Data Security and PII Standards
In enterprise procurement, the first thing buyers ask about today is how you handle personal data. If you can't answer that cleanly, you won't even make the shortlist. We implement standards for data security and the protection of personal data so that you're always ready to give an account.

Our principles
We build data security in from the start, not as an afterthought. At any moment we know where personal data sits, who accesses it, and how long it's stored. And we document it in a way that holds up under an auditor's scrutiny.
- Clear PII mapping: where personal data originates, sits, and flows
- Data minimization and defined retention periods instead of data graveyards
- Encryption in transit and at rest
- Role-based access following the least-privilege principle
- Two-factor requirement for privileged access
- Complete audit logs of all security-relevant actions
- Data storage on EU servers, within the framework of European data protection
- Separate environments with anonymized data in development and staging
How we work
We don't just set these standards up, we make them provable. Technical and organizational measures are documented, responsibilities are clear, and for data processing we provide templates your legal department can sign off directly.
How it fits together
This page describes the standards and principles. You'll find the concrete implementation in the [Enterprise Security Package](enterprise-security-paket.md), and the honest assessment of your data flows in the [GDPR Audit](dsgvo-audit.md).


