Legal Data Tech

Trust is earned through control — not promises.

Our customers include insurance companies, corporate law firms and large enterprises. DEPLAW is a certified, repeatedly audited legal-tech platform – used daily in highly regulated industries.

TÜV-certified

Passed a full penetration test – audited by TÜV Rheinland i-sec GmbH.

Audited multiple times

Successfully reviewed by German and international insurance companies.

100% Germany

Development, hosting and data processing exclusively in Germany.

Proven IT security

Audited by an independent authority.

DEPLAW underwent a comprehensive penetration test and passed it successfully. The audit was carried out by TÜV Rheinland i-sec GmbH as an independent, recognized authority. The focus:

  • Access protection and permissions model
  • Web application security
  • Protection of sensitive data
  • Resilience against common attack vectors
Penetration testPassed
Auditor
TÜV Rheinland i-sec GmbH
Type
Comprehensive penetration test
Scope
Entire platform
Compliance
GDPR · BDSG · AI Act

Proven in enterprise environments

Every regulatory requirement — met.

Our software has been audited multiple times as part of onboarding and risk assessments by German and international insurance companies – suitable for use even in highly sensitive business areas.

StandardDescriptionStatus
GDPREU General Data Protection RegulationMet
BDSGGerman Federal Data Protection ActMet
AI ActEU regulation on artificial intelligenceMet
§ 43e BRAOConfidentiality of engaged service providers (law firms)Contractually secured
ISO 27001Hosting infrastructure (Deutsche Telekom OTC)Certified
SOC 2 Type IIHosting infrastructure (Deutsche Telekom OTC)Certified
TÜV penetration testTÜV Rheinland i-sec GmbHPassed
Insurer auditsOnboarding and risk assessmentsPassed
External DPO reviewExternal data protection officerRegular

Servers & Development

Data sovereignty as a decision criterion.

Operated on Deutsche Telekom (OTC) servers – comprehensively audited and certified to, among others, ISO 27001 and SOC 2 Type II. All data processing is subject to German law, European data protection standards, and in particular the GDPR. No critical components are outsourced to third countries, and there is no dependency on non-European cloud providers – complex cross-border data protection reviews are eliminated entirely.

For elevated security and compliance requirements, the platform can be run on your own servers – on a scalable Kubernetes cluster. That means full control over all data, clear accountability and easy integration into existing security frameworks.

The platform is developed entirely in Germany and runs exclusively on servers located in Germany. Every line of code, every development step happens in Germany – no offshore or nearshore development, and therefore no exposure of the IT systems to other countries.

Hidden dependencies on third-party software, plug-ins or external platform services are an often underestimated risk. Our platform is built entirely in-house – with no critical dependencies on third-party vendors and no external core components. That reduces security risks, update dependencies and compliance complexity, and creates long-term technical stability.

We continuously and automatically check for available security updates to software components, so that any discovered vulnerabilities are closed as quickly as possible. DEPLAW is continuously developed further to respond to new threats and attack vectors and to protect sensitive case data as effectively as possible.

For law firms

§ 43e BRAO: confidentiality — down to the last subcontractor.

Any lawyer engaging an IT provider must, under § 43e BRAO, select them carefully, bind them in writing to confidentiality, and inform them of the criminal confidentiality obligation under § 203 of the German Criminal Code (StGB) — while also ensuring that their subcontractors are bound as well. DEPLAW delivers these building blocks as standard, instead of leaving them to the law firm.

§ 43e Abs. 3 BRAO

Written confidentiality commitment

Everyone and every system that comes into contact with client and case data is provably bound to confidentiality in writing — documented and included as part of the data processing agreement (DPA).

§ 203 StGB

Notice of the confidentiality obligation

Everyone bound is explicitly informed of the criminal confidentiality obligation under § 203 StGB. This keeps attorney-client confidentiality airtight even when external technology is used.

Selection & oversight duty

Subcontractor list

A complete, up-to-date list of every subcontractor in use — with purpose, location (EU/Germany) and proof of their confidentiality commitment. That lets you meet your selection and oversight duty without follow-up questions.

We document this entire chain in full — from the first commitment down to the last subcontractor. You receive the confidentiality declaration, the notice and the subcontractor list as part of the DPA.

For insurers

Recourse review and § 32 VAG.

For insurers commissioning DEPLAW to run recourse reviews on their claims files, this is also relevant: data processing exclusively within the EU, no data shared with external AI providers, and — in our assessment — typically no outsourcing within the meaning of § 32 VAG.

Security & outsourcing for insurers in detail →

Review our security concept in detail.

In the demo, we'll walk through audit documentation, the hosting model and data protection together.

Book a free demo