Company logo

Trust Center - Chino.io

Compliance

GDPR Compliance badge
HIPAA Compliance badge
ISO 27001 Certification badge
ISO 9001 Certification badge
ISO 13485 Certification badge
Gender Equality badge

Overview


Chino.io combines expert legal-technical consulting with ChecksMATE, its compliance automation platform, to guide companies through Europe's data protection and security landscape.

We cover GDPR, HIPAA, ISO 27001, NIS2, the EU AI Act, and national laws across EU member states. We translate this complex, overlapping landscape into one coherent compliance strategy.

ChecksMATE then operationalizes that strategy, automating the implementation, monitoring, and evidence of compliance in place of manual checklists and one-off audits. This turns compliance from a cost center into a scalable system that keeps pace with new regulations.

The result: companies move faster with confidence, cutting time-to-market and overhead while giving clients, regulators, and investors clear proof of trust. This approach is already used by companies across EU, US, and worldwide, spanning digital health, AI, and other sensitive-data sectors.

Compliance Controls


Organizational Security Physical security & workplace policies
6 Active
Product Security App security, code quality & testing
6 Active
Technological Controls Encryption, network security & access controls
16 Active
Data and Privacy Privacy policies & data protection safeguards
14 Active
Data Subject Rights Managing user rights, access & requests
7 Active

FAQs


All data is hosted and stored in the EU, specifically within Hetzner Online GmbH servers in Germany. Backups are stored on OVH in France.

Chino.io maintains a multi-layered backup strategy to ensure reliability and continuity of service. Databases run in a High Availability cluster with live replication across multiple servers, plus continuous streaming to a separate backup server enabling point-in-time recovery, with daily backups retained for 6 months. Daily encrypted (AES256) snapshots of VMs, databases, and other data are kept on-site for up to 6 months, and replicated to a separate facility in another country for disaster recovery, also retained for up to 6 months.

Yes, we perform periodic penetration tests. Reach out to us for more information.

No. Chino.io uses third-party AI models exclusively through API integrations governed by zero-data-retention (ZDR) agreements. Under these agreements, customer data submitted to the AI provider is processed only to generate the requested output and is not stored, logged, or used to train, fine-tune, or otherwise improve the provider's models. Data is discarded immediately after processing, and Chino does not use customer data to train any AI model.