CLOUD Act Exposure
US-headquartered vendors fall under the CLOUD Act regardless of where data is stored. Your data may be accessible to US authorities.
Built by a team in Finland and hosted 100% in the EU. Your training data, participant records, invoices, certificates, and audit logs stay under European rules.
Hosting
100% EU
CLOUD Act
Immune
API Access
Open
Security & Compliance
Compliance Posture
GDPR
CLOUD Act
NIS2 / DORA
Data Residency
REST / GraphQL API
You pick a platform, then it sits for weeks while compliance asks where the data lives and who can reach it. With a US-hosted vendor, the answer is rarely a clean yes.
“We need a clear answer on where training data is stored and who can access it.”
Customers and auditors increasingly ask where training data is stored and who can access it.
What compliance teams face
Vendors with CLOUD Act exposure.
GDPR handled as paperwork, not daily practice.
NIS2, DORA, EU Data Act deadlines approaching.
US-headquartered vendors fall under the CLOUD Act regardless of where data is stored. Your data may be accessible to US authorities.
Most platforms treat GDPR as a setting, not as how the system is built. A data-residency "option" is not the same as data that stays in the EU.
Limited API access creates vendor lock-in. Data export is restricted and integrations require expensive custom work.
NIS2, DORA, and the EU Data Act raise the bar for how data is handled and moved. A platform that is not ready for them now will leave you with gaps.
Hosting, APIs, audit trails, access control. Every layer is European by default.
Step 01
100% EU-hosted. Data never leaves European jurisdiction. Immune to the U.S. CLOUD Act.
Step 02
Full API access to your stack. Connect to any LMS, CRM, or accounting system. Data always exportable.
Step 03
Every action recorded in an immutable audit trail. Full provenance for regulatory review.
Step 04
Granular permissions at organisation, department, and role level. SSO + BankID + FTN + regional e-ID.
CompetenceFlow keeps these requirements connected to the training records themselves.
NIS2 Directive
DORA
EU Data Act
Region-specific compliance, identity, and integrations, all covered.
Identity
Swedish BankID, Norwegian BankID, Finnish Trust Network (FTN)
Finance Integration
Visma (Netvisor, Tripletex, e-conomic) • Fortnox
Credential Registers
Taitorekisteri (Finland) • SSG Skillnation • ID06
Compliance
GoBD-compliant audit trails • BSI C5 ready • AZAV workflow support
Finance Integration
DATEV • SKR03/04 • ZUGFeRD e-invoicing
Audit Trail
Journal entries you cannot rewrite • Full provenance chain
Cloud Standard
SecNumCloud alignment • EU-hosted infrastructure
Quality Framework
Qualiopi audit-ready workflows • Evidence trail generation
E-Invoicing
Factur-X • Peppol • Machine-readable formats
No hidden costs. No vendor lock-in. Full data export at any time. Annual contracts with a standard exit clause.
See Pricing arrow_forwardFull access to your data. Connect to any system in your stack.
CompetenceFlow API
v2 • REST • GraphQL
JSON-native • OAuth 2.0 • Webhook support • Full data export in JSON/CSV
Data Export
Full, anytime
No-Code Builder
Drag-and-drop connectors
Vendor Lock-in
Zero
Core features
EU hosting and auditability are not separate from the product. They protect the records that matter: course bookings, participant data, trainer qualifications, invoices, certificates, and renewal messages.
Build course dates, set capacity, assign rooms, and keep participant lists up to date.
See feature arrow_forwardLet customers book one seat or a whole group, then collect participant details later.
See feature arrow_forwardGive trainers their courses, participant lists, attendance, materials, and feedback.
See feature arrow_forwardTurn bookings and attendance into invoices, with checks before month-end.
See feature arrow_forwardSend joining instructions, reminders, certificate expiry messages, and renewal links.
See feature arrow_forwardAnswers to the concerns we hear most from training providers evaluating a platform change.
Built by a team in Finland. Hosted in Europe. Compliant with European regulation. See it in action.