Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join this August 11 webinar to explore practical strategies for managing cloud complexity and AI-driven workloads →

STAR Registry Listing for

Prakto

Prakto

Prakto is a Swedish SaaS platform, provided by OptiTech Sverige AB, that coordinates work-based learning placements between students, schools, and host companies in Sweden.

Prakto supports the full placement lifecycle for legally distinct Swedish education forms (LIA, APL, VFU, PRAO): matching, applications, contracts and e-signing, on-site supervision, digital journals and time tracking, evaluation, and certification.

Security & privacy posture: - EU data residency (primary data hosted in Frankfurt, EU) - Encryption in transit (TLS/HSTS) and at rest - Column-based multi-tenant isolation with server-side RBAC - GDPR-aligned: lawful basis, data minimisation, data-subject rights, DPA available to schools and companies - PII redaction before any third-country AI processing (Schrems II aligned) - Distributed rate limiting, audit logging, and PII-scrubbed error monitoring

As an EdTech handling student data — often minors' — Prakto treats security, privacy, and responsible AI as core requirements. This CSA STAR Level 1 self-assessment documents our control posture transparently.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about Prakto
Listed Since: 06/09/2026

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.1.0

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed about 2 months ago, on June 09, 2026.