CSAIChaptersEventsBlog
Discover why hybrid cloud is now the standard. Register for the June 4 webinar to explore unified security strategies →

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for NIZU OÜ

Listings for NIZU OÜ

NIZU OÜ is a private limited company incorporated under the laws of the Republic of Estonia (VAT: EE102264113), headquartered in Tallinn, Estonia. NIZU develops and operates NIZU WorkSpace, a subscription-based cloud workspace platform delivered as a Software-as-a-Service (SaaS) offering to business clients across the European Union. NIZU WorkSpace provides isolated, multi-tenant digital workspace environments, enabling clients to manage their teams, data, and operations through a secure, cloud-based platform. The service is delivered on infrastructure provided by Hetzner GmbH (Germany), operating within the European Economic Area. NIZU OÜ operates in full compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act (IKS), and the ePrivacy Directive. A designated Data Protection Officer (DPO) oversees all data protection activities. NIZU acts as a Data Controller for platform-level user data and as a Data Processor under Article 28 GDPR for data processed within client workspaces. Security is foundational to NIZU's operations. The platform enforces encryption at rest (AES-256) and in transit (TLS 1.2+), multi-factor authentication for administrative access, role-based access control, tenant isolation, and continuous vulnerability management. NIZU maintains documented policies covering incident response, business continuity, change management, cryptography, and supply chain risk, all reviewed at least annually.

Hetzner

Hetzner is a German IT company and one of Europe’s largest and most trusted internet service providers, founded in 1997. It operates several thousand servers...

Listed Since: 2026-05-26

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).