CurNext

CurNext

Compliance

How CurNext approaches privacy, construction evidence, and standards alignment - without inventing certifications we have not completed.

This page is a buyer-facing summary. It is not a certificate vault, audit report, or substitute for a signed DPA.

What we claim - and what we do not

  • We do not claim here

    CurNext does not advertise ISO 27001 or SOC 2 certification for itself on public pages. Standards listed elsewhere are design alignment unless we confirm a completed third-party assessment separately.

  • What we do operate under

    EU GDPR applies to core platform processing for EEA Clients. Invite-only access, RBAC, privileged MFA, and GDPR-oriented audit, export, and erasure paths are product and process themes.

  • Infrastructure inheritance

    Hetzner, Supabase, and Cloudflare publish their own trust materials. Customers inherit those provider controls at the infrastructure layer - review vendor trust pages for their certifications.

Frameworks we design against

Listing a framework means engineering and process alignment. It does not mean every certification for that framework is complete.

Compliance frameworks CurNext designs against
FrameworkScopeHow we use it
GDPRPersonal data / EU ClientsRoles, TOMs, subprocessors, transfers - see DPA and Privacy
IEC 62443Industrial / building IoT zonesZone and conduit model; security level targets per layer
NIST SP 800-82 / 800-213ICS / IoT device cybersecuritySegmentation, device identity, secure update themes
ENISA IoT / OT & EU CRAEU IoT / product security lifecycleBaseline crypto, updates, SBOM and disclosure themes
ISO 27001Organisational ISMSDesign and operations target - not claimed certified here
PIPEDA / Law 25 diligenceCanadian ClientsVendor diligence supported; local hosting in Canada is not claimed

Construction and buyer evidence

  • Site readiness trail

    Readiness decisions, alerts, and project activity leave a trail mapped to the building for handover and claims conversations.

  • Audit trail

    Access, provisioning, OTA, admin actions, and GDPR-oriented events are designed for accountability - see Audit Trail.

  • DPA & subprocessors

    Art. 28-oriented summary, public subprocessor list (including Gemini and Groq for AI when enabled), and market notes for Finland, Canada, and Cameroon.

AI in the product

CurNext combines an in-house readiness model with optional assisted AI features.

  • In-house curing model

    Concrete curing prediction runs on a CurNext-trained model built with TensorFlow.js - part of the product readiness engine for CN-CC.

  • Gemini (Google AI)

    Assisted product AI features when Gemini is enabled - prompts and context minimized for the task.

  • Groq

    Knowledge Base assistant on curnext.app after consent, and other assisted product AI features when Groq is enabled.

Operating markets

CurNext is registered in Finland. Commercial markets include Finland, Canada, and Cameroon. Core app and database for EU Users are hosted in Germany / Frankfurt.

  • Finland / EEA - GDPR as primary privacy regime for platform Client Data
  • Canada - PIPEDA / Law 25 vendor diligence supported; Canadian local hosting is not claimed here
  • Cameroon - local diligence supported; Cameroon local hosting is not claimed here

Compliance or DPA requests:[email protected]

Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.