issued | 4 March 2026 |
Expires | 3 March 2029 |
The certificate's validity can be verified directly with the certification body at info@gcert.gr.
The Statement of Applicability that accompanies the certificate is not published. Your security team can request it from support@covve.com.
Independent privacy and security assessment
Covve is assessed annually by CyberVadis, an independent third party that evaluates cybersecurity, security and privacy practices across technology, people, processes and policies.
The most recent assessment was carried out on 30 January 2026 and is valid until 29 January 2027. Covve scored 983 out of 1000 and holds Platinum certification, the highest level CyberVadis awards.

Covve also commissions annual third-party penetration testing, both black-box and code-assisted. Your security team can request the most recent one from support@covve.com.
GDPR
Covve processes personal data as a processor on behalf of the customer, who is the controller. The Covve Scan Data Processing Agreement sets this out under Article 28 of the GDPR, including the categories of data subjects and data processed, the sub-processors engaged, and the technical and organisational measures in place.
Covve staff do not access customer data unless it is necessary to improve the service or resolve an issue, unless required by law, or unless the customer instructs it.
The Data Processing Agreement
For corporate clients, the Data Processing Agreement and the schedule of technical and organisational security measures are published in full
A countersigned copy for your records is available from support@covve.com.
Sub-processors
The sub-processors are approved under the Data Processing Agreement found in the document and Covve notifies customers of any intended addition or replacement of a sub-processor, and customers have 7 days from that notification to object.
Technical and organisational measures
The full schedule is in the Data Processing Agreement linked above. In summary:
Encryption in transit and at rest. TLS between client and server and between servers and databases. Encryption at rest covers the live system and all backups.
Access control. Least privilege, unique credentials, enforced password strength, multi-factor authentication wherever available, OAuth2 for user authentication, and production access restricted to a small number of senior engineers.
Network and data controls. Isolated virtual networks, firewalls, logical segregation of data, and role-based access with monitoring.
Continuous vulnerability management. Automated scanning, patch management and threat protection, at both infrastructure and application code level.
Change control. All changes pass an automated CI/CD pipeline with several thousand tests, require review by an authorised reviewer, and are tested in a separate environment before production. Deployed systems use configuration as code and are immutable after deployment.
Monitoring and logging. Azure Defender plus custom network monitoring alerts.
Resilience. Continuous geo-redundant backups, auto-scaling redundant infrastructure, and documented incident management, business continuity and disaster recovery procedures.
Assurance. Annual independent privacy and security audit, plus quarterly internal management review against Covve's own policies and procedures.
Use of AI systems
Covve maintains a document describing its use of AI systems. Your security team can request it from support@covve.com.
Retention and deletion
Data on a device is deleted when the Covve Scan app is deleted. Data held on Covve's servers is deleted when the agreement ends, or returned to the customer if the customer prefers. Log data is deleted automatically after 30 days.
See Delete your account and data for what happens when an individual account is deleted.
