Salta al contenuto principale
Lympha technologies

FAQ - Frequently asked questions

Real questions - the kind we receive from clients, tenders, and specifications.

349 questions

Company & Vision 16 questions

Who we are, where we come from and how we are organized: offices, history, Business Units and the principles that guide our choices.

Learn more: About us Our story Vision Contact

Who is Lympha Technologies?

Lympha Technologies S.r.l. is a Service Provider & Systems Integrator with its registered office in Bologna (Via Guglielmo Marconi, 32) and its operational office in Castel San Pietro Terme (BO). It designs, manages and secures data centers, server farms and IT systems for local public administration, healthcare, large enterprises and SMEs.

faq-domande-frequenti#chi-e-lympha-technologies

What is the origin of the name “Lympha”?

Lympha is an ancient Roman deity of fresh water, one of the twelve duces deities of Roman farmers. Three key meanings derive from the myth: sap (what nourishes and makes things grow), limpid (clarity and transparency), inspiration and wisdom (knowledge flowing from the source).

faq-domande-frequenti#origine-nome-lympha

How long have you been working in this sector?

Since 2010, when the “Lympha Tech” project was recognized as an innovative business idea in the ICT sector for the adoption of virtualization and cloud computing. The S.r.l. was founded in 2011, incubated by ASTER within the WeTECH-OFF project. Since 2014 we have partnered with Executive Service (today EXE.IT S.r.l. SB), with whom the 00GATE Green Data Center was built.

faq-domande-frequenti#da-quanto-tempo-operate

How is Lympha Technologies organized?

The company is structured into 8 specialized Business Units (CNS, PRJ, PCS, SEC, AED, NOC, NET, OTS) with integrated Competency Centers that operate vertically within their own BU and horizontally in support of the others — or directly embedded in the customer's IT department.

faq-domande-frequenti#come-e-organizzata-lympha

What does “Partner, not supplier” mean?

It is one of the three pillars of our Vision: we build long-term value, anticipating change and supporting our customers' decisions. We avoid vendor lock-in — including lock-in to ourselves.

faq-domande-frequenti#partner-non-fornitore

Where are your data centers located?

Our Green Data Center is called 00GATE and is located in Castel San Pietro Terme (BO), at Via Antonio Meucci, 24/i/2. Data remains exclusively in Italy.

faq-domande-frequenti#dove-si-trovano-i-data-center

How can I contact you?

Email: info@lymphatech.it — Phone: +39 051 0981815 — Operational office: Via Antonio Meucci, 24/c — 40024 Castel San Pietro Terme (BO). A contact form is available on the website, with a selector for your area of interest.

faq-domande-frequenti#come-contattarvi

Are you part of the Climate Neutral Data Center Pact?

No, we have not joined the Climate Neutral Data Center Pact, which is a voluntary self-regulation initiative with a 2030 target. The choice behind 00GATE was a different one: designing it from the outset to produce no emissions — timber structure, free cooling with no refrigeration, 100% renewable energy — and having it verified by a third party through the Green Accredia® certification.

faq-domande-frequenti#climate-neutral-data-center-pact

Do you have strategic technology partnerships?

Yes, and they are declared: Libraesva, Oplon and Veeam. They remain choices, not constraints: our approach is vendor-neutral and we integrate open source technologies (OpenStack, PostgreSQL, Ollama) or commercial ones depending on the use case, without tying you to a single supplier — ourselves included.

faq-domande-frequenti#avete-partnership-tecnologiche

How many Business Units do you have?

Eight: CNS (Data Center Design), PRJ (Business Continuity & Disaster Recovery), PCS (Private Cloud Services & IT Consulting), SEC (IT Security), AED (Applications, ERP & Development), NOC (Network & Security Operations Center), NET (Networking & Unified Communication), OTS (Outsourcing).

faq-domande-frequenti#quante-business-unit-avete

Do you work with the Fashion & Luxury sector?

We do not have a vertical offering dedicated to fashion & luxury: the sectors we cover with specific content and skills are local public administration, healthcare, large enterprises and SMEs. Business continuity, data protection and private cloud services are however cross-sector and are sized around the customer's critical process, whatever the industry.

faq-domande-frequenti#lavorate-con-fashion-luxury

Do you specialize in the Manufacturing sector?

We have neither a vertical specialization in manufacturing nor a dedicated OT/ICS offering. What we bring to a manufacturing company is what we do for everyone: business continuity sized on the BIA, data protection, private cloud and 24×7×365 NOC coverage. If the scope includes industrial networks, it has to be assessed together on a case-by-case basis.

faq-domande-frequenti#siete-specializzati-manufacturing

What is your history with OpenStack?

Since 2010: the first Lympha project was an open source virtualization system based on OpenStack, in years when private cloud was still a gamble. That root has remained in today's approach: open standards, no lock-in to a proprietary stack.

faq-domande-frequenti#storia-con-openstack

Are you an SME or a large enterprise?

We are a structured SME: an organization of eight Business Units with integrated Competency Centers, formalized processes and a quality management system certified to ISO 9001:2015. Our size keeps us agile; our organization allows us to handle enterprise projects and public framework agreements.

faq-domande-frequenti#siete-pmi-o-grande-impresa

What does “LEI” mean in your footer?

The LEI (Legal Entity Identifier) is the unique international code that identifies legal entities in financial markets. It is an indicator of transparency and compliance, particularly relevant for customers in the finance sector.

faq-domande-frequenti#cosa-significa-lei

Do you have offices other than Bologna?

The registered office is in Bologna (Via Guglielmo Marconi, 32). The operational office is in Castel San Pietro Terme at Via Antonio Meucci 24/c, and the 00GATE Green Data Center is on the same street at number 24/i/2: they are two distinct addresses. We operate throughout Italy with the remote SPOC model and scheduled on-site interventions.

faq-domande-frequenti#avete-sedi-oltre-bologna

ITSM & Managed Services 33 questions

The day-to-day operational governance of systems: SPOC model, ITIL processes, CMDB/KMDB, measured SLAs and managed services.

Learn more: ITSM Service Lifecycle & Service Management Recruiting & Competence Centre

What is ITSM and why does it matter?

ITSM (Information Technology & System Management) is the day-to-day operational governance of systems: assets, recurring procedures, levels of responsibility and service quality. We structure management according to ITIL best practices.

faq-domande-frequenti#cos-e-itsm

What is the SPOC and how does it work?

SPOC = Single Point Of Contact: one single entry point for users and for the customer's IT department. Behind it, a front & back office Help Desk filters, classifies and routes every request to remote support or an on-site intervention, with no ping-pong.

faq-domande-frequenti#cos-e-spoc

What are KMDB and CMDB?

KMDB (Knowledge Management Database): a shared knowledge base that grows with every closed ticket. CMDB (Configuration Management Database): an always up-to-date map of assets (serial numbers, technical data sheets, configurations).

faq-domande-frequenti#cosa-sono-kmdb-cmdb

How do you manage incidents?

Every incident follows a formalized macro-process: report via phone/email/ticket → SPOC takes ownership → classification and CMDB/KMDB lookup → remote resolution or on-site queue with priority (VIP or standard) → ticket closure and update of the databases.

faq-domande-frequenti#come-gestite-incident

What are SLAs and how do you measure them?

SLA = Service Level Agreement: agreed and measured response and resolution times. Periodic reporting makes it possible to judge the service by the numbers, not by impressions.

faq-domande-frequenti#cosa-sono-sla

Can I delegate repetitive activities to your SPOC?

Yes. Recurring activities such as workstation incident management, new or replacement workstations, software installations and account management can all be delegated to our SPOC — each with a standard service catalog and traceable processes.

faq-domande-frequenti#delegare-attivita-spoc

What does the ITSM service include?

Asset and configuration inventory and management; incident, request and change management processes; governed recurring procedures (updates, checks, maintenance); reporting and agreed SLAs.

faq-domande-frequenti#cosa-comprende-itsm

Does your ITSM replace our IT department?

No. Our Competency Center integrates with your IT department: no replacement, but reinforcement. Policies and decisions remain with your IT manager.

faq-domande-frequenti#itsm-sostituisce-it-interno

What is FinOps and do you apply it?

FinOps is the discipline that governs cloud costs with visibility and accountability. We apply it in VDC GREEN (pay-per-use fee with no consumption thresholds) and we help customers optimize spending in hybrid environments.

faq-domande-frequenti#cos-e-finops

Do you also do DevOps?

Yes, where the project requires it: CI/CD pipelines, containerization and infrastructure automation, carried out within the customer's perimeter. VDC GREEN exposes REST APIs precisely so that it can be driven by these tools.

faq-domande-frequenti#fate-devops

What is your Agile approach?

We use agile methodologies in software development (AED) with iterative releases, continuous feedback and course correction. For infrastructure we apply Plan-Do-Check-Act (PDCA) cycles.

faq-domande-frequenti#approccio-agile

Do you manage the Service Catalog?

Yes. The standard service catalog is part of the SPOC model: every service (new workstation, replacement, installations) is described with defined SLAs, timeframes and responsibilities.

faq-domande-frequenti#gestite-service-catalog

Do you do Problem Management as well as Incident Management?

Yes. In addition to incident management, we perform Root Cause Analysis to prevent recurrences, enriching the KMDB with permanent workarounds.

faq-domande-frequenti#problem-management

How do you handle Change Requests?

Every change follows a formalized process: request → impact assessment → approval → scheduling → implementation → verification → documented closure.

faq-domande-frequenti#come-gestite-change-request

Do you provide Service Level Reporting?

Yes. Periodic reports (monthly/quarterly) with service KPIs: response times, first-contact resolution, availability, tickets opened/closed by category.

faq-domande-frequenti#service-level-reporting

Do you manage software assets and licenses?

Yes. The CMDB includes not only hardware but also software licenses, with expiry dates, renewals and optimization (e.g. identifying unused licenses).

faq-domande-frequenti#gestite-asset-licenze

Do you offer User Provisioning services?

Yes. The new workstation process includes account provisioning, permission assignment and software configuration according to the catalog, with a complete audit trail.

faq-domande-frequenti#user-provisioning

What does co-sourcing mean?

In co-sourcing, policies and decisions remain with your IT manager while we handle the repetitive operational activities. It is an intermediate model between insourcing and full outsourcing.

faq-domande-frequenti#co-sourcing

Do you manage Patch Management?

Yes. Operating system, middleware and application patches are scheduled, tested in a staging environment and released within agreed windows, with compliance reporting.

faq-domande-frequenti#patch-management

Do you have a proprietary ticketing tool?

We use open source ticketing, inventory and discovery tools, integrated with the CMDB and KMDB. It is a choice consistent with everything else: no licensing constraint on the system that holds the history of your service, and the option to take it with you.

faq-domande-frequenti#tool-ticketing

Do you support Mac workstations as well as Windows?

Yes. Our SPOC supports multi-platform environments: Windows, macOS and Linux, with specific procedures for each operating system.

faq-domande-frequenti#supportate-mac

How do you handle VIP queues?

Critical users (executives, key roles) have priority queues in the SPOC system, with shorter response SLAs and direct escalation.

faq-domande-frequenti#code-vip

Do you offer an onboarding service for new employees?

Yes, as a package in the SPOC catalog: account creation, hardware/software provisioning, basic training, integration with Active Directory and HR systems.

faq-domande-frequenti#onboarding-dipendenti

Do you handle workstation decommissioning?

Yes. The process includes: asset recovery, secure data erasure (wiping), CMDB update, and either reuse or certified WEEE disposal.

faq-domande-frequenti#decommissioning-postazioni

Do you do Capacity Planning?

Yes. We monitor usage trends to anticipate upgrade needs (storage, compute, network), integrating Capacity Planning with the DCMM.

faq-domande-frequenti#capacity-planning

How do you handle maintenance communications?

