BSI C5 - Type 2
KRITIS-V and NIS-2, PCI DSS
Protecting the information entrusted to us is the core of what we do. We operate an information security management system aligned with ISO/IEC 27001:2022, and our policies are reviewed, communicated and approved by management at least once a year.
An ISMS aligned with ISO/IEC 27001:2022. Policies are owned by management, reviewed annually, and every role carries clear security responsibilities.
Customer data is encrypted at rest and in transit. Personal data is handled in line with the GDPR and the BDSG, under clear privacy notices.
Our services run on hardened cloud infrastructure located within the European Union; provider security and compliance are monitored on an ongoing basis.
Unique accounts, enforced multi-factor authentication and least-privilege access, with single sign-on (SAML / OIDC) where configured and access reviewed regularly.
A documented secure development lifecycle with peer review, automated dependency and image scanning in the build pipeline, and independent penetration testing.
Access is restricted to managed devices with encrypted drives and endpoint detection & response, continuously checked against a security baseline.
System activity and security events are logged, protected from tampering and monitored, with alerting for unusual usage and defined retention periods.
Third parties that may process data are risk-assessed before onboarding and reviewed regularly; the current list is available to customers on request.
Important data and systems are backed up and tested, with business continuity and disaster recovery plans maintained so we keep calm and carry on.
If you believe you have found a security vulnerability in our service, please report it to security@eusec.net. If you think your account has been compromised or you notice suspicious activity, use the same address. We review every report and act on it promptly.
The API, dashboard, website and email systems behind EUSEC run on hardened cloud infrastructure operated entirely within the European Union by our infrastructure provider, Hetzner Online GmbH. That infrastructure carries the independently audited certifications and attestations below — so the foundation we build on is held to the same standard we measure others against.
The infrastructure is certified to ISO/IEC 27001:2022. With respect to the controls in Annex A of the standard, there are no exclusions.
A BSI C5 Type 2 attestation demonstrates an independently audited, high level of security for the cloud services. C5 — the Cloud Computing Compliance Criteria Catalogue — is published by Germany's Federal Office for Information Security (BSI) and defines minimum requirements for the information security of cloud services. A Type 2 attestation confirms that the criteria are not only appropriately implemented but have also been effectively applied over a defined period. The catalogue is wide-ranging, spanning organisational, technical and operational measures, governance and management structures, transparency obligations and legal frameworks. Its base criteria incorporate all ISO/IEC 27001 criteria and require a management system aligned with that standard.
The provider is classified in Germany by the Federal Office for Information Security (BSI) as an operator of critical services under the national KRITIS regulation, and is certified in accordance with § 8a BSIG.
The Payment Card Industry Data Security Standard (PCI DSS) is an internationally recognised security standard for companies that process or transmit credit card data. The provider itself does not store credit card information; processing is handled exclusively through its certified German payment service provider, Computop. Card details are entered directly in the provider's customer account, which fully complies with PCI DSS in its current version 4.0, revision 1.0.
The SoA is an internal document that is not made available to third parties. There are no exclusions from the Annex A controls of ISO/IEC 27001:2022.
A wide range of measures safeguards the processing of personal data. An overview of the technical and organisational measures is provided in Annex 2 of the data processing agreement (DPA). The TOMs are reviewed at regular intervals by an external data protection organisation — currently TÜV Rheinland — and the audit report is made available to customers with a DPA directly in their customer account.
More on the measuresThis policy sets out EUSEC's commitment to protecting the information and IT assets entrusted to it — including computers, mobile devices, network equipment, software and sensitive data — against internal, external, deliberate and accidental threats, and to reducing the risks of theft, loss, misuse, damage or abuse of these systems.
Information is protected against unauthorised access. Users may reach only the resources they have been explicitly authorised to use; privileges are tightly controlled and reviewed regularly.
We keep information from being disclosed to unauthorised parties.
We keep information from being altered by unauthorised parties.
We ensure authorised parties can reach the information they need, when business processes require it.
We meet and, wherever possible, exceed national legal and regulatory requirements, standards and good practice.
We continuously improve the information security management system through corrective actions that increase its effectiveness.
We build, maintain and test business continuity plans so we stay on course despite the obstacles we may meet — keeping calm and carrying on.
Security training is available to everyone. Awareness and targeted training run consistently, security responsibilities are reflected in job descriptions, and compliance is an expected and accepted part of our culture.
No action is taken against anyone who raises a security concern — by reporting it or in direct contact with the Information Security Officer — unless the disclosure clearly evidences, beyond reasonable doubt, an unlawful act, gross negligence, or repeated wilful disregard of rules or procedures.
