Security, Privacy & Digital Sovereignty

When managing doctoral candidate files, progress evaluations, and academic publications, information security and privacy are paramount. Hora Finita was designed from the ground up around the principles of Privacy by Design and Security by Design. All research and personal data are rigorously protected and remain strictly within European legal jurisdiction.

Learn more

100% European Digital Sovereignty

Universities rightly demand strict control over the location and chain of custody of their data. Hora Finita guarantees complete digital sovereignty without reliance on non-European entities.

Self-managed infrastructure (Independent of Big Tech Cloud):

Our hosting platform operates entirely on fully self-managed infrastructure within ISO-certified European data centers. Hora Finita is completely independent of American cloud providers such as Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP).

100% Open-source stack (Zero vendor lock-in):

The platform is built on robust, battle-tested open-source technologies including Linux and MariaDB. This eliminates costly commercial license dependencies and prevents vendor lock-in with proprietary software vendors like Microsoft or Oracle.

Exclusive hosting in Europe:

All application data, backups, and data processing workflows remain strictly on infrastructure located in certified European data centers at all times.

Fully Schrems II compliant:

Because no personal or research data is transferred outside the European Economic Area (EEA), your institution is completely shielded from foreign government access risks (such as under the US CLOUD Act).

No offshore outsourcing:

System administration, maintenance, and technical support are performed exclusively by our in-house team within the Netherlands. No operational tasks or data access are outsourced to offshore entities or third-party sub-processors.

Privacy through Fine-Grained Authorization & GDPR Compliance

Managing progress reports, Go/No-Go decisions, and committee evaluations requires strict separation of permissions. Hora Finita ensures that confidential information is accessible only to users with a formal role in the process.

Role-Based Access Control (RBAC) & fine-grained permissions:

Access rights can be configured precisely per organizational role using Role-Based Access Control (RBAC). Confidential meeting notes, supervisor feedback, or sensitive personal circumstances remain strictly isolated from unauthorized personnel.

Built-in data retention policies & archiving:

Flexible settings allow institutions to enforce automated data retention, archiving, and deletion policies in compliance with statutory GDPR requirements and academic record regulations.

Information Security & Secure External Access

Academic workflows require external experts and committee members to participate securely in the review process without compromising institutional security standards.

Integration with University Identity Providers (SSO & MFA):

Seamless support for Single Sign-On (SSO) and Multi-Factor Authentication (MFA) via established academic and enterprise standards such as SURFconext, SAML 2.0, and Microsoft Entra ID.

Frictionless yet secure access for external reviewers:

External thesis evaluators receive temporary, scoped access to relevant manuscripts via secure time-limited tokens. This eliminates the administrative burden of account provisioning, as well as the security risks of large email attachments or third-party file sharing tools.

Full traceability via unalterable audit logging:

Every critical action — from manuscript submission and committee evaluations to formal decision approvals — is recorded in an immutable central audit log, guaranteeing complete accountability and academic integrity.

Controlled Operations & DTAP Infrastructure

Information security extends beyond code; it encompasses the entire operational lifecycle. Hora Finita maintains a predictable release methodology that safeguards the continuity of university operations.

Strict DTAP Pipeline (Development, Testing, Acceptance, Production):

All new features and updates progress through a controlled DTAP pipeline. Universities are provided with a dedicated Acceptance environment to validate changes prior to production deployment.

No unannounced 'Continuous Deployment':

We avoid surprise mid-week updates in production environments. Releases are deployed within fixed, pre-scheduled maintenance windows, minimizing operational burden on functional administrators and IT staff.

Centralized & transparent incident management:

Support requests, change requests, and security queries are centrally tracked, prioritized, and resolved with full transparency.