ISO/IEC 27001 certified

Security you can verify,not just take our word for.

PROBIS Software GmbH operates an information security management system that is certified to ISO/IEC 27001:2022. The security controls are also aligned with the SOC 2 Trust Services criteria and cover every system that processes financial and construction cost data in the real estate industry.

● Active
ISO/IEC 27001:2022

Information Security
-Management System

Independently tested and certified.

CERT. NO. 122943 (Issue 1)VALID THROUGH 08/2028
Download Certificate
● Aligned
SOC 2 TRUST SERVICES CRITERIA

Security, Availability, and Confidentiality

PROBIS does not currently have an independent SOC 2 Type I or Type II audit report.

Available upon request under an NDA
Request Documentation
Certification Report

The details, for the record.

Each piece of information below is taken from our current ISO certificate and reflects our actual SOC 2 status.

iso27001_record.log
certificate_number122943 (Issue 1)
standardISO/IEC 27001:2022
issuing_bodyPrescient Security LLC (Certification Body), accredited by IAS (International Accreditation Service), a member of the Multilateral Recognition Arrangement (IAF)
scopeISO/IEC 27001:2022 for the cloud-based real estate project management platform of PROBIS Software GmbH, including the production infrastructure on Microsoft Azure (West Europe) as well as all processing, storage, and transmission of customer data.
issue_date September 1, 2025
expiry_date August 31, 2028
soc2_position.log
compliance_statusAudits conducted – no independent audit report available
frameworkAICPA SOC 2 Trust Services Criteria
availabilityAvailable upon request under an NDA
Here's how it's implemented

Certification is proof. That's how it works in practice.

A simple explanation of exactly what our ISO 27001 certification and our SOC 2-aligned controls cover.

Access Control

Role-based permissions and multi-factor authentication for every account with access to customer financial data.

Cryptography

Data is encrypted at all levels of the platform, both in transit (TLS 1.3) and at rest (AES-256).

Audit Logging

Every access to and every change made to sensitive data records is logged and retained for independent audit purposes.

Incident Management

Documented procedures for detecting, escalating, and notifying customers in the event of any security incident.

Business Continuity

Tested backup and recovery plans to ensure that customer data remains available even in the event of disruptions.

Supplier Relationships

Every subcontractor and supplier is evaluated according to the same security standards that we hold ourselves to.

Regulatory Classification

Support for NIS2 Cybersecurity Requirements

No certification

The NIS2 Directive sets out requirements for cybersecurity risk management and incident reporting for essential and important facilities in affected sectors. NIS2 is not a certification of a company or product; its legal classification depends on the respective national implementation, the company’s activities, size, and industry.

For customers subject to NIS2, PROBIS can provide relevant information on supplier assessment to support their own risk assessment and supply chain management. This support does not transfer the customer’s legal obligations and does not guarantee NIS2 compliance.

  • Cybersecurity Risk Management & Security Policies
  • Incident Handling & Escalation
  • Business Continuity, Crisis Management & Recovery
  • Supply Chain & Supplier Security
  • Reliable Procurement, Development, and Maintenance
  • Vulnerability Management & Disclosure Processes
  • Access Control, Authentication, and Asset Management
  • Cryptography & Data Protection
Regulatory Classification

DORA Support for Clients in the Financial Sector

No certification

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires regulated financial firms to manage third-party ICT risks and to include appropriate contractual provisions for ICT services. When PROBIS provides ICT services to a financial firm, PROBIS supports that firm as a third-party ICT service provider under the respective DORA agreement.

Whether a particular PROBIS service supports a critical or important function is assessed by each financial institution in the context of its own business operations—PROBIS does not make this assessment on behalf of the customer.

Current Status: PROBIS is not currently designated by the European supervisory authorities as a critical third-party ICT provider (CTPP). This statement is reviewed each time the official CTPP list is updated. (Last reviewed: August 13, 2026)
  • Clear description of contractual obligations and service levels
  • Information on Processing and Storage Locations
  • Disclosure of Subcontractor Agreements
  • Security Measures for Availability, Integrity, and Confidentiality
  • Backup, Recovery, Return, and Deletion Policies
  • Incident Reporting & Support Processes
  • Information on Business Continuity & Exit Support
  • Audit, Access, and Review Rights
✉️

Do you conduct supplier due diligence?

Our security team will be happy to explain our certification, architecture, and controls to you directly.

Contact our security team