OptiTech
    • Docs
    • Pricing
    • Build the program
      • Gap analysisKnow what applies to you
      • Framework libraryDo it once, prove it everywhere
      • Evidence collectionProof from the tools you use
      • Risk registerRisk linked to controls
    • Run it day to day
      • Incident reportingMSB and IMY deadlines, handled
      • Policies & documentsTemplates, reviews, signatures
      • Supplier riskVendors, contracts, DORA register
      • Training & awarenessIncluding the board
    • Prove it
      • Trust CenterShow compliance before anyone asks
      • Auditor modeA portal, not a shoebox
      • DashboardsBoard-ready reporting
      • AI copilotFluent in Swedish law
      • All servicesBrowse everything

    What is OptiTech

    Serverless Postgres, by Databricks

    • Use cases
      • Serverless AppAutoscale with traffic
      • Multi-TBScale and restore instantly
      • Database per tenantData isolation without overhead
    • Build & operate
      • PlatformsOffer Postgres for your users
      • Dev/TestsProduction-like environment
      • AgentsBuild full-stack AI agents
    • Nordic core
      • NIS2The Swedish Cybersecurity Act
      • DORAFinance and its ICT providers
      • GDPRRoPA and the IMY breach flow
      • ISO 27001The full control catalog
      • EU AI ActHigh-risk AI, phasing in
    • Also covered
      • CRAProducts with digital elements
      • SOC 2What US buyers ask for
      • ISO 27701Privacy on top of ISO 27001
      • ISO 22301Business continuity
      • TISAXThe automotive standard
      • All frameworksBrowse everything
    • Learn
      • BlogTechnical posts & product updates
      • Case studiesExplore customer stories
      • ChangelogProduct updates
      • CommunityConnect on Discord
      • StartupsBuild with OptiTech
    • Company
      • About usThe company and the mission
      • CareersLIA & internships with us
      • Contact salesContact sales team
      • SecurityCompliance & privacy
      • StatusService status
    Log inBook a demo
    • All posts
    • Product
    • Company
    • Engineering
    • Case Studies
    • Community
    • Postgres
    • Guides
    • Changelog
    Blog

    What we’re shipping.
    What you’re building.

    OptiTech
      A Nordic Compliance Company
      OptiTech status loading...

      © OptiTech 2026. All rights reserved. OptiTech and the OptiTech logo are trademarks of OptiTech Sverige AB.

      Privacy PolicyTerms of UseOptiTech Platform TermsCookie Policy

      Services
      • Gap analysis
      • Framework library
      • Evidence collection
      • Risk register
      • Incident reporting
      • Policies & documents
      • Supplier risk
      • Training & awareness
      • Trust Center
      • Auditor mode
      • Dashboards
      • AI copilot
      • All services
      Frameworks
      • NIS2
      • DORA
      • GDPR
      • ISO 27001
      • EU AI Act
      • CRA
      • SOC 2
      • ISO 27701
      • ISO 22301
      • TISAX
      • All frameworks
      Company
      • About
      • Blog
      • Careers
      • Contact Sales
      • Security
      Resources
      • Docs
      • Changelog
      • Support
      • Community Guides
      • FAQs
      • PostgreSQL Tutorial
      • Startups
      Community
      • LinkedIn
      • Microsoft
      • Facebook
      Zero-Downtime Patching Part 1: Prewarming
      EngineeringMar 27, 2026

      Zero-Downtime Patching Part 1: Prewarming

      Ensuring customer databases are always available is one of the most important things we do in Neon and Lakebase. We’ve designed the system with redundancy at every level, automatically failing over and recovering your database in the event of hardware or software failures. In a l...
      Neon works with Stripe Projects for agentic provisioning
      ProductMar 26, 2026

      Neon works with Stripe Projects for agentic provisioning

      For most of 2025, AI coding agents got good at a specific thing writing code. Give an agent a prompt, and it could scaffold an app, wire up an API, write migrations. But when the code was done, the agent stopped. Spinning up a real database, creating an account, getting credenti....
      CompanyAug 07, 2026

      Access control and least privilege in practice

      Least privilege is one of the most tested control areas in every framework, and it's where good intentions and daily practice drift apart fastest. This guide covers role based access, the joiner mover leaver lifecycle, timely deprovisioning, access reviews, and how OptiTech keeps...
      CompanyAug 07, 2026

      AI governance and the EU AI Act: where to start

      The EU AI Act sorts AI systems by risk and scales the rules to match. This guide walks through the four risk tiers, what high risk systems owe, how the Act overlaps with GDPR, and how OptiTech helps you inventory AI systems, assign risk, and keep controls and evidence current.
      CompanyAug 07, 2026

      AI-styrning och EU:s AI-förordning: så kommer du igång

      AI förordningen sorterar AI system efter risk och anpassar reglerna därefter. Den här guiden går igenom de fyra risknivåerna, vad högrisksystem kräver, hur förordningen överlappar med GDPR och hur OptiTech hjälper dig att inventera AI system, tilldela risk och hålla kontroller oc...
      CompanyAug 07, 2026

      The asset register: the foundation of security and compliance

      You can't protect what you can't see. An asset register is the inventory of the systems, data, devices, and owners your business depends on, and almost every framework assumes you already have one. This guide covers what belongs in it and how OptiTech keeps it connected to your r...
      CompanyAug 07, 2026

      Åtkomstkontroll och lägsta behörighet i praktiken

      Lägsta behörighet är ett av de mest testade kontrollområdena i varje ramverk, och det är där goda avsikter och daglig praktik glider isär snabbast. Den här guiden går igenom rollbaserad åtkomst, livscykeln när någon börjar, byter roll och slutar, behörighetsgranskningar och hur O...
      CompanyAug 07, 2026

      Audit findings and remediation: what auditors actually judge you on

      A clean audit isn't one with zero findings. It's one where every finding has an owner, a due date, and evidence at the end. This guide shows how to run audit findings and remediation as a process, and how OptiTech tracks findings, assessments, and evidence in one place.
      CompanyAug 07, 2026

      Autentiseringsstandarder: MFA och passkeys

      Flerfaktorsautentisering och passkeys har gått från trevligt att ha till ett baskrav i varje ramverk och varje cyberförsäkring. Den här guiden går igenom varför lösenord ensamma inte räcker, hur nätfiskeresistent autentisering ser ut, och hur OptiTech gör din autentiseringspolicy...
      CompanyAug 07, 2026

      Authentication standards: MFA and passkeys

      Multi factor authentication and passkeys have moved from nice to have to a baseline expectation across every framework and cyber insurance policy. This guide covers why passwords alone fail, what phishing resistant authentication looks like, and how OptiTech turns your authentica...