Search all 478 artefacts by title, document ID or content.
Statement | Family 14, Jurisdiction Variant Sets
Written to be handed straight into a hospital's own supply-chain security file. Every row cites an artefact rather than an assurance.
STM-EU-002 v1.0.0, Last Modified On 01 August 2026, Tier: Public
Written to be handed straight into a hospital's own supply-chain security file. Every row cites an artefact rather than an assurance.
| DM-1 Dedicated | DM-2 Shared | DM-3 Customer Cloud | DM-4 On-Premise |
|---|---|---|---|
| Yes | Yes | Yes | (with the boundary in Section 7) |
Edsol Edtech Pvt. Ltd. is not an essential entity and not an important entity under Directive (EU)
2022/2555 or any national transposition of it. It is not established in the Union or the EEA for that
purpose, it does not operate as a provider of a covered digital infrastructure or digital service in the
Union, it holds no registration with any national competent authority under those instruments, and it
does not represent that it does.
Its obligations in this statement are contractual. They flow from the hospital's own statutory
position, not from Pensieve Labs's.
Stating this precisely is more useful to a hospital's own documentation than implying a registration that does not exist. It is the same discipline
Pensieve Labsapplies to national digital health credentials: the hospital is the regulated participant;Pensieve Labsoperates inside the hospital's authority and says so.
Article 21(2)(d) of the Directive requires a covered entity to address supply chain security, including security-related aspects concerning the relationships between the entity and its direct suppliers or service providers. Article 21(3) requires the entity to take into account the specific vulnerabilities of each direct supplier, the overall quality of their products and cyber-security practices, and their secure development procedures.
In practice a covered entity discharges that duty by flowing requirements into its supplier contracts.
A subcontractor to a health entity is therefore reached indirectly, through supply-chain requirements, even
though it operates no critical infrastructure of its own. That describes Pensieve Labs exactly.
Hospitals are ordinarily essential entities in the health sector. A regional or state hospital operator
almost always is. A private hospital may be an essential or an important entity depending on size and on
the national transposition, and Pensieve Labs does not tell a hospital which it is; the hospital's
own registration position governs.
Pensieve Labs does not assert a transposition status it has not checked. The current position for the
two EEA markets in scope is held in the country delta packs and summarised here:
| Market | Position as at 01 August 2026 |
Effect on this statement |
|---|---|---|
| Denmark | The national implementing act is in force, and the registration duty for covered entities has passed. A Danish hospital's obligations are live law today, which means the supply-chain clauses are already in its contracts | Every commitment below is expected to be requested, and every one is pre-accepted in MSA-EU-001 clause 5 |
| Norway | The current national digital security act implements the first network and information security directive. The second directive requires incorporation into the EEA Agreement before national implementation; it was not in force as at 01 August 2026 [verify at signature] |
The commitments below apply contractually regardless. A Norwegian hospital acquiring on a multi-year term should take them now rather than reopen the contract later |
[Both rows are verified at the date of a bid or a signature, not assumed from this document. The delta packs eu/dk/andeu/no/ carry the current position and the source.]
Each row states the commitment and names the artefact that evidences it. A hospital can cite the artefact in its own file.
| Art. 21(2) | Measure | Pensieve Labs's commitment |
Evidence |
|---|---|---|---|
| (a) | Risk analysis and information system security policies | A documented management system with a policy framework, an owned risk register, and annual review. Pensieve Labs supplies the inputs the hospital's own risk analysis needs, on request and twice per contract year without charge |
POL-GL-100, POL-GL-117, POL-GL-000 |
| (b) | Incident handling | A defined severity model, an exercised response process, and a 4-hour notification to the hospital from Pensieve Labs's awareness, set inside the hospital's own 24-hour early-warning window |
DIS-EU-016, POL-GL-112 |
| (c) | Business continuity, backup management, disaster recovery, crisis management | Recovery time and recovery point objectives stated per deployment model, backups in the same EEA region, restore testing at a stated cadence with the result recorded | DIS-GL-014, POL-GL-106, REP-GL-013, REP-GL-015 |
| (d) | Supply chain security | Section 5 below | DIS-GL-009, DIS-GL-010, POL-GL-135, POL-GL-055 |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling and disclosure | Secure development lifecycle with dependency scanning and pre-release testing; published severity classes and remediation windows; a coordinated disclosure policy with a published security contact and a security.txt |
DIS-GL-018, DIS-GL-017, POL-GL-059, POL-GL-118 |
| (f) | Policies to assess the effectiveness of risk-management measures | At least annual independent security assessment, summary published, full report under non-disclosure; annual continuity exercise; quarterly access review | WPR-GL-005, REP-GL-013 |
| (g) | Cyber hygiene practices and security training | Role-based training at induction and annually, covering the transfer restrictions and the support-ticket content rule; recorded per person | DIS-GL-020, POL-GL-122 |
| (h) | Policies on cryptography and encryption | Encryption at rest and in transit, EEA-resident key custody, customer-managed and customer-held key options, documented rotation and separation of duties | DIS-GL-011, POL-GL-108, POL-GL-129, DIS-EU-008 Section 5 |
| (i) | Human resources security, access control policies and asset management | Pre-engagement screening to the extent lawful, least-privilege role-based access, no standing production privilege, revocation on the same business day as exit, asset inventory | DIS-GL-012, DIS-GL-020, POL-GL-101, POL-GL-103, POL-GL-128, POL-GL-134 |
| (j) | Multi-factor authentication, secured voice/video/text communications, secured emergency communications | Multi-factor authentication enforced on every administrative and production path, phishing-resistant factors for privileged roles; an out-of-band incident channel that does not depend on the Platform | POL-GL-115, DIS-GL-012, DIS-GL-033, POL-GL-056 |
Article 21(2)(d) is the clause Pensieve Labs is being asked about, so it gets its own section.
