Processing

Trust & Governance

Trust & Governance.

Operator-owned data, role-based access, audit trails, NIS2-aware governance, and a clear standards map — we separate marketing claims from verified claims.

01 / Company structure

Three entities, one ecosystem.

A Germany/EU product and R&D base, a Singapore international SaaS and commercial entity, and a Bangladesh engineering and implementation team.

Germany

HoneyBee Technologies GmbH

Germany

European product development, R&D, AI/ML, edge computing, energy-management, mobility/transport, automation, digital infrastructure, partner coordination, and EU/Germany market development.

Singapore

HoneyBee IoT (Pte.) Ltd.

UEN 202507612D

International SaaS, commercial, strategic, and Asia-Pacific entity.

Bangladesh

HoneyBee IoT Ltd.

Bangladesh

Engineering, development, implementation, and regional support.

02 / Data ownership

Your data stays yours.

Operator-owned data, export on demand, and no unnecessary lock-in. You decide where your data lives and you can take it with you.

  • Operator-owned data
  • Export on demand
  • No unnecessary lock-in
  • You choose what to export and when
03 / Security & governance

Governed by design.

Access, approvals, and accountability are built into everyday workflows — including a human-approval step for AI actions.

04 / NIS2-aware governance

NIS2-aware cybersecurity governance.

NIS2 — safe wording
HoneyBee supports NIS2-aware cybersecurity governance for applicable customers and deployments through role-based access control, audit trails, approval workflows, operator-owned data, export controls, incident visibility, infrastructure monitoring, and security-conscious deployment architecture. Applicability depends on the customer's sector, size, country, legal status, and national implementation of NIS2.

Note: NIS2 is an EU directive, not a product certification.

05 / Standards alignment

A clear standards map.

Each item carries a claim-control tag so you can tell, at a glance, what is available now, what is configurable or scoped, what is an internal mapping or self-assessment, and what is still on the roadmap or requires third-party certification.

NIS2-aware governance supportSupported where applicable
GDPR-aligned data handlingAvailable now
Article 28 DPA available, if applicableSupported where applicable
GoBD-aligned audit trail (Germany accounting)Module-scoped
DATEV-ready export where implementedModule-scoped
IEC 62443 self-assessment where applicableSelf-assessment
IEC 61724 KPI support (solar PV) where applicableModule-scoped
ISO/IEC 27001-aligned ISMS roadmapRoadmap
ISO/IEC 27002-aligned control-mapping roadmapRoadmap
ISO/IEC 27701-aligned privacy roadmapRoadmap
ISO 9001 readiness/roadmapRoadmap
ISO 14001 readiness/roadmap where relevantRoadmap
ISO 50001 readiness/roadmap where relevantRoadmap
SOC 2 roadmap/in-progressRoadmap
OWASP ASVS/Top 10 roadmapRoadmap
CIS Controls baseline checklistSelf-assessment
CSA CCM mapping roadmap for cloudRoadmap
EN 50549/VDE/IEEE 1547 grid-code profile support where implemented & project-scopedProject-scoped
CE/EMC/electrical safety for certified hardware onlyThird-party cert
Cyber Resilience Act readiness roadmap if applicableRoadmap
06 / Claim-control matrix

Every claim, classified.

Each category below tells you exactly what kind of claim a control represents. Every standards or compliance mention on this page carries one of these tags. We never present a roadmap or self-assessment item as a certification.

Category Meaning Example items
Available now Live in product today RBAC, audit trails, approval workflows, data export, MFA where applicable, human approval for AI actions
Implemented for specific modules only Real but scoped GoBD-aligned audit trail (accounting), IEC 61724 KPI support (solar PV monitoring), DATEV-ready export (where implemented)
Configurable Per-deployment setup Approval matrices, role scopes, retention, export controls, dashboard scope
Supported where applicable Depends on context NIS2-aware governance, EN 50549/VDE/IEEE 1547 grid-code profiles (project-scoped), Article 28 DPA
Self-assessment / internal control mapping Internal, not third-party IEC 62443-oriented self-assessment, CIS Controls baseline checklist, ISO 27002 control mapping
Roadmap Planned, not yet ISO/IEC 27001/27701, ISO 9001/14001/50001, OWASP ASVS, CSA CCM, Cyber Resilience Act readiness
Requires third-party certification External audit needed SOC 2, ISO 27001 certificate, IEC 62443 certificate, CE/EMC for hardware
Requires customer / project scoping Site/deal dependent HoneyCore Edge+ hardware, integrations, grid-code profiles, on-prem/private cloud
Requires local legal review Jurisdiction dependent NIS2 applicability, country tax/accounting localization, data-residency commitments
07 / What HoneyBee does not claim

Where we draw the line.

HoneyBee separates marketing claims from verified claims. Some controls are available now, some are configurable per deployment, some are internal mappings or self-assessments, and some require third-party certification or local legal review.

See also our Data Processing Agreement and our Experience page.

Talk to us about company & partnership.

For enterprise buyers, investors, banks, partners, and regulated customers — let's discuss governance, structure, and how HoneyBee fits your requirements.

Loading…
Loading the web debug toolbar…
Attempt #