Skip to content
GEFFEN SCHWARZ
DEBook

The questions your IT and your customers ask, answered in advance.

0
US providers for hosting, e-mail and customer data in your project
24 h
early warning under NIS2 Art. 23 – the process is prepared
ISO 27001
certified data centre in Germany
VS-NfD
possible without industrial security clearance
  1. 01CLOUD ACTHosted in Germany, with no US parent.HetznerGermanyISO 27001
  2. 02NIS2 · NISG 2026Ready to report under NIS2 and NISG 2026.24 h early warning72 h notificationNIS2 Art. 23

    Logs, responsibilities and reporting deadlines under NIS2 and Austria's NISG 2026 are prepared.

    SECURITY HEADERS
    HSTS, CSP, frame and MIME protection, referrer and permissions policy on every response – on this website too
    RATE LIMITING
    on login, forms and document downloads
    LOGGING
    access and approvals, tamper-evident
    RESPONSIBILITIES
    named per project, with response time
    EVIDENCE 03 · LIST OF MEASURES · MODULE 13
  3. 03SECURITY CLEARANCEUp to VS-NfD, no clearance needed.VS-NfDBMWK sheetInfoSiG (AT)

    Up to RESTRICTED (VS-NfD) no industrial security clearance is needed. From CONFIDENTIAL (VS-VERTRAULICH) your contracting authority applies for it.

    UP TO VS-NFD
    no industrial security clearance needed. Whether VS-NfD documents may go into the portal is decided by your security officer under the information sheet – we deliver the technical measures
    FROM VS-VERTRAULICH
    your contracting authority applies, with several months' lead time; we are brought in through you as a subcontractor
    AUSTRIA
    EINGESCHRÄNKT / VERTRAULICH under the InfoSiG, applied accordingly
    EVIDENCE 04 · SECURITY CLEARANCE PROCESS · BMWK, LINKED
  4. 04EXPORT CONTROLTechnical documents are not open on the web.Dual-Use Reg. 2021/821Country checkSanctions lists

    Only vetted organisations from permitted countries see them – by invitation, after a country check, with an audit log.

    ACCESS
    invitation, organisation, country, time limit, revocation
    COUNTRY CHECK
    block and warning notices before every approval, geo-blocking by country embargo, screening against sanctions lists
    CLASSIFICATION
    rests with your export control – we implement the logic and document it
    EVIDENCE 05 · APPROVAL LOGIC · MODULE 08
  5. 05ACCESSIBILITY (BFSG)Accessibility only where it applies.BFSG § 1BaFGWCAG 2.1 AA

    Accessibility under BFSG (DE) and BaFG (AT) applies only where you sell to consumers. Dealer and government areas are exempt.

    SCOPE
    products and services for consumers; pure dealer and government areas exempt
    IMPLEMENTATION
    end-customer areas to WCAG 2.1 AA; with no consumer business the work is dropped and costs you nothing
    EVIDENCE 06 · BFSG / BAFG SINCE 28.06.2025
  6. 06DATA PROCESSINGYour data stays in the EU.EU providersCookie-freeProcessor list

    Every project has a short list of processors. Everything that carries customer and product data stays in the EU.

    HOSTING
    Hetzner Online GmbH (DE)
    REACH MEASUREMENT
    cookie-free, self-hosted or EU provider
    E-MAIL DELIVERY
    SMTP from our own server or an EU provider
    US PROVIDERS
    none for hosting, e-mail and customer data; fonts are served from our own server
    EVIDENCE 07 · PROCESSORS, STANDARD PER PROJECT

Frequently asked questions

  1. 01Is the hosting subject to the US CLOUD Act?

    No, the hosting is not exposed to the US CLOUD Act through a parent company. We host with Hetzner Online GmbH in Gunzenhausen, which has no US parent (HRB 6089, Ansbach), data centres in Falkenstein and Nuremberg, and ISO/IEC 27001. What matters is not where the server stands but who can reach the operator.

    → MODULE 13
  2. 02What is prepared for NIS2 and NISG 2026?

    For NIS2 and NISG 2026, the technology, logs and responsibilities are in place: security headers on every response, rate limiting on login, forms and downloads, and audit-proof logging. The reporting path under NIS2 Art. 23 is ready – early warning within 24 hours, incident notification within 72 hours.

    → MODULE 13
  3. 03Does Geffen Schwarz need an industrial security clearance?

    Up to VS-NfD, Geffen Schwarz needs no industrial security clearance. Whether VS-NfD documents may pass through the portal is decided by your security officer under the BMWK guidance; we supply the technical measures. From VS-VERTRAULICH, your client applies for the clearance and we are brought in as your subcontractor. In Austria the same applies under the InfoSiG.

    → COMPLIANCE
  4. 04How is export control implemented for technical documents?

    Export control is implemented through access: by invitation only, with organisation, country, time limit and revocation. Before every release, country screening, embargo blocking and a sanctions-list check run. The basis is EU Dual-Use Regulation 2021/821, the German AWG/AWV, the Austrian AußWG 2011 and the BAFA guidance on technology transfer.

    → MODULE 08
  5. 05Who decides which document is access-restricted?

    Your export control decides which document is access-restricted. We implement and document the release logic.

    → MODULE 08
  6. 06Does the website have to be accessible?

    The website only has to be accessible where you sell to consumers. BFSG (DE) and BaFG (AT) apply to consumer offerings since 28 June 2025; pure dealer and government areas are exempt. We build consumer areas to WCAG 2.1 AA.

    → MODULE 02
  7. 07Which processors are involved in a project?

    Few processors are involved in a project, and every one that carries customer or product data is in the EU. Hosting with Hetzner (DE), cookieless analytics self-hosted or with an EU provider, email from our own server or an EU provider. We use no US providers for hosting, email or customer data.

    → COMPLIANCE
  8. 08Is it logged who downloaded a document?

    Yes, every download from the restricted area is logged. The file carries a watermark with name, organisation and time, created at the moment of download. You are notified and see access by country and organisation – the way export control and auditors require.

    → MODULE 09