5.1 The register is public. DIS-GL-009 names every sub-processor, its role, the country in which it
processes, the categories of data it may reach, and the transfer safeguard relied on. DIS-GL-010 is the
change feed and a hospital can subscribe to it. A hospital should not learn of a sub-processor's
existence for the first time in a breach notification.
5.2 Flow-down. Each sub-processor is bound in writing to obligations no less protective than those
Pensieve Labs owes the hospital, including incident notification, security measures, personnel
obligations and the transfer safeguards.
5.3 Change notice and objection. Thirty days' notice of an addition or replacement of a
sub-processor that processes hospital data, with a right to object on reasonable data-protection or
security grounds and, if the objection cannot be accommodated, a right to terminate the affected services
without liability for the period after termination. POL-GL-055.
5.4 Verification, not assurance. Pensieve Labs operates a documented programme for verifying
that its sub-processors meet the flowed-down obligations, rather than merely contracting for them. For each
sub-processor that processes hospital data the programme records, annually: the security documentation and
any independent assessment examined; where the sub-processor processes outside the EEA, a recorded
assessment of the transfer safeguard against the European Essential Guarantees; the date, the reviewer and
the conclusion; and the action taken on a failure, up to replacement. The evidence is available to the
hospital on request. POL-GL-135.
This is the item most vendors do not have, and it is the item European public bodies have been criticised for lacking in their own supply chains, specifically for not assessing transfers to sub-processors in third countries.
Pensieve Labsis one of those third-country suppliers. The answer is a programme with dated evidence, not a paragraph.
5.5 Concentration and single points. The register states where a component has no ready substitute.
Pensieve Labs does not claim a multi-cloud posture it does not have: the infrastructure provider is
single-sourced, and DIS-GL-014 states what that means for continuity and what the exit path is.
5.6 Liability. Edsol Edtech Pvt. Ltd. remains fully liable to the hospital for its sub-processors'
performance.
Pensieve Labs's outputs feed the hospital's filings| Hospital filing | Statutory window | Pensieve Labs delivers |
By |
|---|---|---|---|
| Early warning to the national CSIRT | 24 hours from the hospital's awareness | First notification with the early-warning content set | 4 hours from Pensieve Labs's awareness |
| Incident notification | 72 hours | Intermediate report with initial severity assessment, indicators of compromise and mitigation applied | 48 hours after the first notification |
| Intermediate report on request | On request | Weekly written update while the incident is open | Weekly |
| Final report | 1 month | Final report with root cause, severity and impact, cross-border impact and remediation with owners and dates | 20 Business Days from containment |
DIS-EU-016 is the source of truth for the clocks and the notification content. MSA-EU-001 clause 5.2
makes them contractual.
Where an incident may be significant for more than one hospital, each affected hospital is notified; no hospital is told another's identity.
A single undifferentiated security statement would be untrue in at least one model.
| Model | What Pensieve Labs is responsible for |
What the hospital is responsible for |
|---|---|---|
DM-1 |
The dedicated project end to end: platform, data stores, network, keys, access, monitoring, backup | Its own endpoints, users, network and identity provider |
DM-2 |
The shared platform, tenant isolation, per-tenant keys, monitoring | Same, plus reviewing the isolation disclosure DIS-GL-032 |
DM-3 |
The platform layer inside the hospital's cloud project, and Pensieve Labs's own administrative access |
The cloud account itself: organisation policy, identity, network, billing, and forwarding account-level alerts to Pensieve Labs |
DM-4 |
The application, its patching, and support | Everything below the application: premises, physical security, environment, power, network, hardware, host operating system, hypervisor, backup custody, and physical access control. ADD-GL-008 states this in full |
In DM-4 Pensieve Labs will not commit to detecting an incident on infrastructure it cannot
observe. A hospital that wants the full commitment should forward telemetry or choose DM-1.
