Don't take our word for it. Verify.
Demonstrable compliance, verifiable certifications and auditable infrastructure: the documentation your DPO, your auditor or a public tender panel needs.
- GDPR
- eIDAS
- Decree-Law 12/2021
- FIPS 140-2 Level 3


Legal framework
Built within European law, not adapted to it.
The three legal pillars that frame the service, and what each one guarantees in practice.
GDPR: Regulation (EU) 2016/679
Data processing in the EU (Portugal), with no transfers to third countries. Full traceability, data minimisation and records of processing available to clients who need to include them in their own compliance records.
eIDAS: Regulation (EU) No 910/2014
Certified communications (Registered Email) rely on qualified certificates issued by providers on the EU Trust List, with cross-border legal validity in all 27 Member States.
Decree-Law No. 12/2021
The platform's certified electronic communications are treated as equivalent to registered mail with acknowledgement of receipt, with evidential value in court in Portugal.
Technical certifications
Cryptography is not a promise. It is audited hardware.
The technical certifications behind certified communications, verifiable by any auditor.
Thales HSM: FIPS 140-2 Level 3
Cryptographic operations for certified communications run on Hardware Security Modules certified to FIPS 140-2 Level 3, the same standard used in banking. Keys never leave the hardware, not even in the event of an attack.
Qualified certification authorities
Qualified certificates are issued by Asseco and Multicert, trust service providers on the EU Trust List, supervised by the competent national authorities.
SSL/TLS certificates
Sooma also partners with the certification authorities Asseco and Multicert to issue Wildcard SSL/TLS certificates for clients: the same chain of trust that protects our own infrastructure.
Due diligence
Documentation for your evaluation process.
If you are evaluating Sooma in a procurement process, audit or public tender, the team provides the compliance documentation you need: technical description of the infrastructure, data processing agreement, privacy policy and evidence of the applicable certifications. Talk to us and tell us what your process requires.
Request documentation →Frequently asked questions
Certifications and compliance
The questions DPOs, auditors and tender panels ask us most often.
Does Sooma's Registered Email have the same legal validity as a registered letter?
Yes. Under Decree-Law No. 12/2021, certified electronic communications are treated as equivalent to registered mail with acknowledgement of receipt, and eIDAS qualified certificates are admissible as evidence in court in Portugal and the EU.
Who issues the qualified certificates?
Qualified trust service providers (Asseco and Multicert), on the EU Trust List and supervised by the competent authorities.
Can I use Sooma's documentation in my own GDPR audit?
Yes. We provide the information needed for our clients' records of processing and compliance assessments. Talk to the support team.
Is Sooma subject to the US CLOUD Act?
No. Sooma is a Portuguese company, with infrastructure in Portugal, subject exclusively to Portuguese and European law, unlike providers subject to US jurisdiction, regardless of where their servers are located.
Compliance that is verified, not rubber-stamped.
Request the documentation your process needs from our team in Europe.
