Frameworks & Principles

EuroChat is built on open European standards and complies with all relevant Dutch and European legislation for government communications.

Government communications require more than encryption. EuroChat is architecturally designed to comply with the most stringent Dutch and European frameworks — from information security to archiving and digital sovereignty.

Legislation & Standards

BIO 2

Mandatory NL government

Baseline Information Security Government 2. The mandatory security framework for all Dutch government organisations. EuroChat implements all BIO 2 measures as baseline.

NIS2

EU Directive

EU Network and Information Security Directive. EuroChat complies with the reporting obligations, risk management and security measures required by NIS2 for digital infrastructure.

VIRBI

Central Government

Government Information Security Regulations for Special Information. EuroChat's classification system (12 levels, including NATO and EU) is directly based on VIRBI classifications.

RORA

Open standard

Government Open and Reproducible Analysis. EuroChat uses open protocols (Matrix) and reproducible build processes. No vendor lock-in, fully auditable.

Open Standards

Forum Standaardisatie

EuroChat implements only open standards from the Forum Standaardisatie list: Matrix, OIDC, TLS 1.3, S/MIME, CalDAV and OpenAPI. No proprietary protocols.

DOSA

Architecture framework

Digital Government Strategy and Architecture. EuroChat aligns with DOSA principles for federated architecture, component reuse and interoperability between government organisations.

ABRO 2026

Supplier requirements

Additional Security Requirements for Government Contracts. EuroChat meets the security requirements that apply to suppliers working for the Dutch central government.

OWASP Top 10

Security standard

EuroChat is developed with security-by-design. All endpoints are tested against the OWASP Top 10 vulnerabilities. Continuous security scans are part of the CI/CD pipeline.

Archives Act & DUTO

Retention obligation

Digital exchange in supervision and investigation. EuroChat complies with the requirements of the Dutch Archives Act with tamper-proof storage, audit trails and legal hold functionality.

EU Sovereignty

EU First

100% hosted in Europe. No dependency on US cloud providers. GDPR-compliant by design. Your data stays under European law — always.

Built for government, controlled by government

EuroChat is open-source, self-hosted and fully auditable. Your organisation has complete control over data, configuration and access. No hidden data flows, no dependency on commercial cloud services.