Scheduled notifications by email/ticket with advance notice, an agreed time window, and a post-intervention report verifying correct operation.

faq-domande-frequenti#comunicazione-maintenance

Do you offer IT Asset Management (ITAM) services?

Yes. Full ITAM with physical and logical inventory, lifecycle traceability, cost optimization, license compliance and management reporting.

faq-domande-frequenti#itam

Do you manage multi-tenant environments?

Yes, especially in VDC GREEN where each customer has their own isolated stack. Multi-tenant management is native to our OpenStack architecture.

faq-domande-frequenti#ambienti-multi-tenant

What is Service Portfolio Management?

It is the strategic governance of all IT services: which to activate, which to retire, which to invest in. We integrate it with IT Governance to align IT with the business.

faq-domande-frequenti#service-portfolio-management

How do you manage the Knowledge Base in a structured way?

The KMDB is a knowledge base organized into categorized articles (resolved incidents, workarounds, procedures), searchable by operators and end users.

faq-domande-frequenti#knowledge-base-strutturata

Do you offer Vendor Management services?

Yes. We can act as intermediaries towards other suppliers (ISPs, software vendors, third-party MSPs), coordinating SLAs, escalation and reporting.

faq-domande-frequenti#vendor-management

How do you measure Customer Satisfaction?

Through feedback at ticket closure and through periodic service reporting, which is the real yardstick: response and resolution times, first-contact resolution, availability. Review meetings with the customer are agreed in the service contract.

faq-domande-frequenti#customer-satisfaction

Do you also provide a 24/7 Service Desk?

The NOC operates 24×7×365 monitoring systems, networks and applications. The user-facing Service Desk, on the other hand, has hours defined in the contract, with evening or holiday extensions where needed: they are two distinct functions and must be sized separately.

faq-domande-frequenti#service-desk-24-7

Data Protection & Backup 27 questions

Backup, retention, restore testing and data protection: why having copies does not mean knowing how to get back up and running.

Learn more: Data Protection Business Continuity & DR

What is DPaaS?

DPaaS (Data Protection as a Service) is the managed backup service on a pay-per-use fee: costs always under control, no upfront investment. It opens the way to Disaster Recovery even for those without the budget for major projects.

faq-domande-frequenti#cos-e-dpaas

What are RPO and RTO?

They are the two metrics of business continuity: RPO (Recovery Point Objective) = how much data I can afford to lose; RTO (Recovery Time Objective) = how quickly I have to be back up. They are defined in the ISO 22300 vocabulary and used by ISO 22301 and ISO/IEC 27031. It is the Business Impact Analysis that sets their values, not the technology catalog.

faq-domande-frequenti#cosa-sono-rpo-rto

What is the RPO–RTO continuum?

Data protection is not a product but a position on a continuum. On the left, backup (low cost, recovery in days/hours); in the middle, Rapid Data Recovery (minutes/seconds); on the right, Continuous Availability (zero data loss, highest cost).

faq-domande-frequenti#continuum-rpo-rto

What are the backup tiers?

The seven-tier model (SHARE 1992, later IBM) describes how quickly you can be back up. The lower tiers live on the Core Site alone with backup and asynchronous replication: recovery in days or hours. The intermediate tiers add a DR site with synchronous replication and standby servers: minutes or seconds. The upper tiers are high availability between sites, targeting zero data loss.

faq-domande-frequenti#tier-backup

Is DPaaS GDPR-compliant?

Yes. Protection is consistent with the GDPR and with company policies, and data is held in a zero-emission data center in Italy.

faq-domande-frequenti#dpaas-gdpr

How much does DPaaS cost?

The fee is pay-per-use: costs always under control, no upfront investment (CAPEX). It is an operating cost (OPEX) sized by contract.

faq-domande-frequenti#costo-dpaas

How do you move from DPaaS to Disaster Recovery?

DPaaS is the gateway to disaster recovery. With our guided 5-phase path (Assessment/BIA → Target architecture → Security → Implementation/testing → Continuous improvement) you progress in a structured way.

faq-domande-frequenti#da-dpaas-a-dr

Why isn't backup enough?

Having copies does not mean knowing how to get back up. Four things make the difference: clear objectives (RTO and RPO), an impact analysis (BIA), real restore tests, and someone watching the jobs every day.

faq-domande-frequenti#perche-backup-non-basta

Which backup technologies do you use?

We choose technology based on the use case, not the price list: among our declared technology partners is Veeam for backup, replication and ransomware recovery, and we use open source solutions where they are the right answer. In every case the destination infrastructure is our data center and oversight is provided by the NOC.

faq-domande-frequenti#tecnologie-backup

What is Continuous Data Protection (CDP)?

CDP is a technique that captures every data change in real time, allowing restores to any point in time. It is useful for databases and highly transactional workloads.

faq-domande-frequenti#continuous-data-protection

What is Vault Backup?

Vault Backup is an immutable copy of data, protected against accidental deletion or ransomware, kept in an isolated (air-gapped) environment.

faq-domande-frequenti#vault-backup

Are your backups immutable?

Yes, on request we configure immutable retention (WORM) to protect against ransomware and internal tampering, in line with the 3-2-1-1-0 best practice.

faq-domande-frequenti#backup-immutabili

Do you follow the 3-2-1-1-0 rule?

Yes: 3 copies of the data, 2 different media, 1 offsite (in our DC), 1 offline/immutable, 0 errors thanks to periodic restore tests.

faq-domande-frequenti#regola-3-2-1-1-0

Do you manage backups of VMware environments?

Yes, with technologies specific to VMware virtualization (vSphere, vCloud Director), VM-level backup, file-level restore and instant recovery.

faq-domande-frequenti#backup-vmware

Do you back up structured databases?

Yes: SQL Server, PostgreSQL, Oracle and MySQL with application-aware backup, guaranteed consistency and point-in-time recovery.

faq-domande-frequenti#backup-database

Do you manage Microsoft 365 backups?

Yes. Backup of Exchange email, SharePoint, OneDrive and Teams with configurable retention and granular restore, because Microsoft guarantees the service but not the user data.

faq-domande-frequenti#backup-microsoft-365

Do you back up Kubernetes environments?

Containerized workloads can be protected like any other, but you have to decide what the data really is: the persistent volumes and the configurations, not the containers, which by definition are re-created. It is an assessment to be made within the project, together with whoever runs the cluster.

faq-domande-frequenti#backup-kubernetes

Do you manage file server and NAS backups?

Yes, with deduplication, compression and replication towards our Green DC for maximum efficiency in cost and space.

faq-domande-frequenti#backup-file-server-nas

Do you offer Backup as a Service (BaaS)?

Yes, it is part of DPaaS: pay-per-use fee, infrastructure included, NOC monitoring and periodic restore tests.

faq-domande-frequenti#baas

What is the typical retention period?

There is no “typical” retention: it is defined in the contract, starting from the regulatory obligations of the sector and the outcomes of the BIA. A recurring scheme alternates short-term daily copies, medium-term weekly and monthly copies, and annual copies where retention is required by law — but that is a starting point, not a price list.

faq-domande-frequenti#retention-tipica

Does backup data stay in Italy?

Yes, all backups are hosted in the 00GATE Data Center in Castel San Pietro Terme (BO), never abroad.

faq-domande-frequenti#backup-in-italia

How do you protect backups from ransomware?

With immutability, logical air-gap, network segmentation, anomaly monitoring, multi-factor authentication and verified restore tests.

faq-domande-frequenti#protezione-backup-ransomware

What is a Backup Service Level Agreement?

A specific SLA that defines: backup frequency, retention, RPO, restore times, reporting and periodic tests.

faq-domande-frequenti#backup-sla

Do you manage backups of public cloud IaaS environments?

Yes, workloads on AWS/Azure/GCP can also be backed up to our DC for data sovereignty and protection against lock-in.

faq-domande-frequenti#backup-cloud-pubblici

Do you perform geographic replication of backups?

Yes, configurable between the Core Site and the DR site, synchronous or asynchronous depending on the target RPO.

faq-domande-frequenti#replica-geografica

How do you monitor backup jobs?

The NOC monitors all jobs 24/7, with automatic alerts on failures, reporting and proactive intervention.

faq-domande-frequenti#monitoraggio-job-backup

Are backups encrypted?

Yes, end-to-end AES-256 encryption both in transit and at rest, with keys managed according to the customer's policy.

faq-domande-frequenti#backup-crittografati

Business Continuity & DR 25 questions

Business Impact Analysis, RTO and RPO per service, continuity plans and disaster recovery put to the test.

Learn more: Business Continuity & DR Data Protection

What is the difference between Business Continuity and Disaster Recovery?

Disaster Recovery is what separates a managed incident from a business standstill. Business Continuity is the level above: systems that never stop (Continuous Availability, zero data loss), typically in a tri-data center architecture.

faq-domande-frequenti#differenza-bc-dr

What is a Business Impact Analysis (BIA)?

The BIA is the analysis that lists business processes, measures what happens if each one stops, and defines RTO and RPO by criticality level. It is the BIA that sets recovery objectives, not the technology catalog.

faq-domande-frequenti#business-impact-analysis

What is a Disaster Recovery Plan (DRP)?

The DRP is the structured plan describing how to reactivate critical services after a disastrous event, with a feasibility study, market comparison, subsystem design, implementation and periodic testing.

faq-domande-frequenti#disaster-recovery-plan

Why must a DR plan be tested?

An untested plan is not a plan. A business outage is not the right moment to discover that the backup does not work or that the procedures are incomplete. Tests with measured timings are an integral part of the service.

faq-domande-frequenti#piano-dr-testato

What are the reference standards for continuity?

ISO 22301 (business continuity), ISO/IEC 27031 (the bridge between continuity and information security), ISO/IEC 27001 (control 5.30 in the 2022 version: planned and tested ICT readiness).

faq-domande-frequenti#normativa-continuita

For which sectors is DR most important?

For organizations with critical services: healthcare, local public administration, manufacturing, finance — and anyone who has calculated what an hour of downtime costs.

faq-domande-frequenti#settori-dr

Does DR integrate with other services?

Yes. Integration with Data Protection and the NOC is natural: whoever does the monitoring also knows how to bring things back up. The whole program follows the Plan-Do-Check-Act cycle.

faq-domande-frequenti#integrazione-dr

What is process resilience?

It is the shift of the objective from the system to the process: not “how long does it take me to switch the server back on”, but “the process keeps running while the incident is under way”. It requires active-active multi-site architectures and it is the top band of the continuum, the one our scheme calls continuous availability.

faq-domande-frequenti#continuous-process-resilience

Do you offer Disaster Recovery as a Service (DRaaS)?

Yes: recovery infrastructure in our data center, documented failover and failback procedures, and periodic tests with measured timings. RTO and RPO objectives are not a price list: they are derived from the Business Impact Analysis and written into the service contract, where they become verifiable commitments.

faq-domande-frequenti#draas

How much does DRaaS cost compared to a traditional project?

There is no percentage that holds for everyone: it depends on the required RTO and RPO, on data volume and on how much has to be replicated. The structural advantage of DRaaS lies elsewhere: the pay-per-use model turns an upfront investment (CAPEX) into a recurring fee (OPEX) and makes disaster recovery reachable even for those who could not afford a second site. Sizing always starts from the BIA.

faq-domande-frequenti#costo-draas

Do you run Disaster Recovery tests?

Yes, mandatory periodic tests: tabletop (simulation), partial failover and full failover, with reports and remediation.

faq-domande-frequenti#test-dr

What is your minimum guaranteed RTO?

