With FileCap, your files and data remain protected throughout the entire process: from sending and receiving to storing and deleting. Our security is based on the international standard ISO 27001:2022.
FileCap is designed to enable the secure exchange of emails and files—within Outlook, Microsoft 365, and the web portal. With FileCap, you can customize security measures to align with your own policies:
In developing and managing FileCap, we follow recognized best practices, including:
ISO 27001 / ISO 27002: the international standard for information security management systems. Contec has been ISO 27001 certified since July 7, 2020; since 2025, we have been certified to the ISO 27001:2022 standard.
NCSC ICT security guidelines for web applications: the guidelines from the National Cyber Security Center serve as a reference framework for our development and management processes.
OWASP Top 10: the ten biggest security risks for web applications identified by the Open Web Application Security Project are incorporated into development, code review, and testing.
Secure Software Development Lifecycle: Security is embedded in our development processes—from design and code review to release and patch management. Administrators can schedule updates to the FileCap server or apply them immediately.
The FileCap SaaS environments run entirely within the European Union. We currently use two EU hosting platforms:
Regardless of the underlying platform, your data will not leave Europe and will not be used for AI training or marketing purposes. Upon request, we will let you know which platform your specific FileCap environment is running on.
Access to your FileCap environment is only possible with a valid account, a strong password, and—for administrators—multi-factor authentication. Your data is always transmitted over an SSL/TLS-encrypted connection.
After logging in, you will have access to only the features you are authorized to use. Based on their roles, administrators, end users, and recipients can be assigned different permissions and authentication requirements.
In line with zero-trust principles, administrator access is being further secured:
We ensure strict compliance with our security measures. Any deviations are detected, investigated, and classified. Based on incidents and the records kept, we implement additional security measures. Customers are notified in accordance with the GDPR and applicable legal reporting requirements if they are affected.
Our process for reporting and handling (security) incidents is outlined in the Incident Reporting Process Description (PDF).
Affected customers will be notified without undue delay, no later than 72 hours after we have determined that an incident affects them. This allows you to meet your own reporting obligations in a timely manner, such as the 24-hour early warning requirement under NIS2 and the 72-hour data breach notification requirement under the GDPR.
FileCap takes the security of customer data and the safe use of our SaaS solution extremely seriously and actively monitors these aspects. To enable users of our systems to actively contribute to this, you can report any instances of misuse or suspected security vulnerabilities directly to our security team at security@filecap.com.
If you suspect any vulnerabilities, please always contact us directly. We strongly advise against reporting or disclosing information via social media in order to minimize potential risks to those involved.
The quality, security, and privacy of FileCap are demonstrated through certifications and regular audits.
Contec B.V., the provider of FileCap, has been certified to the international ISO 27001 standard for Information Security Management Systems (ISMS) since April 1, 2021. View Contec B.V.’s ISO 27001 certificate.
Please also review the Statement of Applicability for ISO 27001:2022 (PDF), which outlines which control measures we implement and how.
ISO 27001 certification means that an independent auditor periodically verifies that our Information Security Management System (ISMS) is demonstrably effective. Among other things, the certification ensures compliance with the following requirements:
FileCap complies with the General Data Protection Regulation (GDPR). View Contec B.V.'s privacy statement (PDF).
In addition, our 2026 Data Processing Agreement (Word) is available as an editable document, so you can easily enter into it with Contec B.V.
Are you conducting a Data Protection Impact Assessment (DPIA) before implementing FileCap? Upon request, we can provide the necessary information, including the division of responsibilities, a list of subprocessors, and the technical and organizational measures. Please contact us at security@filecap.com.
FileCap meets the requirements set forth in the NIS2 Directive on cyber resilience. The combination of AES 256 encryption, TLS 1.3, MFA, DLP via Business Rules, and a verifiable audit trail supports customers in their own compliance efforts. If your organization does not directly comply with NIS2, FileCap helps you serve as a secure building block in the supply chain for customers who are subject to NIS2.
Dutch government organizations are subject to the Government Information Security Baseline (BIO); the healthcare sector is subject to NEN 7510. Both standards frameworks—just like our ISMS—are based on ISO 27001/27002. The control measures in our ISO 27001:2022-certified ISMS are therefore aligned with the corresponding BIO and NEN 7510 measures. A mapping for your supplier assessment is available upon request at security@filecap.com.
Regulation (EU) 2022/2554 (the Digital Operational Resilience Act, "DORA") has applied to financial entities in the EU since January 17, 2025, and sets out legal requirements for information security and the management of ICT risks, including where these risks lie with third-party providers.
If your organization is a financial entity as defined by DORA—such as a credit institution, investment firm, payment institution, insurer, insurance intermediary, pension institution, management company, or similar entity—FileCap may qualify as a third-party IT service provider for you.
