PROBIS Software GmbH operates an information security management system that is certified to ISO/IEC 27001:2022. The security controls are also aligned with the SOC 2 Trust Services criteria and cover every system that processes financial and construction cost data in the real estate industry.
Independently tested and certified.
PROBIS does not currently have an independent SOC 2 Type I or Type II audit report.
Each piece of information below is taken from our current ISO certificate and reflects our actual SOC 2 status.
A simple explanation of exactly what our ISO 27001 certification and our SOC 2-aligned controls cover.
Role-based permissions and multi-factor authentication for every account with access to customer financial data.
Data is encrypted at all levels of the platform, both in transit (TLS 1.3) and at rest (AES-256).
Every access to and every change made to sensitive data records is logged and retained for independent audit purposes.
Documented procedures for detecting, escalating, and notifying customers in the event of any security incident.
Tested backup and recovery plans to ensure that customer data remains available even in the event of disruptions.
Every subcontractor and supplier is evaluated according to the same security standards that we hold ourselves to.
The NIS2 Directive sets out requirements for cybersecurity risk management and incident reporting for essential and important facilities in affected sectors. NIS2 is not a certification of a company or product; its legal classification depends on the respective national implementation, the company’s activities, size, and industry.
For customers subject to NIS2, PROBIS can provide relevant information on supplier assessment to support their own risk assessment and supply chain management. This support does not transfer the customer’s legal obligations and does not guarantee NIS2 compliance.
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires regulated financial firms to manage third-party ICT risks and to include appropriate contractual provisions for ICT services. When PROBIS provides ICT services to a financial firm, PROBIS supports that firm as a third-party ICT service provider under the respective DORA agreement.
Whether a particular PROBIS service supports a critical or important function is assessed by each financial institution in the context of its own business operations—PROBIS does not make this assessment on behalf of the customer.