Insights and updates

From emerging regulation to deal mechanics, we write about the questions founders and investors actually ask — practical analysis you can put to work.

Penetration Testing

Penetration testing (pentesting) is the practice of systematically attempting to exploit security vulnerabilities in systems, networks, applications, or physical premises—simulating the actions of a malicious attacker to identify weaknesses before adversaries do.

ISO 27001

ISO/IEC 27001 is the international standard specifying requirements for an Information Security Management System (ISMS).

SOC 2

SOC 2 (Service Organization Control 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA) for evaluating service organizations’ controls relevant to security, availability, processing integrity, confidentiality, and privacy.

Schrems II

Schrems II is the colloquial name for the 2020 Court of Justice of the European Union (CJEU) decision (Case C-311/18) that invalidated the EU-US Privacy Shield framework and imposed strict requirements on international personal data transfers under GDPR.

NIS2 Directive

The NIS2 Directive (Directive 2022/2555) is EU cybersecurity legislation expanding the original NIS Directive (2016). Member States were required to transpose it into national law by October 2024.

Digital Services Act (DSA)

The Digital Services Act (DSA) is EU regulation (Regulation 2022/2065, fully applicable from February 2024) governing online intermediaries—from web hosts to large social platforms and search engines.

Digital Markets Act (DMA)

The Digital Markets Act (DMA) is EU regulation (Regulation 2022/1925, in force from May 2023, full effects from March 2024) that imposes ex-ante obligations on major digital platforms designated as “gatekeepers” — providers of core platform services with substantial market power.

Trade Secret

A trade secret is confidential business information that derives commercial value from being kept secret and is subject to reasonable measures to maintain its secrecy.

Context Window

The context window of an LLM is the maximum amount of text (measured in tokens) it can process in a single forward pass—including both the input prompt and the generated output.

Multi-modal AI

Multi-modal AI refers to systems that can process and generate multiple types of data—typically combining text, images, audio, video, and code in a single model.