Skip to content

Built for the most confidential work in the firm.

Auditors handle their clients' most sensitive financial information under strict professional-secrecy obligations. dnl is engineered to meet that standard: ISO/IEC 27001-certified, hosted entirely in your own region, independently penetration-tested, and fully isolated between tenants.

Certified, audited, and independently assured

We run a formal Information Security Management System (ISMS) on the ISO/IEC 27001 framework, and hold the certification to prove it. Certificate, audit summaries and reports are available under NDA.

  • ISO/IEC 27001:2022 certified

    Certified since 2024, covering the design, development, operation and delivery of our software, and maintained through annual surveillance audits.

  • A managed ISMS

    Overseen by an internal information-security function with defined accountability and segregation of duties, reviewed by management at least annually, with a full Annex A Statement of Applicability.

  • Independent assurance

    External penetration testing at least annually and after major changes, alongside recurring internal and external ISO 27001 audits and annual privacy audits.

In your region, and only your region

Storage, AI processing and backups all run on Microsoft Azure in your region's data centers. Azure's facilities are ISO 27001- and SOC 2-compliant, with 24/7 physical security.

  • European customers

    Served entirely from the EU/EEA, across Azure regions in six EU countries. Stored, processed, backed up and run through our AI within the EU/EEA. No European customer data is held or processed in Australia, and backups are geo-redundant within EU Azure on a 90-day retention.

  • Australian customers

    Served entirely from Australian infrastructure, including AI processing and backups. Stored, processed, backed up and run through our AI within Australia. No Australian customer data is held or processed in the EU/EEA, and the estate is fully isolated from the European one.

A limited, vetted set, reviewed annually

The current, complete sub-processor and region list for your engagement is maintained in the sub-processor annex to your contract, and available on request.

  • Vetted and contractually bound

    A limited set of sub-processors. Key providers must demonstrate ISO 27001 or SOC 2 compliance, are bound by GDPR Article 28 DPAs, and are reviewed at least annually.

  • Notified before any change

    We inform customers of any intended change with a window to object for good cause. Australian customers are served entirely from Australian infrastructure.

  • Transfers outside your region

    Where a sub-processor's parent entity sits outside your region, processing still runs on in-region infrastructure under Standard Contractual Clauses or equivalent safeguards, and our DPO conducts Transfer Impact Assessments.

Encrypted, isolated, and continuously monitored

  • Encrypted in transit and at rest

    All traffic uses TLS 1.2+ with HTTPS enforced; data at rest is encrypted with AES-256 (FIPS 140-2-validated) across the database, file storage, backups and logs.

  • Key management

    Keys are managed through validated key-management controls, with secrets in a dedicated vault with rotation.

  • Tenant isolation

    The platform is multi-tenant with strict logical isolation; cross-tenant access is technically prevented.

  • Segmented network, defended edge

    Dev, staging and production run in isolated, segmented environments not reachable from the public internet, behind managed DDoS protection and WAF controls.

  • Monitored, logged, and answerable

    A central SIEM gives real-time monitoring and alerting, backed by a documented incident-management process. Actions are logged with attribution and protected against tampering.

Least-privilege access, enforced and reviewed

  • Single sign-on and MFA

    Enterprise SSO via Microsoft Entra ID and other SAML 2.0 / OIDC providers (including Okta), with MFA enforced for privileged production access and for your users through your IdP.

  • Role-based, least-privilege

    Access follows least-privilege and need-to-know: just-in-time access for sensitive infrastructure, dual approval for privileged access, and no shared administrator accounts.

  • Reviewed and revoked

    Access rights are reviewed at least semi-annually and on every role change; on offboarding, access is revoked immediately.

  • Four-eyes on the work product

    A built-in preparation-and-review workflow enforces the four-eyes principle on the audit work product itself.

Secure by design, tested before release

  • Secure by design, built in-house

    A documented secure-SDLC aligned with ISO/IEC 27001 and the OWASP Top 10, with threat modeling and security acceptance criteria at each stage. Core development is not outsourced.

  • Tested before release

    CI/CD runs SAST/DAST and dependency scanning; every change requires peer review and passes staging QA. Test environments use only synthetic or pseudonymized data, never live customer data.

  • Independently penetration-tested

    Weekly dependency checks, quarterly vulnerability scans, and at least annual manual penetration testing by an independent third party, with risk-based remediation. Customers may test too, by arrangement.

People, devices, and process

  • Vetted people

    Background checks before employment, including identity, legal and reference verification.

  • Endpoint management

    Managed endpoint protection, disk encryption and MDM on company devices.

  • Confidentiality and annual training

    All staff and authorized contractors sign lasting confidentiality agreements and complete mandatory security-awareness training (phishing, data handling, GDPR, ISO 27001) at onboarding and annually.

  • Controlled joiners and leavers

    Access is provisioned by role at onboarding and revoked immediately on departure, with asset return tracked.

Resilient by design, tested by schedule

~4 hrs
Recovery time objective (RTO)*
~24 hrs
Recovery point objective (RPO)*
99.5%
Monthly availability target
99.98%
Measured uptime to date
  • Backed up and tested

    Backups are daily, encrypted and geo-redundant within EU Azure, with 90-day retention. Restore tests run at least quarterly, plus scenario-based drills.

  • Warm standby

    A secondary EU Azure environment is kept on warm standby and can be promoted into production at the same security level.

*RTO/RPO are operational targets, not contractual guarantees.

Conducting a vendor security assessment?

Leave your details and someone from our team will get in touch, whether you want a walkthrough of our controls or help completing a security questionnaire.

Contact form loads after consent

This form is provided by HubSpot and sets cookies, so it loads only once you accept functional cookies. You can also email hello@dnlab.de.