FileCap supports you in this as follows:
Upon request, we will provide the relevant supplier declarations so that you can include them in your own DORA information register and risk assessment.
Please note that the accountability under DORA remains with you as a financial entity: you remain fully responsible for compliance with DORA and applicable financial law. FileCap does not provide legal advice; for implementation questions, we refer you to your own legal counsel or the relevant supervisory authorities (in the Netherlands, the AFM and DNB; at the European level, the EBA, EIOPA, ESMA, and—for systemic risks—the ESRB).
Would you like to receive our brief explanation of DORA in relation to FileCap, or discuss a DORA addendum? Please contact us at security@filecap.com.
WCAG (Web Content Accessibility Guidelines) is the international standard for digital accessibility. The guidelines ensure that websites and applications are usable by everyone—including people with visual, hearing, motor, or cognitive disabilities—and are based on four principles: perceivable, operable, understandable, and robust.
Digital accessibility is mandatory for government organizations and—in part due to the European Accessibility Act—is increasingly becoming a procurement requirement for other organizations as well. FileCap complies with WCAG 2.2, ensuring that the solution is accessible to all your employees and recipients.
The full assessment is documented in the WCAG compliance report (PDF).
FileCap does not use artificial intelligence in its product and does not train AI models on customer data. No automated decision-making or profiling takes place based on the content of messages or files you send via FileCap. Therefore, using FileCap does not introduce any AI systems, as defined by the EU AI Regulation (Regulation (EU) 2024/1689), into your environment.
We do use AI when handling support questions and cases—for example, to answer questions more quickly and route cases efficiently. This AI support works exclusively on the content of the support request itself and does not have access to the messages or files you send via FileCap. Questions you ask through our support chat at chat.filecap.com are also answered using AI.
If there are any changes to how we use AI, we will document them on this page.
We periodically conduct both internal and external penetration tests on the FileCap application and the underlying infrastructure. Internal penetration tests are performed by our own team; for external penetration tests, we engage independent specialists. Findings are classified and addressed in accordance with our release process.
The FileCap infrastructure and software are assessed for vulnerabilities whenever significant functional or technical changes are made. We conduct this assessment in-house, followed by the classification and follow-up of findings.
In addition, we continuously use external scanning tools to check for vulnerabilities in the FileCap environment and its underlying components. Any vulnerabilities found are actively tracked and—depending on their impact—resolved or mitigated, and patches and updates are applied according to a defined release process. For ad hoc requests from customers, we facilitate—in consultation—penetration tests on their own FileCap environment.
FileCap SaaS environments run on cloud infrastructure designed for high availability, either on Scaleway or in AWS EU regions. This ensures that, in the event of a component failure, service can continue without interruption for the end user.
Our procedures for restoring service in the event of a disaster are described in the FileCap SaaS Disaster Recovery Plan (PDF), which is part of our ISO 27001 framework.
To safeguard data and configurations, backups are performed periodically. Administrators can request a backup of their environment upon request. The restore functionality, which is available only to authorized FileCap personnel, is used to restore backups.
Our recovery procedures are tested on a regular basis. Findings are classified and followed up; to date, these tests have not revealed any major issues. The backup system is intended for disaster recovery, not for archiving individual customers’ data.
Backups of the SaaS platforms are stored in the Netherlands, with at least one copy always stored off-site.
Our business continuity planning focuses on both the SaaS environment and the support provided by our support team. We have established contractual agreements with our suppliers—including Scaleway and AWS (EU) as hosting partners and our SMS provider—regarding availability, security, and data protection.
FileCap's guaranteed availability, support levels, and response times are set forth in the FileCap 2025 SLA (Dutch, PDF), which is also available in English (PDF).
FileCap is provided as a SaaS service. Responsibility for security and compliance is shared:
FileCap / Contec is responsible for:
The customer is responsible for:
A detailed breakdown can be provided upon request, for example, as part of a supplier assessment or a DPIA.
The most important compliance, security, and legal documents from FileCap and Contec B.V. are available for immediate download:
You can always find the most recent versions of all our regulatory documents at docs.filecap.eu/regulatory.
If you entrust (parts of) your business processes for secure email and file sharing to FileCap, you want to be sure that this is done in a controlled and reliable manner. The quality standards, level of information security, and privacy must meet your expectations, the agreed-upon service terms, and current laws and regulations.
FileCap, developed and managed by Contec B.V., has been recognized for over fifteen years as a reliable partner for encrypted email and file transfer. With an ISO 27001-certified ISMS, hosting within the EU, strong encryption, and a transparent division of responsibilities, we help you maintain control over the information flows you entrust to FileCap.
Do you have questions about this page or a specific security measure? Please contact us at security@filecap.com.