Certified, audited, and independently assured
We run a formal Information Security Management System (ISMS) on the ISO/IEC 27001 framework, and hold the certification to prove it. Certificate, audit summaries and reports are available under NDA.
ISO/IEC 27001:2022 certified
Certified since 2024, covering the design, development, operation and delivery of our software, and maintained through annual surveillance audits.
A managed ISMS
Overseen by an internal information-security function with defined accountability and segregation of duties, reviewed by management at least annually, with a full Annex A Statement of Applicability.
Independent assurance
External penetration testing at least annually and after major changes, alongside recurring internal and external ISO 27001 audits and annual privacy audits.
In your region, and only your region
Storage, AI processing and backups all run on Microsoft Azure in your region's data centers. Azure's facilities are ISO 27001- and SOC 2-compliant, with 24/7 physical security.
European customers
Served entirely from the EU/EEA, across Azure regions in six EU countries. Stored, processed, backed up and run through our AI within the EU/EEA. No European customer data is held or processed in Australia, and backups are geo-redundant within EU Azure on a 90-day retention.
Australian customers
Served entirely from Australian infrastructure, including AI processing and backups. Stored, processed, backed up and run through our AI within Australia. No Australian customer data is held or processed in the EU/EEA, and the estate is fully isolated from the European one.
A limited, vetted set, reviewed annually
The current, complete sub-processor and region list for your engagement is maintained in the sub-processor annex to your contract, and available on request.
Vetted and contractually bound
A limited set of sub-processors. Key providers must demonstrate ISO 27001 or SOC 2 compliance, are bound by GDPR Article 28 DPAs, and are reviewed at least annually.
Notified before any change
We inform customers of any intended change with a window to object for good cause. Australian customers are served entirely from Australian infrastructure.
Transfers outside your region
Where a sub-processor's parent entity sits outside your region, processing still runs on in-region infrastructure under Standard Contractual Clauses or equivalent safeguards, and our DPO conducts Transfer Impact Assessments.
Encrypted, isolated, and continuously monitored
Encrypted in transit and at rest
All traffic uses TLS 1.2+ with HTTPS enforced; data at rest is encrypted with AES-256 (FIPS 140-2-validated) across the database, file storage, backups and logs.
Key management
Keys are managed through validated key-management controls, with secrets in a dedicated vault with rotation.
Tenant isolation
The platform is multi-tenant with strict logical isolation; cross-tenant access is technically prevented.
Segmented network, defended edge
Dev, staging and production run in isolated, segmented environments not reachable from the public internet, behind managed DDoS protection and WAF controls.
Monitored, logged, and answerable
A central SIEM gives real-time monitoring and alerting, backed by a documented incident-management process. Actions are logged with attribution and protected against tampering.
Least-privilege access, enforced and reviewed
Single sign-on and MFA
Enterprise SSO via Microsoft Entra ID and other SAML 2.0 / OIDC providers (including Okta), with MFA enforced for privileged production access and for your users through your IdP.
Role-based, least-privilege
Access follows least-privilege and need-to-know: just-in-time access for sensitive infrastructure, dual approval for privileged access, and no shared administrator accounts.
Reviewed and revoked
Access rights are reviewed at least semi-annually and on every role change; on offboarding, access is revoked immediately.
Four-eyes on the work product
A built-in preparation-and-review workflow enforces the four-eyes principle on the audit work product itself.
Secure by design, tested before release
Secure by design, built in-house
A documented secure-SDLC aligned with ISO/IEC 27001 and the OWASP Top 10, with threat modeling and security acceptance criteria at each stage. Core development is not outsourced.
Tested before release
CI/CD runs SAST/DAST and dependency scanning; every change requires peer review and passes staging QA. Test environments use only synthetic or pseudonymized data, never live customer data.
Independently penetration-tested
Weekly dependency checks, quarterly vulnerability scans, and at least annual manual penetration testing by an independent third party, with risk-based remediation. Customers may test too, by arrangement.
People, devices, and process
Vetted people
Background checks before employment, including identity, legal and reference verification.
Endpoint management
Managed endpoint protection, disk encryption and MDM on company devices.
Confidentiality and annual training
All staff and authorized contractors sign lasting confidentiality agreements and complete mandatory security-awareness training (phishing, data handling, GDPR, ISO 27001) at onboarding and annually.
Controlled joiners and leavers
Access is provisioned by role at onboarding and revoked immediately on departure, with asset return tracked.
Resilient by design, tested by schedule
- ~4 hrs
- Recovery time objective (RTO)*
- ~24 hrs
- Recovery point objective (RPO)*
- 99.5%
- Monthly availability target
- 99.98%
- Measured uptime to date
Backed up and tested
Backups are daily, encrypted and geo-redundant within EU Azure, with 90-day retention. Restore tests run at least quarterly, plus scenario-based drills.
Warm standby
A secondary EU Azure environment is kept on warm standby and can be promoted into production at the same security level.
*RTO/RPO are operational targets, not contractual guarantees.
Conducting a vendor security assessment?
Leave your details and someone from our team will get in touch, whether you want a walkthrough of our controls or help completing a security questionnaire.
Contact form loads after consent
This form is provided by HubSpot and sets cookies, so it loads only once you accept functional cookies. You can also email hello@dnlab.de.
