Trust Center

Vertrouwen ontstaat door transparantie. Daarom geven we je inzicht in hoe SelfGuide omgaat met infrastructuur, Service Delivery, ons product en de privacy.

Categorieën

Infrastructure

To support the secure and reliable delivery of our services, we utilize several cloud hosting platforms. A comprehensive set of controls is implemented to manage and protect this infrastructure, covering access management, monitoring, auditing, backup and recovery, and controlled software and infrastructure deployments.

Hosting locations

All data resides in the European union whereas datacenters of Microsoft Azure are used for hosting purpose and Amazon AWS for disaster recovery. To be more specific, hosting is performed in Azure region West Europe with a datacenter located in The Netherlands and backup sets are stored in Azure region North Europe with a datacenter in Ireland. Amazon AWS is configured to store all data in AWS region Europe with a datacenter in Germany.

Encryption

Encryption ensures that data is only usable when accessed from a trusted platform or source. Data encryption is applied and configured for:

  • Hosting: data being persisted, for normal operations and for disaster recovery purpose, is encrypted using hosting platform functionality with platform managed keys
  • Transport: data being transmitted is always encrypted using TLS 1.2 or higher, where unencrypted connections are automatically redirected to encrypted connections. Data exchanged between platform resources utilize platform managed certificate and data exchanged between SelfGuide and users utilizes SelfGuide managed certificates
  • SelfGuide Recorder: recorded data is kept local on the device, encrypted using .NET data protection functionality with a user scope

Logical access

Logical access is governed by a comprehensive access policy, with regular reviews and audits to ensure access remains tightly controlled. Key measures include:

  • Personal accounts protected by two factor authentication
  • Role based access control and least privileged permissions
  • Conditional access policies that restrict account usages to trusted devices, locations and scenarios
  • Separate administrative accounts for privileged access
  • Centralized identity and access management
  • Auditing on account management activities and monitoring of privileged account changes
  • Periodic reviews for anomalous account activity, inactive accounts and access entitlements

Auditing

Audit logs capture activities performed across the infrastructure, including access being granted, changes made in the infrastructure, and access to sensitive data. These logs are used to detect anomalous activity and investigate incidents. Audit logging is enabled or all infrastructure components used to deliver our services.

Monitoring

Monitoring is implemented across all infrastructure components used to deliver our services, ensuring that administrators are promptly alerted to issues that may impact service delivery. Performance metrics, events, logs, and synthetic transactions are continuously collected and used to:

  • Provide real-time visibility into the operational health of our environment through dashboards
  • Generate 24×7 alerts and notifications to respond to potential issues
  • To identify trends, support capacity planning, and drive continuous improvement

Backup

Data integrity is a key priority. Automated backups are maintained for all persisted data using native capabilities of the hosting platform, enabling recovery from events that could compromise data integrity, such as failed data migrations or other operational incidents. Backup sets are stored in geographically and physically separate locations from the primary data stores to enhance resilience. Regular restore tests are performed to verify backup integrity, availability, and the effectiveness of recovery procedures.

Environment separation

Infrastructure is logically segregated into dedicated development, test, and production environments. This separation ensures that all development activities, including infrastructure changes, can be developed, validated, and tested before being deployed to production, reducing operational risk and protecting service stability. Automated DevOps pipelines, resource templates and Infrastructure-as-Code (IaC) techniques are used to maintain consistency across environments, support controlled deployments, and enable infrastructure changes to be thoroughly tested prior to production release.

Service Delivery

Reliable service delivery is supported by transparent communication, responsive support, and a structured delivery process. This section describes how we deliver, support, maintain, and continuously improve SelfGuide for our customers.

Release frequency

SelfGuide is continuously improved through ongoing investments in new functionality, platform quality, security, and maintainability. Enhancements are released to all tenants approximately every two weeks. This frequent release cadence keeps changes small and manageable, enabling faster delivery of customer value, easier adoption of new features, and quicker identification and resolution of potential issues.

