Compliance Certifications
Ultimo continuously innovates and invests, using best practices and industry standards to achieve compliance with industry-accepted security and privacy frameworks. This helps ensure your data is protected and secure.
Commitment to security and quality
Ultimo holds ISO 27001:2022 and ISO 9001:2015 certifications, demonstrating strong data protection and consistent service quality.
In addition, the SOC 2 Type 2 assurance report provides further confidence in the effectiveness of controls over financial processes and related risks. Customers can request this SOC2 Type 2 Assurance report to verify that robust measures are in place to safeguard data and ensure high levels of security and integrity.
Ultimo in the Cloud
Business moves fast. Your EAM platform shouldn’t lag behind. Ultimo is a cloud-native, software-as-a-service (SaaS) EAM solution built to flex and scale as your industry evolves. This way you’re always ready for what’s next. Cloud-based EAM: Grow fast, stay in control. Read more about Ultimo in the Cloud in our eBook!
Security
-
Your data and process security are top priorities. We take various measures to set your mind at ease and ensure an uptime of 99.7% for Ultimo SaaS environments, as defined in our support policy. Our cloud team communicates all maintenance or downtime updates via our status page.
The infrastructure is fully managed through Infrastructure as Code, eliminating manual actions and minimizing human error. To guard against web-based threats, we use ModSecurity, an advanced open-source Web Application Firewall integrated with NGINX, offering deep traffic inspection, real-time threat mitigation, and customizable security rules.
All customer files are securely stored on Azure Storage, protected with 256-bit AES encryption (FIPS 140-2 compliant), ensuring strong, transparent data protection similar to BitLocker encryption on Windows.
-
Security and quality are built into our agile software development process. Your business benefits from our continuous integration and continuous delivery (CI/CD), a DevOps best practice that ensures fast, secure, and reliable updates.
All code is developed and reviewed according to OWASP guidelines and continuously scanned for vulnerabilities, while automated and manual tests before every release guarantee stability. Static code analysis further monitors complexity and consistency, ensuring every update meets the highest standards for secure, dependable performance.
-
Ultimo applies strict measures to ensure strong authentication security and continuous protection through penetration testing. All user connections to Ultimo environments are secured via HTTPS with HSTS preloading, ensuring browsers always use encrypted connections.
Single Sign-On (SSO) is supported through Microsoft Entra ID, with options for SAML2 and OIDC integration for other identity providers, allowing customers to manage additional security controls such as multifactor authentication.
To maintain robust protection, external experts conduct annual penetration tests covering both the software and the hosting platform, with detailed results available upon request. These combined measures guarantee that user access and data remain secure at all times.
AI
We embrace the power of AI responsibly, ensuring transparency, fairness, security and human oversight in everything we do.
-
At Ultimo, we believe AI should be used responsibly, transparently and with appropriate human oversight. Our approach is guided by principles that support trust: security, privacy, accountability, fairness and clear purpose. We evaluate AI-enabled capabilities carefully before introducing them, considering both their value to customers and the risks that may need to be managed. Where AI is used, we aim to be clear about its role, its limitations and how users remain in control.
-
AI is assessed as part of Ultimo’s broader security, privacy and compliance approach. This means we consider how data is used, where it is processed, who has access to it, and what safeguards are required to protect information.
-
Ultimo uses and explores AI where it can provide meaningful value to enterprise asset management. This may include helping users access information more easily, work more efficiently and gain better insight from their asset and maintenance data.
Privacy
At Ultimo, your privacy is our priority. We are committed to safeguarding your personal data with transparency, integrity, and robust security measures. Our privacy practices are designed to respect your rights and comply with applicable data protection regulation.
-
Data Protection Legislation
We are firmly committed to privacy, security, compliance and transparency. This commitment extends to supporting our customers in meeting UK, EU & US data protection requirements, including those outlined in GDPR, UK GDPR and CCPA.
-
At Ultimo, we are committed to safeguarding your personal data. We collect, process, and store information that is necessary to deliver and improve our services, and we do so in accordance with all applicable data protection laws, including the GDPR, CCPA, and other relevant regulations.
Transparency and ControlWe believe in complete transparency. Our Privacy Policy clearly outlines what data we collect, why we collect it, and how it is used.
Secure Data HandlingYour information is protected by strong technical and organisation measures including encryption, access controls, and regular security audits. We never sell your personal data to third parties.
Accountability and ComplianceWe have designated a Data Protection Officer (DPO) responsible for overseeing our privacy practices. Regular internal reviews ensure we continuously meet evolving privacy standards and maintain customer trust.
SubprocessorsUltimo makes use of the sub-processors. Our sub-processors are kept up to date here.
-
Access management
Ultimo offers a robust suite of access controls and encryption tools to help customers safeguard their information effectively.
Data Hosting LocalityBased on the geolocation of our customers, we have various paired regions for hosting our EAM Software on the MS Azure Platform. Unless instructed otherwise by the customer, the geolocation of the main entity of the customer will be the hosting location (e.g. customer in EU, hosting in EU). MS Azure’s comprehensive security can be found here: Microsoft Trust Center Overview | Microsoft Trust Center.
Privacy by Design & by DefaultAt Ultimo, we integrate Privacy by Design and by Default into every stage of our development process. This means that privacy considerations are not an afterthought. They are embedded into the core of our products and services from the outset.
Data minimizationUltimo uses Data Lifecycle Management to ensure only necessary personal data is collected and retained for the purpose of the collection in both it’s roll as data controller and data processor.
Features in Ultimo EAM SoftwareAs a user of Ultimo EAM Software, you been given various features to be in control over your own data collection and retention. Ask your account manager for more information.
Sustainability
We are committed to ethical practices, thoughtful decision-making, and creating long-term value for our customers, employees, partners, and the wider communities we serve.
-
At Ultimo, sustainability is about responsibility, for people, society, the environment, and the trust our customers place in us. It’s embedded in how we work, make decisions, and deliver technology that supports a better future.
-
We believe in fair and ethical business conduct, respect for human rights, and equal opportunity for all. Acting with integrity, rejecting corruption or exploitation in any form, and fostering a safe, inclusive, and respectful workplace are fundamental to how we operate and collaborate with partners. These values are anchored in our Code of Conduct, which guides our everyday behavior and decision-making.
-
Strong governance underpins everything we do. We manage data, privacy, and security with the same care as we manage our business: responsibly, transparently, and in line with international standards. Every employee completes regular compliance and ethics training, ensuring that awareness and accountability remain part of our culture. Our approach ensures information is protected, risks are managed, and technology, including AI, is used with fairness and integrity.
-
Sustainability at Ultimo is not a project but a commitment. Through clear values, sound controls, and continuous improvement, we work to create lasting value for our customers, employees, and communities, whilst maintaining the highest standards of trust, responsibility, and ethical conduct.