Security & Data Protection
How we handle your data and systems – concrete, without exaggeration.
What we actually do
- Multi-factor authentication and single sign-on for our internal systems
- Encrypted work devices
- Code reviews before changes to client projects
- Automated scanning of dependencies for known vulnerabilities
- Access to client systems only for the people on the project
Data protection
- For projects involving personal data, we sign a data processing agreement.
- We prefer hosting in the EU. Which services are used is decided per project and agreed with you.
- Please send data protection questions to [email protected].
How we process data on this website is described in our Privacy Policy
Experience with ISO 27001 and DORA
As CTO of NetCero, Michael Jauk led its ISO 27001 certification and knows the DORA requirements for ICT service providers from supplier audits by financial companies. We bring this experience into client projects – for example when completing security questionnaires.
Report a vulnerability
If you find a vulnerability in one of our systems, please write to [email protected].
FAQ
Security & data protection
Does dectria sign a data processing agreement?
Yes, for all projects in which we process personal data on your behalf – for example in hosting, operations or support with access to real data. If you bring your own template, we are happy to work with it.
Where is our data hosted?
We prefer hosting in the EU, for example at Hetzner in Germany or in European regions of Azure and Render. Which services are used is decided per project and agreed with you before any data flows.
Does dectria complete security and supplier questionnaires?
Yes, on request. Banks, energy providers and public clients regularly review their service providers – we answer these questionnaires and provide the necessary information about our measures.
Every project starts with a conversation.