RTO is not chosen from a price list: it is derived from the Business Impact Analysis and then you buy the architecture that can sustain it. Along the continuum you go from backup (recovery in hours or days) to rapid data recovery (minutes) up to continuous availability (uninterrupted). The guaranteed value is written into the service contract after the assessment, and it must be demonstrated with timed tests.

faq-domande-frequenti#rto-minimo

What is your minimum guaranteed RPO?

It depends on the chosen architecture: with synchronous replication the objective is zero data loss, with asynchronous replication it is measured in minutes, with periodic backup alone it is measured by the interval between two copies. Which one is sustainable for you is established by the BIA, which relates the data lost to the damage it causes.

faq-domande-frequenti#rpo-minimo

Do you support automatic failover?

Yes, for workloads with aggressive RTO requirements. Failover is orchestrated by monitoring and orchestration systems.

faq-domande-frequenti#failover-automatico

What is failback and how do you manage it?

Failback is the return to the primary environment after an incident. We manage it with documented procedures, data synchronization and consistency testing.

faq-domande-frequenti#failback

Does DR also work for hybrid cloud environments?

Yes. Hybrid architectures (on-prem + VDC + public cloud) with DR orchestrated across all environments.

faq-domande-frequenti#dr-cloud-ibridi

How do you integrate DR and Cybersecurity?

DR plans include cyber-attack recovery scenarios (ransomware, data breach), with restores from immutable backups and remediation procedures.

faq-domande-frequenti#dr-cybersecurity

Do you offer Business Continuity Planning as well as the DR plan?

Our contribution stops where IT stops, and it is worth saying so: BIA, RTO and RPO objectives per process, continuity architectures, timed tests and incident management. A complete business continuity plan also covers people, logistics and non-IT suppliers: those areas remain with the organization or its consultants.

faq-domande-frequenti#bcp-oltre-drp

What is crisis management in a continuity plan?

It is the part concerning people and communications during a serious event: who informs whom, within what timeframes, towards which parties. It is not a service we deliver. What we do provide is the technical precondition: traced escalations, system status known at all times and measured recovery times, so that whoever is communicating knows what they are saying.

faq-domande-frequenti#crisis-management

Do you assess supply chain risk?

Within the IT perimeter, yes, and it is part of the continuity reasoning: which suppliers a critical service depends on, what happens if one of them stops, what alternatives exist. Supply risk assessment across the entire corporate chain is a broader exercise, and it falls to the organization.

faq-domande-frequenti#supply-chain-risk

How do you manage continuity in pandemic or geopolitical scenarios?

With continuity plans that also cover people and not just systems: remote work for the functions that allow it, NOC coverage that does not depend on a single location, documented operating procedures so that whoever is on shift knows what to do. Specific scenarios are defined in the BCP together with the customer.

faq-domande-frequenti#continuita-pandemica

Do you support multi-cloud environments in DR?

Yes. DR involving workloads on AWS, Azure, GCP and our VDC, with centralized orchestration.

faq-domande-frequenti#dr-multi-cloud

What is a DR runbook?

An operational, step-by-step document describing how to activate DR: who does what, in what order, with which tools and checks.

faq-domande-frequenti#runbook-dr

How often do you update DR plans?

At least annually, or whenever there are significant changes (new systems, M&A, regulatory changes).

faq-domande-frequenti#aggiornamento-piani-dr

Are DR tests included in the fee?

Planned tests are part of the service and are agreed in the contract: an untested continuity plan is not a plan. Additional or unscheduled sessions are quoted separately.

faq-domande-frequenti#test-dr-canone

Cybersecurity 25 questions

Assessments, penetration tests (including on AI bots and agents), incident response and identity protection.

Learn more: Cybersecurity NOC & Monitoring

What does the Cybersecurity service include?

Vulnerability Assessment & Penetration Test with customized reporting; web application security; reverse engineering and code review; log management, data analysis and correlation; Identity Management & Access Control; incident response (malware, data breach).

faq-domande-frequenti#cosa-comprende-cybersecurity

What is a Configuration & Architecture Review?

It is the first level of analysis: we verify that the main components are configured according to vendor best practices and industry standards, with attention to segregation (SAFE), the permission model (principle of least privilege) and core functionality.

faq-domande-frequenti#configuration-architecture-review

Do you run Penetration Tests on networks and applications?

Yes. The Network Penetration Test assesses the reachability and exposure of critical components: mapping of exposed ports and services, known vulnerabilities, segmentation and firewall policies. We approach it from a dual point of view — cyber and systems/infrastructure.

faq-domande-frequenti#network-penetration-test

What is an LLM Penetration Test?

It is a test specific to scenarios in which bots and AI agents interface with PAM systems. We verify whether they can be manipulated through prompt injection, jailbreaking or abuse of authorization flows in order to obtain unauthorized access.

faq-domande-frequenti#llm-penetration-test

Do you perform SSO & Identity Integration Reviews?

Yes. If the platform is integrated with SSO (SAML 2.0, OIDC, AD/LDAP), we verify its implementation: validation of authentication flows, session management and robustness of the trust chain.

faq-domande-frequenti#sso-identity-integration-review

How do you handle security incidents?

Management of malware and data breaches with analysis of the entry vector and remote connections; remediation of the information system and fixing of the exploited vulnerability; intervention with custom SLAs, including within 24 hours of the call.

faq-domande-frequenti#gestione-incidenti-sicurezza

What is Web Application Firewall as a Service?

It is a WAF delivered as a managed service, protecting web applications from attacks such as SQL injection, XSS and other OWASP threats, without requiring dedicated hardware.

faq-domande-frequenti#waf-as-service

How are test findings classified?

At the end of the activities we produce a detailed report with findings classified by risk level — critical, high, medium, low — and practical remediation guidance for each finding.

faq-domande-frequenti#classificazione-findings

Is Cybersecurity important for public administration?

Yes. The ACN guidance on cloud for public administration and the NIS2 directive require data sovereignty and localization, as well as adequate security measures. Our private cloud is a dedicated perimeter, in Italy.

faq-domande-frequenti#cybersecurity-pa

What is a SOC and do you have one?

A SOC (Security Operation Center) is the structure that continuously monitors, detects and responds to security incidents. What Lympha has is the NOC — Network & Security Operations Center — active 24×7×365 monitoring systems, networks and applications, with escalation and incident management procedures. Offensive analysis activities (assessments and penetration tests) are delivered as projects by the SEC Business Unit, not as continuous coverage.

faq-domande-frequenti#cos-e-soc

What is Threat Hunting?

It is the proactive search for threats already present in an infrastructure, instead of waiting for an alert. We do not deliver it as a continuous service: our scope is commissioned assessments and penetration tests, incident management and NOC coverage. Where a continuous hunting capability is needed, it has to be built with you as a dedicated project.

faq-domande-frequenti#threat-hunting

What is a Purple Team?

It is the joint work of those who attack (Red Team) and those who defend (Blue Team), designed so that every simulation produces a measurable defensive improvement rather than just a report card. Our typical contribution is on the analytical side: penetration tests, Configuration & Architecture Review and a remediation plan with findings ranked by risk.

faq-domande-frequenti#purple-team

What is Red Teaming?

It is the realistic simulation of an advanced attacker attempting to compromise an organization using several vectors at once: phishing, social engineering, exploits, lateral movement. It is a different exercise from the perimeter penetration test we deliver, which has an objective and a scope agreed in advance.

faq-domande-frequenti#red-teaming

What is Cyber Threat Intelligence (CTI)?

It is the collection and analysis of information on actors, techniques and indicators of compromise, used to anticipate attacks instead of suffering them. We do not deliver it as a subscription service: public intelligence sources feed our assessment work and vulnerability management.

faq-domande-frequenti#cyber-threat-intelligence

What is PAM (Privileged Access Management)?

PAM (Privileged Access Management) is the platform that holds and controls privileged accounts: credentials in a vault, session recording, access granted only when needed, approval flows. It is the perimeter on which our security assessment is built: whoever controls the PAM holds the keys to the kingdom, and it must be verified that only those who should are using them.

faq-domande-frequenti#pam

What is Message Hardening?

Hardening of messaging systems (email, chat) with protection against phishing and spoofing (SPF, DKIM, DMARC) and end-to-end encryption.

faq-domande-frequenti#message-hardening

What is Cloud Native Security?

It is security designed for container environments: image scanning, runtime protection, policy enforcement, zero-trust networking between services. We deal with it when the perimeter being assessed includes them, within configuration and architecture assessments.

faq-domande-frequenti#cloud-native-security

What is SecOps?

Integration between Security and Operations teams for faster incident response, playbook automation and reduced remediation times.

faq-domande-frequenti#secops

What is a Zero Trust Architecture?

A security model that trusts nothing by default: continuous verification of identity, device and context for every access to resources.

faq-domande-frequenti#zero-trust-architecture

Do you implement Zero Trust?

Zero trust principles — continuous identity verification, least privilege, segmentation — are the ones we use to assess architectures in our reviews, particularly in the Configuration & Architecture Review and the SSO & Identity Integration Review. A complete zero trust program, however, is a multi-year journey for the organization, not a product you install.

faq-domande-frequenti#implementate-zero-trust

What is EDR/XDR?

EDR (Endpoint Detection & Response) watches endpoints and records their suspicious behavior; XDR extends the same logic to network, cloud and identity. These are technologies we find installed at customer sites and whose configuration and effectiveness we verify during assessments; their ongoing management is evaluated case by case.

faq-domande-frequenti#edr-xdr

What is a Vulnerability Management Program?

A structured program of scanning, prioritization and remediation of vulnerabilities, with KPIs and continuous reporting.

faq-domande-frequenti#vulnerability-management-program

What is Adversary Emulation?

It is the reproduction of the tactics and techniques of a specific attacker, catalogued in frameworks such as MITRE ATT&CK, to verify whether defenses hold up against precisely those. It is a specialist practice that does not appear in our catalog: our scope is penetration testing on networks, applications and — this one is a specificity — LLM-based agents and bots.

faq-domande-frequenti#adversary-emulation

Do you perform assessments on AI/LLM?

Yes: the LLM Penetration Test verifies whether bots and agents based on language models can be manipulated with prompt injection, jailbreaking or abuse of authorization flows, to the point of obtaining unintended access. It is where our work on AI and our work on security meet: we build these systems, so we know where to look.

faq-domande-frequenti#assessment-ai-llm

How do you handle cyber emergencies?

Intervention SLA within 24 hours, dedicated team, containment, eradication and recovery procedures, lessons learned.

faq-domande-frequenti#emergenze-cyber

Private Cloud & VDC 31 questions

The VDC GREEN Virtual Data Center: pay-per-use with no consumption thresholds, per-tenant isolation, data in Italy, 99.98% continuity.

Learn more: Hybrid/Private Cloud & VDC Server Farm & Data Centre Design

What is VDC GREEN?

VDC GREEN is our Virtual Data Center service: dedicated virtual environments (computing, storage and network), isolated and scalable, hosted in our 00GATE Green Data Center. Every resource (vCPU, vRAM, storage, network) scales independently.

faq-domande-frequenti#cos-e-vdc-green

How private is your Private Cloud really?

Every VDC lives on an isolated infrastructure stack: what is inside your perimeter is yours, including VLANs and virtual networks with fine-grained control over firewall rules. In the public cloud, some elements remain logically shared between customers.

faq-domande-frequenti#quanto-e-privato-vdc

What is the difference between on-premise and VDC GREEN?

On-premise: CAPEX licenses, limited scalability, maintenance on internal IT. VDC GREEN: OPEX fee, scalability in minutes, managed maintenance, security included, DR ready. The difference is tangible in total costs and agility.

faq-domande-frequenti#differenza-onprem-vdc

How much does VDC GREEN cost?