In addition to these scheduled releases, critical bug fixes may be deployed as hotfixes between release cycles when an issue requires immediate attention and a validated fix is available.

Staged releases

To ensure the quality and reliability of each SelfGuide, releases are deployed gradually across all SelfGuide tenants. This staged rollout approach allows us to:

  • Validate releases in production-equivalent environments
  • Gather early feedback from internally used tenants
  • Detect and address potential issues before the release reaches all customers

By rolling out releases in stages, we can further test a release, respond quickly to feedback, minimize the impact of potential issues, and maintain the availability and quality of SelfGuide.

After deployment begins, it typically takes around one week for a release to become available on all tenants.

Early access

During a release, new or updated functionality may be deployed without being immediately available to all users. This deliberate approach allows us to gradually introduce new capabilities, gather feedback, and further validate features before they are released more broadly.

Features with a significant impact or requiring extensive validation may follow an early access lifecycle consisting of one or more of the following stages:

  • Beta – Private access by invitation only. Customers participating in a beta program work closely with the development team, providing feedback and receiving updates on enhancements and changes.
  • Preview – Public access on request. Preview features are announced through product updates and can be enabled for interested customers upon request.
  • General Availability (GA) – Available to all customers as a fully released feature.

The appropriate release approach is determined on a feature-by-feature basis. Depending on the expected impact and feedback requirements, functionality may be released directly to all customers or first made available through one or more early access programs.

Product updates

Keeping users informed and aligned as SelfGuide evolves is important to us. Staying up to date enables users to get the most value from the product by adopting new capabilities and helps prevent questions that may arise from product changes.

For every release, whether a planned release or a hotfix, a product update is published describing all changes. Product updates are available here.

To stay up to date, users can:

  • Read the product update when a notification is displayed within the product.
  • Subscribe to product updates to receive an email whenever a new update is published.
  • Register for What's New? webinars to learn about recent improvements, see live demonstrations, and ask questions.

Roadmap

A publicly available roadmap is used to communicate our plans and future direction for SelfGuide. The roadmap provides visibility into upcoming enhancements, recently delivered functionality, and longer-term ideas under consideration. Roadmap items are categorized as:

  • Upcoming: Features planned for delivery in the coming months
  • Finished: Functionality that has been released and is generally available to customers
  • Ideas: Longer-term concepts and improvements that are being evaluated for future development

The SelfGuide Roadmap is updated regularly to ensure the information remains accurate and up to date.

Availablity

SelfGuide is delivered as a Software-as-a-Service (SaaS) solution, where trust and reliability are essential to building long-term customer relationships. Service availability is a key aspect of that trust and is supported through a combination of technical and operational measures. These measures are designed to minimize service interruptions, detect potential issues early, and ensure that maintenance activities and changes can be performed with limited impact on customers.

Key measures include:

  • Careful selection of cloud hosting providers
  • A resilient product architecture
  • Separation of development, test, and production environments
  • Separation of customer environments
  • Continuous monitoring, dashboards, and automated notifications
  • Maintenance scheduled, where feasible, outside business hours
  • Frequent releases using controlled and staged deployment processes

We strive to provide a reliable and continuously improving service experience for our customers. Our SaaS Terms and Conditions include a best-effort availability commitment that aligns with the standard subscription offering. For customers with higher availability requirements, an optional Service Level Agreement (SLAs) is available, providing enhanced availability commitments and support assurances.

Status

To provide transparency around major incidents, a public status page is available. The status page is used during major incidents to share timely updates on the impact, progress, and resolution of issues that may affect service availability or performance.

