Trust is earned through control — not promises.
Our customers include insurance companies, corporate law firms and large enterprises. DEPLAW is a certified, repeatedly audited legal-tech platform – used daily in highly regulated industries.
TÜV-certified
Passed a full penetration test – audited by TÜV Rheinland i-sec GmbH.
Audited multiple times
Successfully reviewed by German and international insurance companies.
100% Germany
Development, hosting and data processing exclusively in Germany.
Proven IT security
Audited by an independent authority.
DEPLAW underwent a comprehensive penetration test and passed it successfully. The audit was carried out by TÜV Rheinland i-sec GmbH as an independent, recognized authority. The focus:
- Access protection and permissions model
- Web application security
- Protection of sensitive data
- Resilience against common attack vectors
- Auditor
- TÜV Rheinland i-sec GmbH
- Type
- Comprehensive penetration test
- Scope
- Entire platform
- Compliance
- GDPR · BDSG · AI Act
Proven in enterprise environments
Every regulatory requirement — met.
Our software has been audited multiple times as part of onboarding and risk assessments by German and international insurance companies – suitable for use even in highly sensitive business areas.
| Standard | Description | Status |
|---|---|---|
| GDPR | EU General Data Protection Regulation | Met |
| BDSG | German Federal Data Protection Act | Met |
| AI Act | EU regulation on artificial intelligence | Met |
| § 43e BRAO | Confidentiality of engaged service providers (law firms) | Contractually secured |
| ISO 27001 | Hosting infrastructure (Deutsche Telekom OTC) | Certified |
| SOC 2 Type II | Hosting infrastructure (Deutsche Telekom OTC) | Certified |
| TÜV penetration test | TÜV Rheinland i-sec GmbH | Passed |
| Insurer audits | Onboarding and risk assessments | Passed |
| External DPO review | External data protection officer | Regular |
Servers & Development
Data sovereignty as a decision criterion.
Operated on Deutsche Telekom (OTC) servers – comprehensively audited and certified to, among others, ISO 27001 and SOC 2 Type II. All data processing is subject to German law, European data protection standards, and in particular the GDPR. No critical components are outsourced to third countries, and there is no dependency on non-European cloud providers – complex cross-border data protection reviews are eliminated entirely.
For elevated security and compliance requirements, the platform can be run on your own servers – on a scalable Kubernetes cluster. That means full control over all data, clear accountability and easy integration into existing security frameworks.
The platform is developed entirely in Germany and runs exclusively on servers located in Germany. Every line of code, every development step happens in Germany – no offshore or nearshore development, and therefore no exposure of the IT systems to other countries.
Hidden dependencies on third-party software, plug-ins or external platform services are an often underestimated risk. Our platform is built entirely in-house – with no critical dependencies on third-party vendors and no external core components. That reduces security risks, update dependencies and compliance complexity, and creates long-term technical stability.
We continuously and automatically check for available security updates to software components, so that any discovered vulnerabilities are closed as quickly as possible. DEPLAW is continuously developed further to respond to new threats and attack vectors and to protect sensitive case data as effectively as possible.
For law firms
§ 43e BRAO: confidentiality — down to the last subcontractor.
Any lawyer engaging an IT provider must, under § 43e BRAO, select them carefully, bind them in writing to confidentiality, and inform them of the criminal confidentiality obligation under § 203 of the German Criminal Code (StGB) — while also ensuring that their subcontractors are bound as well. DEPLAW delivers these building blocks as standard, instead of leaving them to the law firm.
Written confidentiality commitment
Everyone and every system that comes into contact with client and case data is provably bound to confidentiality in writing — documented and included as part of the data processing agreement (DPA).
Notice of the confidentiality obligation
Everyone bound is explicitly informed of the criminal confidentiality obligation under § 203 StGB. This keeps attorney-client confidentiality airtight even when external technology is used.
Subcontractor list
A complete, up-to-date list of every subcontractor in use — with purpose, location (EU/Germany) and proof of their confidentiality commitment. That lets you meet your selection and oversight duty without follow-up questions.
We document this entire chain in full — from the first commitment down to the last subcontractor. You receive the confidentiality declaration, the notice and the subcontractor list as part of the DPA.
For insurers
Recourse review and § 32 VAG.
For insurers commissioning DEPLAW to run recourse reviews on their claims files, this is also relevant: data processing exclusively within the EU, no data shared with external AI providers, and — in our assessment — typically no outsourcing within the meaning of § 32 VAG.
Security & outsourcing for insurers in detail →Review our security concept in detail.
In the demo, we'll walk through audit documentation, the hosting model and data protection together.
Book a free demo