CurNext
Compliance
How CurNext approaches privacy, construction evidence, and standards alignment - without inventing certifications we have not completed.
This page is a buyer-facing summary. It is not a certificate vault, audit report, or substitute for a signed DPA.
What we claim - and what we do not
We do not claim here
CurNext does not advertise ISO 27001 or SOC 2 certification for itself on public pages. Standards listed elsewhere are design alignment unless we confirm a completed third-party assessment separately.
What we do operate under
EU GDPR applies to core platform processing for EEA Clients. Invite-only access, RBAC, privileged MFA, and GDPR-oriented audit, export, and erasure paths are product and process themes.
Infrastructure inheritance
Hetzner, Supabase, and Cloudflare publish their own trust materials. Customers inherit those provider controls at the infrastructure layer - review vendor trust pages for their certifications.
Frameworks we design against
Listing a framework means engineering and process alignment. It does not mean every certification for that framework is complete.
| Framework | Scope | How we use it |
|---|---|---|
| GDPR | Personal data / EU Clients | Roles, TOMs, subprocessors, transfers - see DPA and Privacy |
| IEC 62443 | Industrial / building IoT zones | Zone and conduit model; security level targets per layer |
| NIST SP 800-82 / 800-213 | ICS / IoT device cybersecurity | Segmentation, device identity, secure update themes |
| ENISA IoT / OT & EU CRA | EU IoT / product security lifecycle | Baseline crypto, updates, SBOM and disclosure themes |
| ISO 27001 | Organisational ISMS | Design and operations target - not claimed certified here |
| PIPEDA / Law 25 diligence | Canadian Clients | Vendor diligence supported; local hosting in Canada is not claimed |
Construction and buyer evidence
Site readiness trail
Readiness decisions, alerts, and project activity leave a trail mapped to the building for handover and claims conversations.
Audit trail
Access, provisioning, OTA, admin actions, and GDPR-oriented events are designed for accountability - see Audit Trail.
DPA & subprocessors
Art. 28-oriented summary, public subprocessor list (including Gemini and Groq for AI when enabled), and market notes for Finland, Canada, and Cameroon.
AI in the product
CurNext combines an in-house readiness model with optional assisted AI features.
In-house curing model
Concrete curing prediction runs on a CurNext-trained model built with TensorFlow.js - part of the product readiness engine for CN-CC.
Gemini (Google AI)
Assisted product AI features when Gemini is enabled - prompts and context minimized for the task.
Groq
Knowledge Base assistant on curnext.app after consent, and other assisted product AI features when Groq is enabled.
Operating markets
CurNext is registered in Finland. Commercial markets include Finland, Canada, and Cameroon. Core app and database for EU Users are hosted in Germany / Frankfurt.
- Finland / EEA - GDPR as primary privacy regime for platform Client Data
- Canada - PIPEDA / Law 25 vendor diligence supported; Canadian local hosting is not claimed here
- Cameroon - local diligence supported; Cameroon local hosting is not claimed here
Related
Compliance or DPA requests:[email protected]
Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.