Disaster recovery

A disaster recovery process is implemented to safeguard data and restore services in the event of a major outage or disaster scenario. The process is designed to support data recovery, maintain business continuity, and validate our ability to recover from significant service disruptions. The process includes:

  • Daily offsite, vendor-independent backups that are maintained automatically to ensure data availability and maximum data retention
  • Regular restore tests using offsite backup data to validate backup integrity and recovery procedures
  • Dedicated emergency ("break-glass") accounts that provide controlled administrative access during disaster recovery scenarios or identity service disruptions

Telemetry & statistics

To continuously improve SelfGuide and ensure a reliable user experience, we collect operational data that provides insight into how the product is used and performs. Two types of data are collected:

  • Telemetry data generated by user interactions and system behavior, including requests, dependencies, exceptions, and specific application events
  • Statistical data collected over time, consisting of aggregated usage counters and metrics at tenant level

The collected data helps us:

  • Monitor the health and performance of our services
  • Analyze incidents and identify root causes more efficiently
  • Evaluate feature adoption and feedback during preview and early access programs
  • Identify usage trends that help guide future product development

All collected data consists of metadata only and does not include customer content or personally identifiable information. Access to operational data is strictly limited to authorized personnel and governed by role-based access controls and auditing.

Support

Support is available to help customers with questions, tenant configuration changes, and incident resolution to ensure effective use of SelfGuide. Customers can contact support via email (support@selfguide.com) or the contact form. Requests are handled on a best-effort basis during business hours, as defined in our SaaS Conditions. An optional SLA is available for customers who require enhanced support levels and additional service commitments.

Compatibility

SelfGuide is designed to provide a consistent user experience across modern devices and platforms. End users can access SelfGuide using the latest versions of major web browsers, including Chrome, Edge, Safari, and Firefox, on their preferred operating system and device, such as a computer, tablet, or mobile device.

Content creation is simplified through the SelfGuide Recorder, which requires:

  • A current Microsoft Windows operating system
  • Standard desktop or laptop hardware specifications
  • Permission to install software in the user's profile, or pre-installation by administrators
  • Access to the device's screen and input during recording sessions

The SelfGuide Recorder captures user interactions directly from the desktop session and does not rely on application-specific integrations, interoperability components, or modifications to the applications being recorded.

Common device and session virtualization technologies, including Citrix and VMware environments, are supported. Compatibility may depend on the specific configuration of the virtualized environment. Security features that restrict screen capture, user input monitoring, or interaction with the desktop session, such as Citrix App Protection, can interfere with SelfGuide Recorder functionality and may prevent successful recordings.

For environments where the SelfGuide Recorder cannot be used, such as non-Windows operating systems or devices where software installation is restricted, instruction steps can be created directly from uploaded images and screenshots.

Known limitations:

  • Microsoft Windows Server 2019 is not supported for recording sessions and may result in black screen recordings.
  • Low-performance devices may not meet the requirements for reliable recording and can result in missing instruction steps.

Product

SelfGuide provides built-in functionality to help organizations manage access, protect sensitive information, and maintain visibility into how content is accessed and used.

Authentication

Users must authenticate before they can access and use SelfGuide. Two authentication options are available:

  • Native Identity Provider: The default authentication module included with SelfGuide, supporting username/password authentication.
  • Microsoft Entra ID Integration: An optional authentication module that can replace the native identity provider and enables advanced identity and access management capabilities, including single sign-on (SSO), multi-factor authentication (MFA), and Conditional Access policies.

Customers can choose which authentication method best fits their requirements; however, only one authentication provider can be active at a time. To enhance security and leverage modern identity management capabilities, the Microsoft Entra ID integration is recommended whenever possible.

In addition to user authentication, SelfGuide supports application identities for automation and system-to-system integrations. Application identities authenticate using a client key and client secret, allowing automated processes to securely access SelfGuide without relying on interactive user authentication.

Authorization

Permissions are granted to users and application identities through a role-based access model. Each role is designed to provide the level of access required to perform specific tasks within SelfGuide.

