1. Organisation and responsibilities
- Need-to-know and least-privilege principle for access rights.
- Administrative activities only by authorised persons.
- Confidentiality undertaking for persons with access to personal data.
- Documented handling of significant security and operational incidents.
2. Physical access control
- Physical access to data centre and cloud infrastructure is protected by the respective infrastructure providers.
- No publicly accessible physical operation of production servers by end customers.
3. System access control
- Individual user accounts and role-based permissions.
- Strong authentication for administrative access; multi-factor authentication where technically available and appropriate.
- Key-based or comparably secured administrative access.
- Secure session and sign-in procedures.
- No storage of access credentials in publicly accessible source code.
4. Data access control and separation of customer data
- Logical separation of customer data and production customer environments.
- Role- and site-based permissions.
- Server-side authorisation checks.
- Database and infrastructure components not directly publicly reachable where possible.
- Administrative rights limited to the necessary minimum.
5. Transfer and transport control
- TLS/HTTPS for the web application.
- Protected administrative connections.
- Network segmentation between public and internal components.
- Secure or encrypted transfer of backups to external object storage.
6. Logging
- Logging of security- and operations-relevant events.
- Traceability of essential business transactions, as far as provided for by SmartShelf.
- Access to logs only for authorised persons or engaged monitoring service providers.
- Sensitive content is not written to logs unnecessarily, where possible.
7. Availability and backup
- Production-relevant data is backed up daily as scheduled, starting at around 03:00.
- At least 14 daily backups; in addition, weekly and monthly backups in accordance with the Restic retention scheme in force at the time.
- Backups are encrypted with Restic.
- Backups are kept in S3-compatible object storage separate from the primary production environment.
- Access to backups is protected with separate permissions and credentials.
- Recovery procedures are reviewed to an appropriate extent.
- Backups do not replace any statutory archiving obligation of the Client.
8. Protection against malware
- Technical restriction of permitted file types and file sizes, where provided for.
- Malware/virus scanning of uploads, where provided for in the respective process.
- Regular security updates and patch management.
- Reduction of unnecessary publicly reachable services.
9. Application security and development
- Versioned source code management and controlled deployment processes.
- Automated quality and security checks, where set up.
- Separation of development/test and production environments, where operationally provided for.
- Secrets and security-relevant configuration kept outside publicly accessible source code.
- Prioritisation of bug fixes and security updates according to risk.
10. Privacy by default
- Role-based visibility and data minimisation.
- No general use of production customer data for development purposes.
- Technical diagnostic and log data limited to the necessary extent.
- Deletion and export processes after the end of the contract in accordance with the DPA.
11. Incident response
- Recording, assessment and prioritisation of relevant security events.
- Containment and technical remediation of identified incidents.
- Documentation of significant measures and findings.
- Informing the Client without delay of relevant personal data breaches in accordance with the DPA.
12. Sub-processors
- Conclusion of the necessary data protection agreements.
- Review of processing regions and transfer mechanisms.
- Maintenance of an up-to-date list of sub-processors.
- Disclosure of personal data only to the extent necessary.
13. Regular review
- Review of administrative permissions.
- Review of backup and recovery procedures.
- Review of monitoring, patch level and security configurations.
- Adjustment of the TOMs in the event of significant changes to the risk profile or the infrastructure.