Article 20 places responsibility for approving and overseeing risk-management measures on the covered
entity's management body, and requires its members to follow training. That obligation is the
hospital's and Pensieve Labs does not discharge it.
What Pensieve Labs does offer, so that the hospital's management body can discharge it:
Roadmap security owner, reachable at
info@pensievelabs.org;ADD-GL-001, extending to verification of this statement; andPensieve Labs will sign, and what it will notBeing explicit here removes a negotiation round.
Will sign:
MSA-EU-001 clause 5;Pensieve Labs's own cost where the deficiency
is a breach of the security addendum or of this statement;Will not sign:
| Term | Why |
|---|---|
A representation that Edsol Edtech Pvt. Ltd. is a registered essential or important entity |
It is not, and a false representation in a hospital's own file is worse than no representation |
| An obligation to notify a national competent authority on the hospital's behalf | The hospital is the covered entity. A supplier filing on its behalf creates a record the hospital cannot stand behind |
| A blanket "the supplier shall comply with NIS2" | It is not a standard a supplier can be measured against, and competent-authority guidance itself discourages undifferentiated compliance demands in favour of concrete, evaluable requirements. Pensieve Labs proposes the mapped matrix in Section 4 instead, which is more onerous, not less |
| Unlimited liability for a security incident | The liability position is in MSA-EU-001 clause 10, which already carves out the non-excludable heads |
| An obligation to hold a specific certification by a specific date | Edsol Edtech Pvt. Ltd. holds none and will not promise one to win a deal. WPR-GL-005 states the position and what compensates for it |
Detection commitments for infrastructure the hospital controls in DM-3 or DM-4 |
Section 7 |
Delivered as one download, within 5 Business Days of a request, under the applicable tier gate.
| # | Item | Tier |
|---|---|---|
| 1 | This statement, signed and dated | Public |
| 2 | Policy framework index and the security policy set | Public |
| 3 | Subprocessor register and the current change log | Public |
| 4 | Encryption, access control and audit logging disclosures | Public |
| 5 | Backup, recovery and continuity disclosure with objectives per model | Public |
| 6 | Vulnerability management disclosure and the disclosure policy | Public |
| 7 | Remote access and support model | Public |
| 8 | Independent security assessment summary | Public; full report under non-disclosure |
| 9 | Continuity exercise report | NDA |
| 10 | Sub-processor verification evidence | NDA |
| 11 | Register of individuals with production access | NDA |
| 12 | Completed supply-chain questionnaire in the hospital's own template | Client |
11.1 This is not a certification. Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001 certificate, no SOC 2
report and no equivalent. The management system is mapped to ISO/IEC 27001:2022 Annex A and the statement
of applicability is published without a certificate. WPR-GL-005 states what compensates.
11.2 Transposition varies. The Directive is transposed differently in each State, and a national act
may impose requirements this statement does not anticipate. MSA-EU-001 clause 5.9 commits
Pensieve Labs to renegotiate the flow-down without charge where that happens.
11.3 Registration status can change. If Edsol Edtech Pvt. Ltd. ever establishes in the Union or the
EEA in a way that brings it into scope, this statement is revised and the hospitals affected are notified.
11.4 Sub-processor verification is documentary and, where offered, based on the sub-processor's own
independent assessment. Pensieve Labs does not perform on-site audits of hyperscale infrastructure
providers and does not claim to.
| ID | Artefact |
|---|---|
MSA-EU-001 |
Master Services Agreement: EU/EEA Variant, clause 5 and Schedule B |
DIS-EU-016 |
Breach Notification Commitment (GDPR) |
DIS-GL-009, DIS-GL-010 |
Subprocessor Register and change log |
POL-GL-135, POL-GL-055 |
Sub-processor management and notification/objection terms |
DIS-GL-014 |
Backup, Retention & Recovery; Business Continuity |
DIS-GL-017, POL-GL-059 |
Vulnerability management and coordinated disclosure |
ADD-GL-001 |
Security Addendum: the audit right |
ADD-GL-008 |
On-Premise Supplement (DM-4) |
WPR-GL-005 |
Assurance Overview |
Issued by Edsol Edtech Pvt. Ltd..
| Role | Name | Signature | Date |
|---|---|---|---|
| Security owner | Roadmap security owner |
||
| Authorised signatory | [TO BE SUPPLIED] |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Security | First issue. Boundary stated first; Article 21(2) mapped measure by measure to named evidence; supply-chain verification programme; the phased reporting map; and an explicit list of terms Pensieve Labs will not sign. |