The following roles are available:

  • User: consumes content to learn, follow procedures, and find answers to questions.
  • Editor: creates and maintains content for end users.
  • SelfGuide Manager: acts as a SelfGuide ambassador within the customer organization and provides oversight of adoption, content usage, and platform utilization.
  • Administrator: manages the SelfGuide environment, configuration, and user administration for the customer.

Roles are hierarchical, meaning permissions accumulate as higher-level roles are assigned. For example, an Editor also inherits the permissions of a User, and a SelfGuide Manager inherits the permissions of both an Editor and a User.

Roles are assigned by Administrators and can be configured during user creation or updated later as responsibilities change. When Microsoft Entra ID integration is enabled, unknown users who successfully authenticate are automatically provisioned within SelfGuide and assigned the User role by default. A REST API is available to automate user provisioning and role assignments for large-scale or advanced user management scenarios.

Alternative access methods

We continuously enhance SelfGuide to better integrate with customer IT environments and support a variety of content-sharing scenarios. To facilitate this, SelfGuide offers several alternative access methods that extend beyond standard user authentication and authorization mechanisms.

Examples include:

  • Guest Access: enables content to be shared with anonymous users
  • Embedding: llows SelfGuide content to be integrated into third-party applications and portals.
  • Private Links: enables specific content to be shared with an individual without requiring or allowing a SelfGuide account
  • LTI Integration: enables SelfGuide Courses to be accessed and used directly from a Learning Management System (LMS). In this scenario, authentication and authorization continue to rely on the identity provider configured for the SelfGuide tenant, either the Native Identity Provider or Microsoft Entra ID integration

As these access methods may introduce additional security and governance considerations, several safeguards are implemented:

  • Disabled by default
  • Can only be enabled by an Administrator
  • Contextual guidance is provided to Administrators, including information about risks and recommended best practices
  • Usage can be monitored and managed through administrative functionality
  • Usage and configuration changes are recorded in the audit log

These controls help customers make informed decisions about the use of alternative access methods while maintaining visibility and oversight of how content is shared and accessed.

Auditing

Activities performed within SelfGuide result in audit-related information being stored, providing visibility into user and system actions across the platform. This information covers a wide range of operations, including content creation and usage, content sharing activities, configuration changes, and tenant administration.

The stored information helps organizations gain insight into how SelfGuide is being used, supports compliance and governance requirements, and provides the information needed to investigate incidents or review historical activities.

Audit information can be made available upon request through support.

Censoring

Images used in SelfGuide instructions, whether captured using the SelfGuide Recorder or uploaded by an Editor, may contain sensitive information. Examples include personal identifiers, profile pictures, internal application URLs, and application configuration data.

As a best practice, SelfGuide recommends:

  • Creating instructions in non-production environments whenever possible
  • Using fictional accounts and sample data when instructions must be created in production environments

When these approaches are not feasible, SelfGuide provides built-in censoring functionality that can be used by Editors to remove sensitive information from images during the instruction creation process. Censoring is applied directly to the source image and cannot be reversed after it has been saved. This approach helps prevent the accidental disclosure of sensitive information by ensuring that censored content cannot be restored or made visible again at a later stage.

Privacy

Privacy staat centraal in de manier waarop wij onze dienstverlening vormgeven. Persoonsgegevens worden zorgvuldig verwerkt en beschermd, volledig in lijn met de geldende wet- en regelgeving.

No items found.

Organisatie

De beveiliging van je gegevens heeft onze hoogste prioriteit. Daarom hanteren we strikte beveiligingsmaatregelen en processen om de vertrouwelijkheid, integriteit en beschikbaarheid van uw data te waarborgen.

Incident management

AI

We streven ernaar SelfGuide voor zoveel mogelijk gebruikers toegankelijk te maken. Daarom houden we bij de ontwikkeling van onze software rekening met de geldende toegankelijkheidsrichtlijnen.

No items found.

Heb je vragen over beveiliging of compliance?

ISO 27001:2022, certified by Brand Compliance