A pre-agreed monthly pay-per-use fee, with no consumption thresholds on any resource (vCPU, vRAM, storage, bandwidth). Software licenses also follow consumption, and the fee adjusts downwards if users or resources are reduced.

faq-domande-frequenti#costo-vdc

What technology is the VDC based on?

Virtualization runs on established, open technologies — our root is OpenStack, since 2010. The platform is accessible from a single web console and through REST APIs for DevOps automation.

faq-domande-frequenti#tecnologia-vdc

Is the 00GATE Data Center certified?

Yes. It is Green certified by Accredia® (the Italian national accreditation body). Certification for hosted services is free of charge for the customer and published in the Green Cloud Consortium register, verifiable by anyone.

faq-domande-frequenti#certificazione-green

What continuity does the data center guarantee?

Tier III configuration with guaranteed operational continuity of 99.98% (a maximum of 1.6 hours of downtime per year).

faq-domande-frequenti#continuita-data-center

Can I use my own firewall with the VDC?

Yes. The data center has a housing area with protected racks where you can install your own appliances, or we can install them for you. The logical connection to the VDC is handled by technical support.

faq-domande-frequenti#firewall-proprio-vdc

Does data stay in Italy?

Yes. Data remains exclusively in Italy, in our 00GATE Data Center in Castel San Pietro Terme.

faq-domande-frequenti#dati-in-italia

Can I use the Green certification as a commercial argument?

Yes. If the services you deliver to your customers run in your VDC, they can obtain a certificate derived from yours and display the sustainable hosting badge on their own websites.

faq-domande-frequenti#certificazione-green-clienti

Do you use VMware in the VDC?

VDC GREEN is based on OpenStack. If you have already made VMware investments, the first point to clarify is the cost of the licenses and their portability: it is an assessment we make together, without assuming that the best route is to replicate what already exists.

faq-domande-frequenti#vmware-vdc

Do you support Proxmox?

VDC GREEN is based on OpenStack, which has been our technological root since 2010. Environments built on other hypervisors are evaluated as projects: the right question is not which hypervisor you prefer, but who takes on the operation of that stack and with what service levels.

faq-domande-frequenti#proxmox-support

What is Hyperconvergence?

Hyperconvergence integrates compute, storage and network into a single software-defined platform, reducing the number of components to manage separately. It is an architecture we consider when designing infrastructures for customers; our VDC GREEN, by contrast, follows a different route, with resources that scale independently of one another.

faq-domande-frequenti#hyperconvergence

Do you offer managed Kubernetes?

Not as a catalog service with published SLAs. VDC GREEN provides the resources and the APIs on which to run a cluster, and the NOC can take on its monitoring within a management contract: the level — from ticket-only to full management — is chosen and can be changed over time.

faq-domande-frequenti#kubernetes-gestito

Do you support Red Hat OpenShift?

It is not a platform we deliver from our catalog. VDC GREEN provides the resources (computing, storage, network) and the REST APIs on which an organization can bring its own application platform; if the project involves OpenShift, we need to assess together what remains your responsibility and what becomes ours.

faq-domande-frequenti#openshift

Do you offer dedicated physical servers (bare metal)?

The data center has a housing area with protected racks to host customer-owned hardware — useful for workloads tied to hardware licensing or to particular performance requirements. It is a colocation service with the logical connection to the VDC managed by our technical support, not a bare-metal-as-a-service catalog.

faq-domande-frequenti#bare-metal

Do you offer managed databases?

Within the VDC we can deliver databases with backup, monitoring and updates taken on by the NOC, according to the agreed management level. PostgreSQL is also the foundation on which our RAG platform runs. The scope of the service — and who is answerable for what — is defined in the contract.

faq-domande-frequenti#dbaas

Do you handle Cloud Migration?

Yes. Assessment, planning, execution and validation of migrations from on-premise or other clouds towards our VDC GREEN.

faq-domande-frequenti#cloud-migration

What is Colocation?

Dedicated rack space in our DC for customer-owned hardware. Power, cooling, connectivity and physical security included.

faq-domande-frequenti#colocation

Do you support Docker containerization?

Yes. Docker runtime, private registries, K8s orchestration, monitoring and container backup.

faq-domande-frequenti#containerizzazione-docker

What is S3-compatible Object Storage?

Scalable storage with S3-compatible APIs, ideal for backups, archives, data lakes and media.

faq-domande-frequenti#object-storage-s3

What network connectivity does the VDC have?

Guaranteed bandwidth, multihoming across 2 carriers, redundant fiber connectivity on a dual ring, peering with the main IXs.

faq-domande-frequenti#connettivita-vdc

Can I physically see my servers?

Yes, visits to the 00GATE DC are always welcome. By appointment and subject to security procedures.

faq-domande-frequenti#visitare-data-center

What is sovereign cloud?

It is the idea that data and operations remain under the jurisdiction of a country. It needs to be read carefully, though: a data center in Europe owned by someone else does not make your data sovereign — what counts is ownership, control and the ability to leave. In our case data remains in Italy, in a data center we can take you to visit, and the stack is open: the way out exists.

faq-domande-frequenti#sovereign-cloud

Do you support Windows Server environments?

Yes. Windows Server environments can run in the VDC, with licenses either provided within the fee or brought by you. The pay-per-use principle applies: licenses too follow consumption, and the fee adjusts if the number of users falls.

faq-domande-frequenti#windows-server

Do you provide managed load balancing?

Yes, as an architectural component within the VDC: traffic distribution across instances, TLS termination and health checks, sized on the service to be published. Oversight is provided by the NOC according to the agreed management level.

faq-domande-frequenti#load-balancing

Do you offer staging/development environments?

Yes. Isolated environments for testing, development and QA, with the option to clone production, at reduced cost.

faq-domande-frequenti#ambienti-staging

How does resource scaling work?

Every VDC GREEN resource (vCPU, vRAM, storage, network) scales independently of the others, in minutes and with no consumption thresholds: the fee follows usage, including downwards if you reduce users or resources. Metric-driven auto-scaling policies are set up on top of the REST APIs, as part of the project.

faq-domande-frequenti#auto-scaling

Do you support REST APIs for automation?

Yes. Complete APIs for provisioning, management and monitoring, integrable with CI/CD pipelines and IaC (Terraform, Ansible).

faq-domande-frequenti#api-rest-automazione

What is the difference between IaaS, PaaS and SaaS in your case?

IaaS is VDC GREEN: virtual resources that you manage. PaaS covers the services we take on above those resources (databases, application environments), according to the chosen management level. SaaS covers our products — ACME ECMS and the ACME ECMS IA & RAG Integration platform. In all cases the infrastructure is the same and data remains in Italy.

faq-domande-frequenti#iaas-paas-saas

NOC & Monitoring 19 questions

24×7×365 coverage, proactive monitoring and scheduled activities: backups, patching and logs under control.

Learn more: NOC & Monitoring ITSM

What is the NOC?

The NOC (Network & Security Operations Center) is our operations center, which handles the monitoring of servers, networks and applications 24×7×365, acting proactively to resolve problems and ensure service continuity.

faq-domande-frequenti#cos-e-noc

Is the NOC active 24 hours a day?

Yes. Coverage is continuous and proactive, 24×7×365, with immediate escalation procedures for unpredictable events (power failure, cut fiber).

faq-domande-frequenti#noc-24-ore

What does the NOC monitor?

Servers, networks and applications, actively and proactively; IP network operation; scheduled activities (backup verification, patching, log checks); compliance with ITIL best practices in incident management.

faq-domande-frequenti#cosa-monitora-noc

How does escalation work?

For unpredictable events, immediate escalation procedures towards the responsible technicians are in place, with full tracking through to resolution.

faq-domande-frequenti#escalation-noc

Does the NOC integrate with ITSM?

Yes. When coverage also extends to workstations and user support, the NOC works in tandem with the SPOC/Help Desk model: a single point of contact, prioritized queues, shared KMDB/CMDB.

faq-domande-frequenti#noc-itsm

Can I delegate scheduled activities to the NOC?

Yes. Repetitive scheduled activities such as backup verification, patching and log checks can be delegated to the NOC, with customizable standard procedures.

faq-domande-frequenti#delegare-attivita-noc

How do you choose the VDC management level with the NOC?

You choose the level and can change it over time: from a simple ticket when needed, to co-sourcing of virtual servers with the NOC proactive day and night, up to full management.

faq-domande-frequenti#livelli-gestione-vdc-noc

What is Application Performance Monitoring (APM)?

Monitoring of application performance: response times, throughput, errors and distributed tracing to identify bottlenecks.

faq-domande-frequenti#apm

What is synthetic monitoring?

Proactive monitoring through scripts that simulate real users: availability, performance and key functionality checks.

faq-domande-frequenti#synthetic-monitoring

Do you monitor databases?

Yes. Query performance, connection pools, replication lag, deadlocks and capacity, with proactive alerting.

faq-domande-frequenti#monitoraggio-database

Do you support centralized log management?

Yes. Log collection, indexing and alerting are among the scheduled activities that can be delegated to the NOC, alongside backup verification and patching. The choice of stack is made case by case: where possible we favor open source components, so as not to tie the history of your logs to a license.

faq-domande-frequenti#log-management-centralizzato

What is observability?

An evolution of monitoring: a combination of metrics, logs and tracing to understand the internal state of complex systems (microservices, K8s).

faq-domande-frequenti#observability

Do you offer observability as a service?

The observability of a system is designed together with the system, it is not added afterwards: where the project provides for it, we implement the instrumentation and the NOC takes on continuous oversight. It is not an off-the-shelf package with a predefined stack.

faq-domande-frequenti#observability-servizio

Do you monitor SD-WAN networks?

Monitoring the operation of IP networks is part of the NOC service. On specific SD-WAN architectures, the scope of visibility depends on the vendor's platform and has to be verified during the assessment phase: the NET Business Unit handles networking and perimeter security.

faq-domande-frequenti#monitoraggio-sd-wan

Do you perform capacity monitoring?

Yes. Trend analysis to anticipate resource exhaustion (storage, CPU, RAM, bandwidth) with proactive planning.

faq-domande-frequenti#capacity-monitoring

Do you monitor containers and Kubernetes?

The NOC monitors systems, networks and applications: where the agreed perimeter includes a cluster, we monitor its availability and resources according to the chosen management level. Specific instrumentation has to be agreed with whoever manages the cluster.

faq-domande-frequenti#monitoraggio-kubernetes

Do you support monitoring of IoT environments?

It is not an area we cover with dedicated skills. The NOC monitors systems, networks and applications 24×7×365: if a project includes peripheral devices, we need to assess together what is actually observable and with what thresholds.

faq-domande-frequenti#monitoraggio-iot

What is DCIM and do you use it?

DCIM (Data Center Infrastructure Management) is the monitoring of the data center's physical infrastructure: power, cooling, rack space and environmental conditions. It is a component of the Zero Emission Data Centers we design for customers, where it serves to keep consumption and efficiency under control.

faq-domande-frequenti#dcim

Are NOC reports customizable?

Yes. Custom dashboards and reports for different stakeholders: technical, managerial, executive, compliance.

faq-domande-frequenti#report-noc-custom

AI, Agents and RAG 37 questions

On-premise RAG architectures and AI agents: models connected to corporate data, with verifiable sources and inside the customer's perimeter.

Learn more: IA, Agenti e RAG Development

What is a RAG architecture?

RAG (Retrieval-Augmented Generation) connects language models to a company's real data — documents, knowledge bases, management systems — so that answers are relevant, up to date and verifiable, with references to the sources.

faq-domande-frequenti#cos-e-rag

What are agents in AI?

With agents we take the next step: AI does not just answer, it performs activities — it queries systems, prepares documents, triggers workflows — within rules and permissions defined by the customer.

faq-domande-frequenti#cosa-sono-agenti-ia

What is your RAG platform?

