Global Colocation Brand Achieves Compliance With PCI DSS and ISAE Standards


Jouke Albeda
“My comprehensive IT audit experience comes in handy and it didn’t take us that much effort to help our AMS1 data center in Amsterdam successfully prepare for the PCI DSS and ISAE3402 compliance audits,” said Jouke Albeda – Security & Compliance Manager at, a global provider of on-demand colocation services that paid more than $500,000 for its domain name, with its first large-scale AMS1 colocation data center located in Amsterdam, the Netherlands, has achieved 3rd party confirmed compliance with PCI DSS 3.2 and ISAE3402 standards. The certifications ensure that has enterprise-grade controls in place to protect payment data while safeguarding the effectiveness of its internal control system (ICS) as a service organization and global provider of professional ICT outsourcing solutions.

The PCI DSS (Payment Card Industry Data Security Standard) certification would be an important accreditation for financials and e-commerce merchants collocated at’s Amsterdam premises. The PCI DSS 3.2 standard provides a set of policies and procedures intended to ensure customers that their card data and financial transactions within this colocation data center environment in Amsterdam are successfully being protected at all times.

ISAE3402 is the international acknowledged outsourcing standard for services organizations. It provides customers with the assurance that their (sensitive) data is protected properly and adheres to stringent privacy guidelines. It also addresses risk management capabilities as well as anti-fraud measures taking into account the risks identified.’s 3rd party compliance validation for these PCI DSS and ISAE3402 certifications did not require any additional adjustments when being finalized, said Jouke Albeda – Security & Compliance Manager at, mainly due to his previous working experience as an IT auditor for EY and BDO. “As an IT auditor for multiple consulting firms, I’ve conducted many IT audits including ISAE compliance for companies within the data center industry,” said Jouke Albeda. “Now that I’m operating on the client-side, my comprehensive IT audit experience comes in handy and it didn’t take us that much effort to help our AMS1 facility in Amsterdam successfully prepare for these compliance audits.”

To learn more about, visit

Data Lifecycle Management Compliance

As’s management team is placing great emphasis on compliance and security efforts, one of their first hires was actually Mr. Albeda – who as a compliance, privacy and security expert is driving’s robust compliance management strategy.

“My comprehensive IT auditing experience allows us to go the extra mile for our customers when it comes to their compliance requirements,” added Mr. Albeda. “With regards to PCI DSS for example, you first have to define a scope to which the PCI DSS controls may apply. Upon defining your scope, you have to apply all security controls in the standard to the contained environment you have defined. Needless to say that an extensive PCI DSS scope will normally result in a more complex compliance trajectory that is harder to achieve. Not in our case. We chose to even include customer data lifecycle management in our PCI DSS compliance scope.”

Protecting Customer Data End-to-End

So for, achieving the PCI DSS compliance certification means that the company now even has 3rd party accreditation for securely processing customers’ data carriers. “As a pure-play colocation provider we’re purely focused on delivering colocation data center services, we don’t do cloud for example,” said Jochem Steman, CEO of “We do carefully listen to the needs of our customers though, including CSPs, enterprises, broadcasters and online gaming providers. Providing our colocation services on-demand with month-to-month contracts is an important asset within our product portfolio. It caters to the needs of cloud providers and enterprises alike. We also expect data lifecycle management to be quite an interesting service, as it unburdens our colocation customers helping them to protect their data end-to-end.”

PCI DSS includes a set of security standards created in 2004 by Visa, MasterCard, Discover, and American Express. ISAE3402 was developed by the IAASB (International Auditing and Assurance Standards Board), prescribing Service Organization Control (SOC) reports, first being published in 2011. As’s Security & Compliance Manager, Mr. Albeda is not only focused on maintaining these compliance accreditations. Other certifications already achieved or planned to obtain include ISO27001, ISO14001, ISO9001, and Uptime Institute.

About’s investors have committed themselves to invest heavily in state-of-the-art data center infrastructure – to meet the market’s growing need for energy efficient, highly interconnected and modular colocation facilities, in which organizations can flexibly and securely host their critical IT infrastructure while cloud computing needs are addressed.’s customized, reliable and innovative data center solutions are accompanied by the company’s best-in-class customer support.