Optimaite
39 controls

Security measures

Technical and organisational measures (TOMs) that protect your data. Every control is reviewed and updated regularly.

Compliance

At a glance

GDPR, professional secrecy, beA and deployment — what matters to law firms and regulated companies.

GDPR-compliant

Full compliance with the EU General Data Protection Regulation. Processing agreement, TOMs and subprocessor register immediately available.

§43e BRAO compliant

Contractual commitment to legal professional secrecy under §43e BRAO and §203 StGB — binding for every employee and subcontractor.

Native beA integration

Direct connection to the German lawyers' electronic mailbox. Send, receive, archive — all in the same system.

§203 StGB compliant

Commissioned personnel are explicitly bound to secrecy under §203 StGB. A separate confidentiality declaration is available on request.

On-premise available

Optimaite Law can run inside your own infrastructure on request — with the full feature set and no cloud requirement.

Cloud in Germany

Securely operated cloud in German data centres with encryption, tenant separation and clearly documented data flows.

Solo firm to large practice

Scales linearly from the sole practitioner to a 200-lawyer partnership. Same platform, same data, same workflows.

Infrastructure security

12 controls

Encryption in transit

TLS 1.3 for all external and internal connections. HSTS enabled.

Encryption at rest

AES-256 encryption for all stored data (database, object storage, backups).

Network segmentation

Kubernetes cluster with dedicated namespaces and network policies. Workloads are isolated from one another.

Firewall & network protection

Restricted network access. Only required ports are open. Firewall rules are reviewed regularly.

Automated backups

Daily automated database backups with point-in-time recovery. Object storage with versioning.

Intrusion detection

Monitoring of suspicious activity at the infrastructure layer. Automatic alerts on anomalies.

Patch management

Regular updates of infrastructure components. Automated container image updates.

Logging & monitoring

Centralised logging of all system events. Real-time monitoring with alerting.

DDoS protection

Protection against distributed denial-of-service attacks at the network and application layer.

Container security

Minimal base images. No root containers. Security contexts on Kubernetes pods.

Secrets management

Encrypted storage of all credentials and API keys. SOPS-encrypted secrets in version control.

High availability

Multi-node Kubernetes cluster. Automatic pod recovery on failure. Target availability 99.5%.

Access control

8 controls

Multi-tenant isolation

Strict data separation at the database layer. Every query is automatically filtered to the respective tenant.

JWT authentication

Token-based authentication with tenant scoping. Tokens have a limited lifetime.

Role-based access control

RBAC system with configurable roles and permissions. Principle of least privilege.

SSH-key infrastructure access

No password login on servers. SSH-key authentication only for administrators.

Access revocation on offboarding

Immediate revocation of all access rights when someone leaves. Documented offboarding process.

API key management

Secure generation and rotation of API keys. No hardcoded credentials.

Session management

Automatic session timeout. Secure session tokens with HttpOnly and Secure flags.

BFF proxy architecture

Tokens are never exposed to the browser. A backend-for-frontend proxy injects authentication server-side.

Data protection & privacy

10 controls

EU data residency

All application data is processed and stored exclusively in the EU (Germany).

Data minimisation

Only the data required for the respective processing purpose is collected and processed.

Deletion at end of contract

30-day export window, then complete deletion of all customer data. Backups purged within 90 days.

Data classification

Documented policies for classifying personal and confidential data.

Retention policies

Defined retention periods for different data categories. Automatic clean-up.

AI zero-retention

Contractual agreements with AI providers: no storage, no training on customer data.

Pseudonymisation in logs

Technical IDs instead of names in logs. No directly identifying data in error reports.

Right to data portability

Export of all customer data in common, machine-readable formats at any time.

Data processing agreement

Standardised processing agreement under Art. 28 GDPR, automatically part of the terms of service.

Subprocessor transparency

Publicly visible list of all subprocessors with advance notice of changes.

Organisational security

9 controls

Confidentiality agreements

All employees and contractors sign confidentiality agreements (NDAs).

Security training

Regular data protection and security training for all employees.

Incident response plan

Documented plan with defined escalation levels. Customer notification within 24 hours.

Disaster recovery

Documented recovery plans. Regular testing of backup-restore procedures.

Change management

Code reviews, automated tests and staged deployment (staging → production).

Secure development (SDLC)

Security by design. Dependency scanning. Automated security tests in the CI/CD pipeline.

Vendor management

Careful selection and regular review of all third-party providers. Contractual data protection obligations.

Documentation

Complete documentation of all processing activities, policies and procedures.

Physical security

Data centres with ISO 27001 certification. Access control, video surveillance, fire protection.

Security

Questions about the TOMs?

We are happy to walk through controls, the DPA and deployment options with you. security@optimaite.eu

14 Tage kostenlos testen · Keine Kreditkarte · DSGVO-konform