Our on-premise RAG platform is called ACME ECMS IA & RAG Integration (Private, Simple & Fast RAG). It is a fully containerized stack, running on dedicated GPUs in an isolated private network.

faq-domande-frequenti#piattaforma-rag-lympha

Does data leave the corporate perimeter?

No. All components are open source, models are interchangeable (Mistral, Gemma, Qwen…), there are no calls to external services, no data leaves the perimeter, and there is no vendor lock-in.

faq-domande-frequenti#dati-non-escono

Why does RAG often not work?

When a document assistant answers badly, the problem is almost always in retrieval, not in the model. The search that decides which documents the model reads has to be measured, before spending money. We use hybrid retrieval (vector index + knowledge graph).

faq-domande-frequenti#perche-rag-non-funziona

What is the knowledge graph in RAG?

In addition to the vector index, LightRAG builds a graph of entities and relations (Apache AGE on PostgreSQL): answers connect facts, rather than merely resembling the question.

faq-domande-frequenti#knowledge-graph-rag

Which language models do you support?

Models are interchangeable: Mistral, Gemma, Qwen and others run through Ollama for LLMs and embeddings, and vLLM for re-ranking. No dependency on a single vendor.

faq-domande-frequenti#modelli-linguistici-supportati

How do you measure RAG quality?

We use RAGAS, a tool that generates sets of test questions from your own documents and evaluates the answers with metrics in Italian. Quality is measured, not declared.

faq-domande-frequenti#misura-qualita-rag

What do off-grid distilled models mean?

It means processing documents without them leaving the corporate perimeter. The question customers ask has changed: no longer “can we use generative AI?” but “can we process these documents without them leaving our perimeter?”. The answer is yes.

faq-domande-frequenti#modelli-distillati-off-grid

What are the typical use cases for on-premise RAG?

Intelligent document search: querying archives, resolutions and manuals with the source cited; internal assistants on the corporate knowledge base; analysis and preparation of documents; agents within processes: repetitive activities carried out by AI inside workflows.

faq-domande-frequenti#casi-uso-rag

What is Sovereign AI?

It is AI that remains under the control of whoever uses it: models, data and infrastructure inside a defined perimeter. Our RAG platform meets this requirement in the most direct way possible — it runs on-premise on dedicated GPUs in an isolated network, the components are open source, the models are interchangeable and no call goes out to external services.

faq-domande-frequenti#sovereign-ai

What is Agentic AI?

It is AI that does not merely answer but acts: it queries systems, prepares documents and triggers workflows, always within rules and permissions defined by the customer. It is exactly what we do with agents in document and approval processes.

faq-domande-frequenti#industrial-agentic-ai

Do you offer AI for manufacturing?

We do not have a vertical offering for manufacturing: predictive maintenance and visual quality control require domain expertise and process data that are not our trade. What we bring is the infrastructure to run it in-house — dedicated GPUs, isolated network, data that does not leave — and RAG and agent architectures on corporate documents.

faq-domande-frequenti#ai-manufacturing

What is an Agentic Workflow?

A workflow in which autonomous AI agents carry out complex tasks with planning, execution, validation and interaction with systems.

faq-domande-frequenti#agentic-workflow

What is Confidential Computing?

It is the processing of data inside processor-level encrypted enclaves, so that not even whoever manages the infrastructure can read it. It is not a technology we employ: the problem it solves — having sensitive data processed without exposing it to third parties — we address upstream, by keeping processing inside the customer's perimeter.

faq-domande-frequenti#confidential-computing

Do you do AI Observability?

The quality of a RAG system has to be kept under observation over time, not measured once at acceptance: with RAGAS we generate sets of test questions from your own documents and re-evaluate the answers at every significant change. Behavioral drift and degradation show up that way.

faq-domande-frequenti#ai-observability

What is hybrid vector+graph RAG?

A combination of similarity search (vectors) and knowledge graph (entities + relations) for more precise retrieval. It is our LightRAG architecture.

faq-domande-frequenti#rag-ibrido

Do you support Mistral AI?

Yes. Mistral is one of the models that can run on the platform, alongside Gemma, Qwen and others: they are interchangeable by architectural choice, so the choice of model remains reversible and does not become a constraint.

faq-domande-frequenti#supportate-mistral

Do you support Gemma models (Google)?

Yes. Gemma is supported as an open source alternative for specific workloads.

faq-domande-frequenti#supportate-gemma

Do you support Qwen (Alibaba)?

Yes. The Qwen family is available for multilingual scenarios or specific performance requirements.

faq-domande-frequenti#supportate-qwen

Do you support Llama (Meta)?

Yes. Llama is among the models that can run on-premise on the platform. The selection criterion is not the model's name but its usage license, its handling of Italian and its measured behavior on your documents.

faq-domande-frequenti#supportate-llama

Do you fine-tune models?

In most cases it is not necessary, and it is a point we insist on: when a document assistant answers badly, the problem is almost always in retrieval, not in the model. First you measure retrieval quality (we use RAGAS on an Italian test set), then you assess whether working on the model really adds anything.

faq-domande-frequenti#fine-tuning-modelli

What is Retrieval Re-ranking?

A technique that reorders retrieved documents by relevance before passing them to the LLM. We use vLLM for dedicated re-ranking.

faq-domande-frequenti#retrieval-re-ranking

What is an AI Guardrail?

Guardrails are the controls on what goes into and out of an AI system: filters against circumvention attempts, protection of personal data, verification that the answer stays anchored to the sources. In our architecture the first guardrail is structural: the model answers by citing the documents it drew on, so the statement is verifiable.

faq-domande-frequenti#ai-guardrail

What is MLOps?

It is the application of DevOps practices to models: versioning, release, monitoring, retraining. In our platform, the part that really counts is the continuous measurement of quality: at every configuration change the system is re-evaluated with RAGAS, because quality is measured, not declared.

faq-domande-frequenti#mlops

What is Edge AI?

AI executed on edge devices (IoT, edge servers) rather than in the cloud, for low latency and privacy.

faq-domande-frequenti#edge-ai

Do you do Edge AI?

It is not an area we cover. Our approach is the opposite, and deliberately so: concentrating processing on dedicated GPUs inside the corporate perimeter, where data remains governable, rather than distributing it across peripheral devices.

faq-domande-frequenti#fate-edge-ai

What is Model Distillation?

It is the technique by which a small model is trained to replicate the behavior of a large one, reducing the cost of running it. It is what makes “off-grid” AI practicable: models compact enough to run on dedicated GPUs on your premises, without documents having to leave in order to be processed.

faq-domande-frequenti#model-distillation

What is an Embedding?

A vector representation of text or images in a multidimensional space. The basis of retrieval in RAG.

faq-domande-frequenti#embedding

Which embedding models do you use?

Open source models such as Nomic, BGE and E5, run on-premise via Ollama.

faq-domande-frequenti#modelli-embedding

What is a Vector Database?

A database optimized for similarity search over vectors. We use pgvector (a PostgreSQL extension).

faq-domande-frequenti#vector-database

What is a Knowledge Graph?

A representation of entities and relations. We use Apache AGE on PostgreSQL for enriched RAG.

faq-domande-frequenti#knowledge-graph

Do you support multimodal AI?

Yes, within the customer's perimeter: the platform includes on-premise image generation (ComfyUI with FLUX/SDXL) alongside the language models, and the processing of documents containing both text and images. The same rule applies as everywhere else: nothing leaves the isolated network.

faq-domande-frequenti#ai-multimodale

Do you do on-premise image generation?

Yes. ComfyUI + FLUX/SDXL for image generation in a corporate context without leaving the perimeter.

faq-domande-frequenti#generazione-immagini-onprem

What is AI Governance?

A framework of policies, processes and controls for the ethical, compliant and secure use of AI.

faq-domande-frequenti#ai-governance

Do you offer AI governance consulting?

Our contribution lies where the AI Act intersects with IT governance: taking an inventory of the AI systems in use, classifying their risk, documenting the choices made and putting in place the technical transparency measures. This is IT governance work, not legal advice: legal qualifications must be validated with a consultant.

faq-domande-frequenti#ai-governance-consulting

What is Generative Engine Optimisation (GEO)?

It is the work of making content citable by conversational assistants, which increasingly stand between people and websites. It is a practice we apply first of all to ourselves: this page also exists in Markdown and in JSON-LD precisely so that an assistant can retrieve it in full and cite it accurately.

faq-domande-frequenti#generative-engine-optimisation

Development, CMS & Workflow 33 questions

Custom development, the ACME ECMS platform and process orchestration: applications built around the real process.

Learn more: Development Custom development Content Management System

What is ACME ECMS?

ACME ECMS is our CMS platform for creating, organizing and publishing digital content in a structured, scalable and consistent way. It is a Lympha Technologies product (dedicated website: acmecms.it), modular and built on CakePHP 5.2.

faq-domande-frequenti#cos-e-acme-ecms

Is ACME ECMS accessibility-compliant?

Yes. Content is usable by everyone — an in-house requirement for those who work with public administration. The CMS complies with WCAG 2.1 AA and with the AgID Guidelines (Italian Law 4/2004).

faq-domande-frequenti#acme-ecms-accessibilita

How do multisite and multilingual work in ACME ECMS?

Multiple sites and domains from a single installation, with content in several languages coordinated and consistent within the same editorial workflow.

faq-domande-frequenti#multisito-multilingua

How many plugins does ACME ECMS have?

The official catalog currently lists 31 plugins: modules, extensions and integrations that grow the platform without one-off development.

faq-domande-frequenti#plugin-acme-ecms

How does Custom Development work?

We do not start from technology: we start from the process to be supported. Before writing code we map use cases, roles and integrations together with the people who live the process every day, then we design an application that fits into existing systems instead of replacing them.

faq-domande-frequenti#custom-development

Do you develop in open source?

Wherever possible we use open source technologies: the software remains yours and governable. Open standards and ownership of the result = no vendor lock-in.

faq-domande-frequenti#sviluppo-open-source

What is Workflow & Process Orchestration?

We connect applications and services into coherent, orchestrated flows, where every step is automatic when it can be and human when it must be — and always traced.

faq-domande-frequenti#workflow-process-orchestration

Which processes can you automate?

Approval workflows (requests, authorizations, signatures); integration between management systems (ERP, CRM); onboarding and provisioning; notifications and deadline tracking; AI agents within workflows (classification, summarization, preparation).

faq-domande-frequenti#processi-automatizzabili

Is the application lifecycle managed?

Yes. We offer a single point of contact from development to operations: hosting in the private cloud, NOC monitoring and continuous support. Evolution is planned, not endured.

faq-domande-frequenti#ciclo-vita-applicazione

Do you also do on-premise AI in your development work?

Yes. We develop solutions with agents and RAG architectures running on-premise, within the perimeter the customer controls. We are AI providers within the meaning of Regulation (EU) 2024/1689 (the AI Act).

faq-domande-frequenti#ia-onprem-sviluppi

What is BPM (Business Process Management)?

A discipline for modelling, automating, monitoring and optimizing end-to-end business processes.

faq-domande-frequenti#bpm

Do you do BPM?

Yes. Process analysis, BPMN modelling, workflow implementation, KPI monitoring.

faq-domande-frequenti#fate-bpm

What is ECM (Enterprise Content Management)?

Management of the lifecycle of corporate content: creation, collaboration, publication, archiving. ACME ECMS is our ECM.

faq-domande-frequenti#ecm

What is CCM (Customer Communication Management)?

Centralized management of communications towards customers: personalized, multichannel, compliant documents.

faq-domande-frequenti#ccm

Do you do Customer Communication Management?

