The questions your IT and your customers ask, answered in advance.
- 0
- US providers for hosting, e-mail and customer data in your project
- 24 h
- early warning under NIS2 Art. 23 – the process is prepared
- ISO 27001
- certified data centre in Germany
- VS-NfD
- possible without industrial security clearance
01CLOUD ACTHosted in Germany, with no US parent.HetznerGermanyISO 27001
No US group behind it, so no access through the CLOUD Act. The data centres are in Falkenstein and Nuremberg.
- CERTIFICATION
- ISO/IEC 27001 (source, opens in a new tab)
02NIS2 · NISG 2026Ready to report under NIS2 and NISG 2026.24 h early warning72 h notificationNIS2 Art. 23
Logs, responsibilities and reporting deadlines under NIS2 and Austria's NISG 2026 are prepared.
- SECURITY HEADERS
- HSTS, CSP, frame and MIME protection, referrer and permissions policy on every response – on this website too
- RATE LIMITING
- on login, forms and document downloads
- LOGGING
- access and approvals, tamper-evident
- RESPONSIBILITIES
- named per project, with response time
03SECURITY CLEARANCEUp to VS-NfD, no clearance needed.VS-NfDBMWK sheetInfoSiG (AT)
Up to RESTRICTED (VS-NfD) no industrial security clearance is needed. From CONFIDENTIAL (VS-VERTRAULICH) your contracting authority applies for it.
- UP TO VS-NFD
- no industrial security clearance needed. Whether VS-NfD documents may go into the portal is decided by your security officer under the information sheet – we deliver the technical measures
- FROM VS-VERTRAULICH
- your contracting authority applies, with several months' lead time; we are brought in through you as a subcontractor
- AUSTRIA
- EINGESCHRÄNKT / VERTRAULICH under the InfoSiG, applied accordingly
04EXPORT CONTROLTechnical documents are not open on the web.Dual-Use Reg. 2021/821Country checkSanctions lists
Only vetted organisations from permitted countries see them – by invitation, after a country check, with an audit log.
- ACCESS
- invitation, organisation, country, time limit, revocation
- COUNTRY CHECK
- block and warning notices before every approval, geo-blocking by country embargo, screening against sanctions lists
- CLASSIFICATION
- rests with your export control – we implement the logic and document it
05ACCESSIBILITY (BFSG)Accessibility only where it applies.BFSG § 1BaFGWCAG 2.1 AA
Accessibility under BFSG (DE) and BaFG (AT) applies only where you sell to consumers. Dealer and government areas are exempt.
- SCOPE
- products and services for consumers; pure dealer and government areas exempt
- IMPLEMENTATION
- end-customer areas to WCAG 2.1 AA; with no consumer business the work is dropped and costs you nothing
06DATA PROCESSINGYour data stays in the EU.EU providersCookie-freeProcessor list
Every project has a short list of processors. Everything that carries customer and product data stays in the EU.
- HOSTING
- Hetzner Online GmbH (DE)
- REACH MEASUREMENT
- cookie-free, self-hosted or EU provider
- E-MAIL DELIVERY
- SMTP from our own server or an EU provider
- US PROVIDERS
- none for hosting, e-mail and customer data; fonts are served from our own server
Frequently asked questions
01Is the hosting subject to the US CLOUD Act?
No, the hosting is not exposed to the US CLOUD Act through a parent company. We host with Hetzner Online GmbH in Gunzenhausen, which has no US parent (HRB 6089, Ansbach), data centres in Falkenstein and Nuremberg, and ISO/IEC 27001. What matters is not where the server stands but who can reach the operator.
→ MODULE 1302What is prepared for NIS2 and NISG 2026?
For NIS2 and NISG 2026, the technology, logs and responsibilities are in place: security headers on every response, rate limiting on login, forms and downloads, and audit-proof logging. The reporting path under NIS2 Art. 23 is ready – early warning within 24 hours, incident notification within 72 hours.
→ MODULE 1303Does Geffen Schwarz need an industrial security clearance?
Up to VS-NfD, Geffen Schwarz needs no industrial security clearance. Whether VS-NfD documents may pass through the portal is decided by your security officer under the BMWK guidance; we supply the technical measures. From VS-VERTRAULICH, your client applies for the clearance and we are brought in as your subcontractor. In Austria the same applies under the InfoSiG.
→ COMPLIANCE04How is export control implemented for technical documents?
Export control is implemented through access: by invitation only, with organisation, country, time limit and revocation. Before every release, country screening, embargo blocking and a sanctions-list check run. The basis is EU Dual-Use Regulation 2021/821, the German AWG/AWV, the Austrian AußWG 2011 and the BAFA guidance on technology transfer.
→ MODULE 0805Who decides which document is access-restricted?
Your export control decides which document is access-restricted. We implement and document the release logic.
→ MODULE 0806Does the website have to be accessible?
The website only has to be accessible where you sell to consumers. BFSG (DE) and BaFG (AT) apply to consumer offerings since 28 June 2025; pure dealer and government areas are exempt. We build consumer areas to WCAG 2.1 AA.
→ MODULE 0207Which processors are involved in a project?
Few processors are involved in a project, and every one that carries customer or product data is in the EU. Hosting with Hetzner (DE), cookieless analytics self-hosted or with an EU provider, email from our own server or an EU provider. We use no US providers for hosting, email or customer data.
→ COMPLIANCE08Is it logged who downloaded a document?
Yes, every download from the restricted area is logged. The file carries a watermark with name, organisation and time, created at the moment of download. You are notified and see access by country and organisation – the way export control and auditors require.
→ MODULE 09