All actual or suspected information security breaches are reported to security@eusec.net or through our incident management procedure.
Non-conformance with this policy may lead to disciplinary action — from informal or formal warnings up to termination of contract.
Any exception requires written authorisation by email from the Information Security Officer and is granted as a time-limited policy waiver.
Anyone covered by this policy may submit complaints about it at any time. Complaints are filed and answered within 14 days of submission.
Requests for exceptions and complaints are addressed to the Information Security Officer at security@eusec.net.
The measures below are organised across the four domains of the international standard. Together they describe how EUSEC governs people, processes, premises and technology to keep information safe.
A documented information security policy, approved by leadership and backed by topic-specific policies, sets the direction for the whole programme and is reviewed at planned intervals and after significant change.
Specific security duties are assigned to named people, so accountability for protecting information and assets — including risk ownership — is always clear.
Leadership actively backs the programme: staff are briefed on their obligations, resourced, trained annually and given a confidential channel to raise concerns.
Conflicting tasks are deliberately split so no single person holds enough access or authority to act unchecked, reducing the risk of error or fraud.
Up-to-date, easy-to-follow procedures for IT operations live in our internal wiki, so work is carried out consistently and securely.
We keep a current register of information and assets together with the people accountable for each, so nothing falls outside management.
Clear rules govern how company information and equipment may be used and handled, and those expectations are communicated to everyone.
Structured offboarding checklists ensure departing staff and partners hand back every company asset they hold.
A documented scheme rates information by sensitivity and business value so it can be handled with appropriate care.
Information carries labels that reflect its classification, making the required level of protection obvious to anyone who handles it.
Data moving inside or outside EUSEC follows defined, secure rules that preserve its confidentiality and integrity.
Records are stored securely with least-privilege access and retained per legal requirements, guarding against loss or tampering.
We respect copyright and licensing, use only properly licensed software, and follow defined rules to protect our own and third-party IP.
A documented policy governs who may reach which systems; network access is limited to authorised people and reviewed regularly.
The full lifecycle of accounts is managed so every user is uniquely identifiable and holds only appropriate rights.
Passwords and other credentials are issued, stored and protected carefully so only legitimate users gain access.
Permissions are granted, adjusted and revoked in step with people's roles, and reviewed periodically.
We maintain a supplier register and work only with partners who meet defined security expectations for handling our data.
Contracts spell out the security requirements and responsibilities of each party, so risk is managed and data stays protected.
Security requirements are set for providers of cloud services, connected devices and hosting, and their compliance is monitored across the chain.
Supplier security is reviewed on a risk-prioritised basis — higher-risk providers at least annually — with issues addressed promptly.
Security considerations, including vendor due diligence, are built into projects from the outset to ensure secure outcomes.
Selecting, using and exiting cloud services follows defined guidance, with clear roles and responsibilities for each service.
We collect and analyse information on emerging threats to anticipate them and make better-informed defensive decisions.
Roles, responsibilities and processes for incidents are defined and documented in advance, so we respond quickly and keep stakeholders informed.
Events are triaged for severity and prioritised, with decisions and supporting detail recorded for later analysis.
Incidents are handled with documented procedures covering containment, evidence handling and clear communication throughout.
Insights from past incidents feed back into stronger controls, better response plans and sharper staff awareness.
Defined procedures govern how evidence is identified, gathered and preserved, so it stays sound for any legal or disciplinary use.
We define when and by whom regulators, supervisory bodies or law enforcement are contacted, and how incidents are reported in good time.
We take part in security communities and advisories to stay current on threats, good practice and new vulnerabilities.
Plans set out how security is maintained when normal operations are disrupted, captured in our continuity and recovery documentation.
Continuity arrangements for IT are defined and tested so systems and data stay available and protected through unexpected events.
We identify and track our legal, regulatory and contractual obligations — DPAs, NDAs, SLAs and more — to remain consistently compliant.
Our security approach and its controls are reviewed independently at planned intervals and after major change — through internal audits and external assessments such as ISO/IEC 27001 — to confirm they remain effective.
We check regularly that day-to-day work complies with our own security policies, standards and procedures, and address any gaps so practice stays aligned with the programme.
Personal data is handled in line with applicable law and contracts under clear privacy notices, with systems that process it kept under close review.
Controls are described at a summary level and mapped to the four domains of ISO/IEC 27001:2022 (Annex A).
Rate up to 10 companies for free — no credit card, no account, zero obligation.