Not as a standalone product. ACME ECMS manages multichannel and multilingual content from a single installation, and it is the basis on which we build communications towards users and citizens when they are part of a process we are digitizing.

faq-domande-frequenti#fate-ccm

What is low-code/no-code?

Platforms that allow applications to be built with minimal code writing, through visual interfaces.

faq-domande-frequenti#low-code-no-code

Do you offer low-code platforms?

ACME ECMS includes configurable modules for forms and workflows, which cover recurring cases without development. For complex logic we prefer custom development: a low-code platform moves the constraint, it does not remove it, and the software must remain yours and governable.

faq-domande-frequenti#piattaforme-low-code

What is a Digital Human?

These are AI-generated avatars used for assistance or communication. We do not build them. It is worth recalling that, since 2 August 2026, Article 50 of the AI Act requires interaction with an AI system to be made recognizable and synthetic content to be labelled: an obligation that falls on whoever publishes it.

faq-domande-frequenti#digital-human

What is an API-first approach?

Designing systems starting from APIs as the contract, ensuring integration and reusability.

faq-domande-frequenti#api-first

Do you follow API-first in your development?

Yes. Every application we develop has documented REST/GraphQL APIs as its primary interface.

faq-domande-frequenti#api-first-sviluppi

What is Enterprise iPaaS?

An enterprise integration platform for connecting on-premise and cloud applications with workflows.

faq-domande-frequenti#enterprise-ipaas

Do you offer integration platforms (iPaaS)?

Our way of connecting applications and services is Workflow & Process Orchestration: flows in which every step is automatic when it can be and human when it must be, and always traced. If the right solution is an off-the-shelf integration platform we will consider it, but we do not resell one from a catalog.

faq-domande-frequenti#offrite-ipaas

Do you develop Progressive Web Apps (PWA)?

Yes. PWAs for mobile-native experiences without publishing on app stores.

faq-domande-frequenti#pwa

Do you develop native mobile apps?

We do not have a team dedicated to native mobile development. The applications we build are designed API-first and accessible from a browser on mobile devices too; if a project requires a native app, the point has to be addressed openly during the analysis phase.

faq-domande-frequenti#mobile-app-native

Do you develop for e-commerce?

It is not our ground: we have neither an e-commerce offering nor expertise in e-commerce platforms. We develop management and document applications built around the process — approval workflows, integrations with ERP and management systems, workflow orchestration.

faq-domande-frequenti#e-commerce

What is omnichannel?

It is a consistent customer experience across every touchpoint — web, mobile, counter, call center. It is a marketing and customer experience topic: it is not the field we operate in, which is that of internal processes and digital services for citizens.

faq-domande-frequenti#omnichannel

Do you implement omnichannel architectures?

No. We integrate applications and services into orchestrated and traced flows — that is Workflow & Process Orchestration — but the integration of CRM, e-commerce, POS and call center for a 360° customer view is not part of our offering.

faq-domande-frequenti#architetture-omnichannel

What is a Headless CMS?

A headless CMS separates content management from content presentation: content is published via APIs and can feed different channels. ACME ECMS is designed API-first, which makes it possible to use it in this mode on projects that require it.

faq-domande-frequenti#headless-cms

Do you develop using microservices?

When the problem justifies it. We do not start from technology but from the process to be supported: a microservices architecture adds operational cost, and it makes sense if it brings an advantage the process genuinely demands. Applications are in any case designed API-first, with documented interfaces.

faq-domande-frequenti#microservizi

Do you support event-driven architectures?

Yes, where the process requires it: events that decouple systems are often the right answer for integrating management systems that should not have to know about each other. Component choices are made within the project, following the same rule as always: open standards and no lock-in.

faq-domande-frequenti#event-driven

What is RPA (Robotic Process Automation)?

Automation of repetitive tasks through software bots. We integrate it with AI agents for hyperautomation.

faq-domande-frequenti#rpa

Do you do RPA?

Automating repetitive steps is part of Workflow & Process Orchestration, and increasingly the piece that once required a bot is handled by an AI agent: classifying a document, extracting its data, preparing a case file. The difference is that the agent works within rules and permissions you define, and every step remains traced.

faq-domande-frequenti#fate-rpa

Do you offer UX/UI design services?

Interface design is part of development, with an attention that for us is not optional: WCAG 2.1 AA accessibility is an in-house requirement, because we work with public administration. We do not, however, have a separate design team to offer as a standalone service.

faq-domande-frequenti#ux-ui-design

IT Governance & DCMM 31 questions

Decision-making models, KPIs and infrastructure maturity: the Data Center Maturity Model applied to the smallest server rooms too.

Learn more: IT Governance Data Center Maturity Model (DCMM)

What is IT Governance?

It is what allows IT to be governed like the rest of the company: with explicit priorities, justified budgets, measured risks and comparable results. We help build decision-making models, service and project KPIs, and investment governance.

faq-domande-frequenti#cos-e-it-governance

What is the DCMM (Data Center Maturity Model)?

The DCMM is the model published in 2011 by The Green Grid to measure the efficiency and sustainability of a data center on a six-level scale (0–5) and across two dimensions: facility (power, cooling, building) and IT (compute, storage, network).

faq-domande-frequenti#cos-e-dcmm

What is the DCMM for?

The result is not a grade but a roadmap: knowing where you are today in order to decide where to go tomorrow. It serves to measure before investing, to direct investment where it produces most value, and to plan evolution instead of chasing emergencies.

faq-domande-frequenti#a-cosa-serve-dcmm

Is the DCMM only for large data centers?

No. Its questions apply identically to a server room with three racks: how much does cooling consume? How hard are the servers working? Is cold data occupying expensive storage? We use it as a reading grid for organizations of every size.

faq-domande-frequenti#dcmm-piccole-realta

What is the Service Lifecycle according to ITIL?

We manage the complete service lifecycle following the ITIL Service Lifecycle approach in four phases: Strategy and design → Transition → Operation → Continual improvement. A single end-to-end owner.

faq-domande-frequenti#service-lifecycle-itil

What are the benefits of the Service Lifecycle?

A single owner throughout the cycle; verifiable phases and outputs, so no grey areas between project and operations; the Competency Centers that design are integrated with those who manage and support.

faq-domande-frequenti#benefici-service-lifecycle

Which metrics are used in the DCMM?

PUE (Power Usage Effectiveness); ERF (Energy Reuse Factor); CUE (Carbon Usage Effectiveness); WUE (Water Usage Effectiveness); average monthly server utilization; efficiency of the electrical chain.

faq-domande-frequenti#metriche-dcmm

What does IT Governance include in practice?

Definition of decision-making models (who decides what); service and project KPIs measured over time; governance of investments, priorities and IT risk; continuous alignment between IT and business objectives.

faq-domande-frequenti#cosa-comprende-it-governance

What is ESG and why does it matter?

Environmental, Social, Governance: three dimensions of sustainability. Increasingly relevant for access to credit, tenders and investors.

faq-domande-frequenti#esg

What ESG rating have you obtained?

In June 2026 Ecomate assigned Lympha Technologies a BBB grade in the ESG SME Rating, with an overall score of 51/100: Environmental 45, Social 52, Governance 57. The profile is public and the rating is updated periodically: the value reported here is the one from the June 2026 assessment.

faq-domande-frequenti#rating-esg

What is greenwashing?

Environmental claims that are unverifiable or misleading. We avoid it with certified, measurable data.

faq-domande-frequenti#greenwashing

How do you avoid greenwashing?

With third-party verification rather than declarations: the data center's Green certification is issued according to a specification and published in the Green Cloud Consortium register, verifiable by anyone; the ESG rating is assigned by an external assessor and the profile is public. Where we do not publish a figure, we do not claim it.

faq-domande-frequenti#evitare-greenwashing

What is FinOps within IT Governance?

A framework for the economic governance of cloud: visibility, optimization, accountability.

faq-domande-frequenti#finops-governance

Do you offer FinOps consulting?

Yes. Assessment, implementation, training and continuous monitoring for cloud cost optimization.

faq-domande-frequenti#finops-consulting

What is TCO (Total Cost of Ownership)?

The total cost of an IT asset over its lifecycle (purchase, operation, maintenance, disposal).

faq-domande-frequenti#tco

Do you perform TCO analysis?

Yes, to compare scenarios (on-premise vs cloud, different vendors, different architectures).

faq-domande-frequenti#analisi-tco

What is ITIL 4?

The evolution of ITIL: it includes Agile, DevOps, digital transformation, value streams and the 4 dimensions of service management.

faq-domande-frequenti#itil-4

Are you ITIL certified?

The company is certified to ISO 9001:2015 (registration 19349-A, certification body Kiwa, Accredia accreditation). ITIL is not a company certification but a set of best practices: our incident, request and change management processes are aligned with it, as described on the ITSM and Service Lifecycle pages.

faq-domande-frequenti#certificazioni-itil

What is Continual Service Improvement (CSI)?

The ITIL phase for continual improvement, based on metrics, reviews and corrective actions.

faq-domande-frequenti#csi

Do you apply continual improvement?

Yes, and it is an explicit phase of our Service Lifecycle, not a good intention: service reporting produces the numbers, and the numbers produce the corrective actions. The cadence of reviews with the customer is the one agreed in the service contract.

faq-domande-frequenti#applicate-csi

What is TOGAF?

TOGAF is a framework for enterprise architecture: it relates business, data, applications and technology within a single picture. It is one of the reference points in the reasoning around governance; the model we use operationally to measure infrastructure maturity is The Green Grid's DCMM.

faq-domande-frequenti#togaf

What is COBIT?

COBIT is an IT governance framework, complementary to ITIL: where ITIL describes how to deliver services, COBIT describes how to govern and measure them. In our IT Governance work the objective is the same — explicit decision-making models, measured KPIs, justified investments — using the tools the organization already has.

faq-domande-frequenti#cobit

What is IT Risk Management?

Identification, analysis and treatment of IT risks using frameworks (ISO 27005, NIST SP 800-30).

faq-domande-frequenti#risk-management-it

Do you perform IT Risk Assessments?

Yes. Structured assessment with a risk matrix, treatment plan and monitoring.

faq-domande-frequenti#it-risk-assessment

What is Enterprise Architecture?

A blueprint of the IT organization aligned with the business: processes, data, applications, technology.

faq-domande-frequenti#enterprise-architecture

Do you provide Enterprise Architecture consulting?

We work on IT governance and infrastructure maturity: decision-making models, service and project KPIs, governance of investments and risk, and the DCMM assessment as a starting snapshot. An enterprise architecture engagement in the strict sense, across the organization's entire application landscape, is not our trade.

faq-domande-frequenti#ea-consulting

What is a Digital Transformation Office?

A governance structure for coordinating digital transformation initiatives.

faq-domande-frequenti#dto

Do you help set up a Digital Transformation Office?

The organizational design of a structure of this kind is not what we sell. What we bring is the IT piece on which a transformation stands or falls: measuring maturity before investing, defining who decides what, and putting comparable KPIs on services and projects.

faq-domande-frequenti#aiuto-dto

What is a maturity assessment?

An evaluation of the maturity level of an area (IT, security, data center) against frameworks (DCMM, CMMI, ISO).

faq-domande-frequenti#maturity-assessment

Do you perform maturity assessments?

The model we use is The Green Grid's DCMM (Data Center Maturity Model): six levels, two dimensions (facility and IT), and a roadmap rather than a grade as the outcome. It works on a data center just as it does on a server room with three racks.

faq-domande-frequenti#fate-maturity-assessment

What is a Technology Radar?

