Security measures
Technical and organisational measures (TOMs) that protect your data. Every control is reviewed and updated regularly.
At a glance
GDPR, professional secrecy, beA and deployment — what matters to law firms and regulated companies.
GDPR-compliant
Full compliance with the EU General Data Protection Regulation. Processing agreement, TOMs and subprocessor register immediately available.
§43e BRAO compliant
Contractual commitment to legal professional secrecy under §43e BRAO and §203 StGB — binding for every employee and subcontractor.
Native beA integration
Direct connection to the German lawyers' electronic mailbox. Send, receive, archive — all in the same system.
§203 StGB compliant
Commissioned personnel are explicitly bound to secrecy under §203 StGB. A separate confidentiality declaration is available on request.
On-premise available
Optimaite Law can run inside your own infrastructure on request — with the full feature set and no cloud requirement.
Cloud in Germany
Securely operated cloud in German data centres with encryption, tenant separation and clearly documented data flows.
Solo firm to large practice
Scales linearly from the sole practitioner to a 200-lawyer partnership. Same platform, same data, same workflows.
Infrastructure security
12 controlsEncryption in transit
TLS 1.3 for all external and internal connections. HSTS enabled.
Encryption at rest
AES-256 encryption for all stored data (database, object storage, backups).
Network segmentation
Kubernetes cluster with dedicated namespaces and network policies. Workloads are isolated from one another.
Firewall & network protection
Restricted network access. Only required ports are open. Firewall rules are reviewed regularly.
Automated backups
Daily automated database backups with point-in-time recovery. Object storage with versioning.
Intrusion detection
Monitoring of suspicious activity at the infrastructure layer. Automatic alerts on anomalies.
Patch management
Regular updates of infrastructure components. Automated container image updates.
Logging & monitoring
Centralised logging of all system events. Real-time monitoring with alerting.
DDoS protection
Protection against distributed denial-of-service attacks at the network and application layer.
Container security
Minimal base images. No root containers. Security contexts on Kubernetes pods.
Secrets management
Encrypted storage of all credentials and API keys. SOPS-encrypted secrets in version control.
High availability
Multi-node Kubernetes cluster. Automatic pod recovery on failure. Target availability 99.5%.
Access control
8 controlsMulti-tenant isolation
Strict data separation at the database layer. Every query is automatically filtered to the respective tenant.
JWT authentication
Token-based authentication with tenant scoping. Tokens have a limited lifetime.
Role-based access control
RBAC system with configurable roles and permissions. Principle of least privilege.
SSH-key infrastructure access
No password login on servers. SSH-key authentication only for administrators.
Access revocation on offboarding
Immediate revocation of all access rights when someone leaves. Documented offboarding process.
API key management
Secure generation and rotation of API keys. No hardcoded credentials.
Session management
Automatic session timeout. Secure session tokens with HttpOnly and Secure flags.
BFF proxy architecture
Tokens are never exposed to the browser. A backend-for-frontend proxy injects authentication server-side.
Data protection & privacy
10 controlsEU data residency
All application data is processed and stored exclusively in the EU (Germany).
Data minimisation
Only the data required for the respective processing purpose is collected and processed.
Deletion at end of contract
30-day export window, then complete deletion of all customer data. Backups purged within 90 days.
Data classification
Documented policies for classifying personal and confidential data.
Retention policies
Defined retention periods for different data categories. Automatic clean-up.
AI zero-retention
Contractual agreements with AI providers: no storage, no training on customer data.
Pseudonymisation in logs
Technical IDs instead of names in logs. No directly identifying data in error reports.
Right to data portability
Export of all customer data in common, machine-readable formats at any time.
Data processing agreement
Standardised processing agreement under Art. 28 GDPR, automatically part of the terms of service.
Subprocessor transparency
Publicly visible list of all subprocessors with advance notice of changes.
Organisational security
9 controlsConfidentiality agreements
All employees and contractors sign confidentiality agreements (NDAs).
Security training
Regular data protection and security training for all employees.
Incident response plan
Documented plan with defined escalation levels. Customer notification within 24 hours.
Disaster recovery
Documented recovery plans. Regular testing of backup-restore procedures.
Change management
Code reviews, automated tests and staged deployment (staging → production).
Secure development (SDLC)
Security by design. Dependency scanning. Automated security tests in the CI/CD pipeline.
Vendor management
Careful selection and regular review of all third-party providers. Contractual data protection obligations.
Documentation
Complete documentation of all processing activities, policies and procedures.
Physical security
Data centres with ISO 27001 certification. Access control, video surveillance, fire protection.
Questions about the TOMs?
We are happy to walk through controls, the DPA and deployment options with you. security@optimaite.eu
14 Tage kostenlos testen · Keine Kreditkarte · DSGVO-konform