It is the instrument by which an organization keeps track of emerging technologies and decides whether to adopt them, trial them or leave them alone. It is the kind of decision that IT Governance makes explicit instead of leaving it to urgency: declared priorities, justified investments, measured risks.

faq-domande-frequenti#technology-radar

Data Centre & Green IT 27 questions

The 00GATE Green Data Center and measured efficiency: PUE, free cooling, renewable energy, Zero Emission Data Center.

Learn more: Server Farm & Data Centre Design Our commitment to the environment Facility Management Data Center Maturity Model (DCMM)

What is a Green Data Center?

A data center designed for minimal environmental impact: a low-transmittance timber structure, low infrastructure density, free cooling without refrigeration, 100% renewable energy. Our 00GATE is Green certified by Accredia® and, given the way it is built, is among the first of its kind in southern Europe.

faq-domande-frequenti#cos-e-data-center-green

What is PUE?

PUE (Power Usage Effectiveness) is an indicator introduced in 2007 that measures how efficiently a data center uses energy. A PUE of 1.0 would be perfect (all the energy goes to IT). It is the number that separates data centers that are managed from those that are merely endured.

faq-domande-frequenti#cos-e-pue

Why isn't PUE enough?

In newer data centers, 70–90% of the energy is consumed by the IT systems — precisely the part PUE does not measure. What is needed are metrics of work capacity, productivity per megawatt-hour, and the newer work-efficiency metrics.

faq-domande-frequenti#pue-non-basta

How is your Green Data Center built?

A timber structure for minimal thermal transmittance; low density (50% of rack space used) for natural dissipation; free cooling (convective air movement, without refrigeration); an operating temperature of around 28°C instead of the traditional 18–20°C; 100% renewable energy (photovoltaic and wind).

faq-domande-frequenti#come-e-fatto-green-dc

What does digital energy cost?

Average values (source: Gartner): ≈200 g of CO₂ for an email with 10 MB of attachments; 250 g of CO₂ for a minute of video; 200 g of CO₂ for a text message; 4 g of CO₂ for a web page.

faq-domande-frequenti#costo-energia-digitale

Do you have an ESG rating?

Yes. In June 2026 Ecomate assigned Lympha Technologies a BBB grade (ESG SME Rating) with a score of 51/100: Environmental 45/100, Social 52/100, Governance 57/100.

faq-domande-frequenti#rating-esg-ambiente

What is digital sovereignty?

A data center built on European soil but owned by someone else does not make your data sovereign: what counts is ownership, control and the ability to leave. We guarantee that data stays in Italy and under your control.

faq-domande-frequenti#sovranita-digitale

Do you design Green Data Centers for customers?

Yes. Our experience has become a service: we design Zero Emission Data Centers for customers — zero-emission data centers powered by renewables, with optimized PUE and DCIM monitoring of consumption and efficiency.

faq-domande-frequenti#progettate-dc-green

What are Tier III and Tier IV?

They are the Uptime Institute's classifications of a data center's redundancy: Tier III can be maintained without stopping services, Tier IV tolerates the failure of a component without interruption. 00GATE is in a Tier III configuration, with guaranteed operational continuity of 99.98% — a maximum of 1.6 hours of downtime per year.

faq-domande-frequenti#tier-iii-tier-iv

Is 00GATE Tier III or Tier IV?

It is in a Tier III configuration, with guaranteed operational continuity of 99.98% — a maximum of 1.6 hours of downtime per year — and physical protection entrusted to almost 200 devices across access control, detection and video surveillance.

faq-domande-frequenti#00gate-tier

What is LEED certification?

LEED (Leadership in Energy and Environmental Design) is an international building sustainability certification that assesses materials, consumption and the quality of indoor environments. It is widespread in construction, data centers included.

faq-domande-frequenti#certificazione-leed

Does 00GATE have LEED?

No. The external verification we have chosen is the Green certification issued according to a specification and accredited by Accredia®, published in the Green Cloud Consortium register and verifiable by anyone. LEED concerns the sustainability of the building; that certification concerns the operation of the data center.

faq-domande-frequenti#00gate-leed

What is CUE (Carbon Usage Effectiveness)?

CUE (Carbon Usage Effectiveness) measures carbon emissions per unit of energy consumed by IT. It is the metric on which the choice of source weighs most: 00GATE is powered 100% from renewable sources, and it is this — not an offsetting mechanism — that affects the result.

faq-domande-frequenti#cue

What is WUE (Water Usage Effectiveness)?

WUE (Water Usage Effectiveness) measures the litres of water consumed per unit of IT energy. It is a metric that matters because many data centers cool with water. 00GATE does not: it uses free cooling by convective air movement, with no refrigeration plant and therefore no water consumption for cooling.

faq-domande-frequenti#wue

What is ERF (Energy Reuse Factor)?

ERF (Energy Reuse Factor) measures how much of the energy consumed is recovered and reused elsewhere, typically as waste heat. It is a metric that rewards high-density data centers with a lot of concentrated heat; 00GATE is designed the opposite way — low density and natural dissipation — and there is structurally little heat to recover.

faq-domande-frequenti#erf

What is a GO (Guarantee of Origin)?

The Guarantee of Origin is the European certificate attesting the renewable origin of electricity. The data center is powered 100% from renewable sources, photovoltaic and wind; the certificates from our supply contracts are published and downloadable on the Sustainability page.

faq-domande-frequenti#go-energy

What is DORA and does it concern you?

DORA (the Digital Operational Resilience Act) is the European regulation on digital operational resilience in the financial sector. It does not apply to us as such: it applies to financial entities and, by contractual extension, to the ICT suppliers that serve them. If you are subject to DORA, the requirements on continuity, testing and incident management must be translated into contractual clauses: that is a check to be carried out together before signing, not a compliance declaration on our part.

faq-domande-frequenti#dora

What is the Climate Neutral Data Center Pact?

It is the voluntary initiative through which European data center operators have committed to climate neutrality by 2030, with targets on efficiency, clean energy, water and the circular economy. We have not joined it: 00GATE was designed to produce no emissions from the outset, and the external verification we bring is the Accredia® Green certification.

faq-domande-frequenti#climate-neutral-pact

What is the EU Code of Conduct for Data Centres?

It is the European Commission's voluntary programme on data center energy efficiency, with a public list of participants and endorsers. We do not appear on it: the external verification we have chosen for 00GATE is the Accredia® Green certification, published in the Green Cloud Consortium register.

faq-domande-frequenti#eu-code-conduct-dc

What is ISO 50001 and are you certified?

ISO 50001 is the standard for energy management systems, and it requires measuring the work produced per unit of energy consumed — not just how much energy is consumed. We are not ISO 50001 certified: Lympha Technologies' only management system certification is ISO 9001:2015 (registration 19349-A, certification body Kiwa, Accredia accreditation).

faq-domande-frequenti#iso-50001

What is the ISO 22237 standard?

It is the series of international standards dedicated to data center infrastructures — power, cooling, physical security, cabling — similar in purpose to the American TIA-942. 00GATE is in a Tier III configuration and Green certified by Accredia®; a declared conformity to the 22237 series is not among the certifications we publish.

faq-domande-frequenti#iso-22237

What is annual versus instantaneous PUE?

Instantaneous PUE says little: it depends on load and season, and it lends itself to being picked at the most favourable moment. The annual figure, an average over twelve months, is the only comparable one. There is also a more uncomfortable premise: in recent data centers 70–90% of the energy is consumed by IT, that is, precisely the part PUE does not measure.

faq-domande-frequenti#pue-annuo-vs-istantaneo

What is free cooling?

Cooling with outside air without compressor-based cooling. 00GATE uses only winter and convective free cooling.

faq-domande-frequenti#free-cooling

What is hot aisle containment?

It is the containment of hot aisles, separating hot and cold air flows so as not to waste cooling. It is a technique designed for high-density rooms: 00GATE follows a different route — low density, half the rack space deliberately used, and dissipation through natural convective air movement.

faq-domande-frequenti#hot-aisle-containment

What is liquid cooling?

It is liquid cooling, needed when power density per rack becomes too high for air to suffice — it is the route taken by rooms dedicated to intensive computing. 00GATE goes in the opposite direction by design: half the rack space deliberately used, an operating temperature of around 28 °C and convective free cooling, with no refrigeration plant.

faq-domande-frequenti#liquid-cooling

What is the environmental impact of an email?

Among the average values we cite (source: Gartner), an email with 10 MB of attachments weighs around 200 g of CO₂. For comparison: 250 g for a minute of video, 200 g for a text message, 4 g for a web page. These are orders of magnitude, useful for understanding that digital does have an environmental cost.

faq-domande-frequenti#impronta-email

What is the digital carbon footprint?

It is the overall footprint of an organization's digital activities: devices, network, data center, cloud services. Measuring it requires data that sits in different places, and it is one of the reasons we insist on asset inventory: the CMDB and consumption monitoring are the precondition for any credible measurement.

faq-domande-frequenti#digital-carbon-footprint

Sectors & Verticals 22 questions

How continuity, security and traceability change across Public Administration, Healthcare, Large Enterprises and SMEs.

Learn more: Sectors PA Locale Healthcare Large Enterprises SMEs

How do you work with local public administration?

Compliance with the CAD (Italian Legislative Decree 82/2005): preference for open source software and reuse (Articles 68–69), WCAG 2.1 AA accessibility, full GDPR compliance with a qualified DPO, data sovereignty in line with NIS2 and ACN guidance.

faq-domande-frequenti#lavorate-pa-locale

How do you handle healthcare data?

Health data falls into special categories (Article 9 GDPR): reinforced safeguards, minimization, access traceability. We offer BC/DR with RTO/RPO per clinical service, a 24×7 NOC, dedicated private cloud and on-premise AI with no data leaving the perimeter.

faq-domande-frequenti#dati-sanitari

What is the NIS2 directive and does it concern you?

NIS2 covers essential and important sectors — including healthcare, energy, transport, public administration, finance and telecoms — and requires adequate security measures, tested continuity plans and incident notification. If you fall within its scope, the elements we affect are the infrastructural ones: continuity with RTO and RPO derived from the BIA, timed tests, documented incident management, security assessments. Qualifying your organization as a NIS2 entity, however, is a determination that falls to you.

faq-domande-frequenti#nis2

How do you work with Large Enterprises?

We offer IT Governance and DCMM to govern large-scale investments, data center design and facility management (including Zero Emission), management of the workstation estate through SPOC with VIP queues and a CMDB, and integrated Competency Centers.

faq-domande-frequenti#grandi-aziende

What services do you offer to SMEs?

Modular subscription-based paths: 1. Protection & continuity — DPaaS on a fee basis; 2. Managed workstations — SPOC/Help Desk model; 3. Fully managed IT — NOC + continuous support.

faq-domande-frequenti#servizi-pmi

Do SMEs face the same risks as large enterprises?

Yes — downtime, data loss, attacks — but not the same budgets or a structured IT department. The pay-per-use model and modular paths make it possible to start from what is genuinely needed and grow when required.

faq-domande-frequenti#pmi-stessi-rischi

Do you also do facility management?

Yes. Data center design and facility management are part of the CNS Business Unit, with architectures, capacity planning and facility planning for server farms and data centers.

faq-domande-frequenti#facility-management

How do you manage projects for public administration?

In the language of public framework agreements: formalized processes, SLAs and reporting. The ACME ECMS CMS complies with the CAD and with the AgID accessibility guidelines.

faq-domande-frequenti#progetti-pa

What is the Electronic Health Record (FSE)?

It is the system that collects a citizen's clinical history in digital form, managed at regional level. We do not implement FSE systems: our role in healthcare is the infrastructure beneath the clinical applications — continuity, data protection, continuous oversight, private cloud with data in Italy.

faq-domande-frequenti#fse

Do you work with Local Health Authorities?

Healthcare is one of the four sectors we cover. The approach is the one described on the dedicated page: continuity and disaster recovery with RTO and RPO defined per clinical service, 24×7×365 NOC coverage, dedicated private cloud with data in Italy, and on-premise AI for documents that cannot leave. Specific references are shared on request.

faq-domande-frequenti#asl

What is the CAD for public administration?

The CAD (Codice dell'Amministrazione Digitale, Italian Legislative Decree 82/2005) is the regulatory framework for the digitalization of public administration. The articles that concern us most closely are 68 and 69, on the preference for open source software and on reuse: it is the reason we develop with open technologies and the software remains the property of the public body.

faq-domande-frequenti#cad-pa

Do you integrate SPID and CIE?

ACME ECMS includes the Acme SpidFedera plugin for authentication with SPID and Federa, and the Acme LDAP plugin for corporate accounts. Integration with CIE is not part of the published plugin catalog: if a project requires it, it has to be explicitly planned.

faq-domande-frequenti#spid-cie

Do you integrate PagoPA?

PagoPA does not appear in the published ACME ECMS plugin catalog. It is an integration that can be built as custom development within a public administration project, but it has to be planned and sized: it is not a feature already available from the catalog.

faq-domande-frequenti#pagopa

Do you integrate the IO app?

Integration with the IO app is not part of the published ACME ECMS plugin catalog. As with the other services of the national public platform, it can be built as custom development and has to be planned within the project.

faq-domande-frequenti#app-io

Do you integrate ANPR?

Integration with ANPR (the Italian National Register of the Resident Population) is not part of the published ACME ECMS plugin catalog. It can be built as custom development within a project for municipal registry services.

faq-domande-frequenti#anpr

Do you follow NRRP (PNRR) projects for public administration?

The areas in which we operate — cloud migration, security, process digitalization, accessibility — are those in which many public bodies have invested using NRRP funds. We work in the language of public framework agreements: formalized processes, SLAs and reporting. Reporting on the use of funds remains the responsibility of the public body and its consultants.

faq-domande-frequenti#pnrr

What is the Cloud First principle for public administration?

It is the principle by which an administration must first evaluate cloud solutions, and justify its choice if it decides otherwise. It has to be read together with the requirements on data sovereignty and localization referred to by NIS2 and ACN guidance: our private cloud is a dedicated perimeter with data in Italy. Where a tender requires ACN qualification of the services, the requirement has to be verified upfront.

faq-domande-frequenti#cloud-first-pa

Do you work with Universities?

We do not have an offering dedicated to the university world. Our roots do pass close by, however: Lympha was founded in 2011, incubated by ASTER, the Emilia-Romagna Region consortium with the University of Bologna, CNR and ENEA. The sectors we cover with specific content and skills are local public administration, healthcare, large enterprises and SMEs.

faq-domande-frequenti#universita

Do you work with Foundations?

We do not have a vertical offering for foundations. Continuity, data protection, managed workstation and private cloud services are cross-sector and are sized on the organization requesting them, whatever its legal form.

faq-domande-frequenti#fondazioni

Do you work with Cooperatives?

We do not have a vertical offering for the cooperative world. The same applies as for other organizations: the modular subscription paths — protection and continuity, managed workstations, fully managed IT — are chosen on the basis of what is genuinely needed and grow over time.

faq-domande-frequenti#cooperative

Do you work with Consortia?

We do not have a vertical offering for consortia. The infrastructure and managed services we deliver are the same, sized on the organization's critical process: the starting point is always understanding which outage you cannot afford.

faq-domande-frequenti#consorzi

Are you registered on MePA?

Registration on the Italian public administration electronic marketplace has to be verified on the Acquisti in Rete portal, where the list of operators is public and always up to date. For purchasing arrangements and the framework agreements applicable to your organization, the quickest route is to ask us directly.

faq-domande-frequenti#mepa

Regulation & Compliance 23 questions

GDPR, NIS2, AI Act, AgID and accessibility: the obligations that affect infrastructure and how we govern them.

Learn more: Certifications PA Locale Cybersecurity Privacy & Cookie Policy

What is the European AI Act?

Regulation (EU) 2024/1689 is the first comprehensive body of rules on artificial intelligence in Europe: it grades obligations according to the risk of the system, from absolute prohibitions to transparency obligations. It has been amended by Regulation (EU) 2026/1744, the “Digital Omnibus on AI”, in force since 27 July 2026, which rewrote some of its articles and pushed back the high-risk deadlines.

faq-domande-frequenti#cos-e-ai-act

What came into effect on 2 August 2026?

The transparency obligations of Article 50, the penalty regime and the operation of market surveillance authorities: this is the deadline the Digital Omnibus confirmed rather than postponed. They concern anyone who has people interact with an AI system or who publishes generated content, including those who do not consider themselves an “AI company”.

faq-domande-frequenti#cosa-scatto-2-agosto-2026

What has been postponed, and until when?

Only high risk, and with two distinct dates set by the Digital Omnibus: 2 December 2027 for Annex III systems (Article 6(2)) and 2 August 2028 for those embedded in Annex I products (Article 6(1)). Unchanged at 2 December 2026 are the transitional deadline for marking content generated by systems already on the market and the new prohibitions introduced by the Omnibus.

faq-domande-frequenti#cosa-rinviato-2027

What does it mean to be an AI provider under the AI Act?

A provider is whoever places an AI system on the market or puts it into service under their own name, even when the underlying model belongs to a third party; a deployer is whoever uses it under their own authority. This distinction determines all the other obligations, and it is the first determination to make, system by system. We qualify as providers for the platforms we build, and we set down in writing in the contract which obligations we discharge and which remain yours.

faq-domande-frequenti#fornitore-ia-ai-act

Is your CMS compliant with public administration regulations?

Yes. ACME ECMS complies with the CAD (Italian Legislative Decree 82/2005), with the AgID Guidelines, with Italian Law 4/2004 on accessibility (WCAG 2.1 AA) and with the GDPR, with a qualified DPO.

faq-domande-frequenti#cms-conformita-pa

How do you position yourselves on compliance?

The choices we describe are structural, not bolted on afterwards: the ISO 9001:2015 certified quality system, the data center Green certified by Accredia®, GDPR compliance with a qualified DPO, and the legality rating. On NIS2 and the AI Act our role is different and needs stating precisely: we are not the ones who make you compliant, but we govern the infrastructural and technical aspects on which your compliance depends.

faq-domande-frequenti#compliance-posizionamento

What is the ACN?

The Italian National Cybersecurity Agency is the country's cybersecurity authority: it manages the qualification of cloud services for public administration and oversight of NIS2 implementation. Law 132/2025 also gave it a role on artificial intelligence — supervision, inspections and penalties — while notification, evaluation and accreditation fall to AgID.

faq-domande-frequenti#cos-e-acn

What is CISPE?

CISPE (Cloud Infrastructure Services Providers in Europe) is the association of European cloud infrastructure providers, known for its data protection code of conduct recognized under Article 40 of the GDPR. We are not members: the external verifications we bring are the data center's Green certification and the ISO 9001:2015 quality system.

faq-domande-frequenti#cispe

What is GDPR Article 9 (special category data)?

Health, biometric and genetic data, political opinions, religion, sex life. They require reinforced safeguards.

faq-domande-frequenti#gdpr-art-9

How do you handle Article 9 data?

With the safeguards that special category data requires: encryption, minimization, granular access control and traceability of who saw what. When we process such data on behalf of a customer we do so as a processor, within the controller's instructions; the impact assessment, where required, falls to the controller.

faq-domande-frequenti#trattamento-art-9

What is a DPIA (Data Protection Impact Assessment)?

It is the data protection impact assessment, mandatory for processing that presents a high risk to people's rights. It is an obligation of the data controller: in projects involving special category data we provide the necessary technical elements — security measures, data flows, retention periods — and our qualified DPO can support you, but the assessment remains yours.

faq-domande-frequenti#dpia

What is a DPO (Data Protection Officer)?

A mandatory role for public administration and certain private entities. We offer an external qualified DPO service.

faq-domande-frequenti#dpo

How does the AI Act classify risks?

Four levels: prohibited practices (Article 5), high risk (Article 6 and Annex III), transparency risk (Article 50) and minimal risk. Penalties follow the same scale: up to 35 million euros or 7% of worldwide turnover for prohibited practices, up to 15 million or 3% for breaches of transparency obligations. The classification must be justified in writing: it is the first document an authority asks for.

faq-domande-frequenti#ai-act-risk-classification

Are your AI systems high-risk?

As a rule, no: the document platforms and agents we build fall under the transparency obligations of Article 50 or under minimal risk. But classification is done system by system, on actual use: the most realistic high-risk case for a company is recruitment (Annex III), which is often a blind spot because the tool comes from HR and not from IT.

faq-domande-frequenti#sistemi-ai-high-risk

What is the conformity assessment for high-risk AI?

It is the procedure by which a high-risk system is verified as meeting the requirements of the regulation before being placed on the market; in some cases it requires the involvement of a notified body. The Digital Omnibus introduced a simplified technical documentation form for SMEs and start-ups, which notified bodies are required to accept.

faq-domande-frequenti#conformity-assessment-ai

What is CE marking for AI systems?

It is the marking that attests the conformity of a high-risk system and is required before placing it on the EU market. It should be kept distinct from another obligation, which takes effect earlier and concerns far more parties: the machine-readable marking of AI-generated content, required by Article 50(2) of the provider, with a transitional deadline of 2 December 2026 for systems already on the market.

faq-domande-frequenti#ce-marking-ai

Is there a public register of AI systems?

The AI Act provides for an EU database (Article 71) in which high-risk systems must be registered before being placed on the market, with information obligations on the provider. It is not a general register of all AI systems: for those subject only to Article 50, the obligation is transparency towards people, not registration.

faq-domande-frequenti#transparency-register-ai

What is DORA in brief?

The Digital Operational Resilience Act is the European regulation that requires financial entities to have a structured ICT risk management framework: an inventory of dependencies, resilience testing, incident notification and mandatory clauses in contracts with ICT service providers. The obligations fall on the financial entity, which passes them down the supply chain contractually.

faq-domande-frequenti#dora-sintesi

How do you support a customer subject to DORA?

On the points where the regulation touches infrastructure: continuity and disaster recovery plans tested with measured timings, documented incident management, security assessments and reporting usable as evidence. The contractual clauses required by DORA have to be agreed explicitly; the legal qualification of the relationship has to be validated with your consultants.

faq-domande-frequenti#conformita-dora

What is the CER Directive?

The CER (Critical Entities Resilience) directive concerns the physical and organizational resilience of critical entities — energy, transport, healthcare, banking — and is the complement to NIS2, which instead deals with information security. The two must be read together: a continuity plan that covers only the cyber incident leaves half the problem uncovered.

faq-domande-frequenti#direttiva-cer

What is data residency?

A geographic constraint on where data physically resides. Our data resides exclusively in Italy.

faq-domande-frequenti#data-residency

Is healthcare subject to NIS2?

Yes. Healthcare is among the essential sectors (NIS2 directive) — tested continuity and recovery plans are needed, not declared ones.

faq-domande-frequenti#settore-sanita-nis2

Which regulations must public administrations comply with?

The CAD (Italian Legislative Decree 82/2005), the GDPR, NIS2, ACN guidance on cloud, accessibility under Italian Law 4/2004 and WCAG 2.1 AA, and now the AI Act. Our contribution lies where these rules touch infrastructure and applications: data sovereignty and localization, tested continuity, verified accessibility, traceability. The obligations that fall on the public body as controller remain its own.

faq-domande-frequenti#compliance-pa-gdpr-cad-nis2

La tua domanda non è in elenco?

Scrivicela: rispondiamo entro 2 giorni lavorativi e, se è una domanda che si ripete, la aggiungiamo a questa pagina.