Trust is earned through control — not promises.
Our customers include insurance companies, corporate law firms and large enterprises. DEPLAW is a certified, repeatedly audited legal-tech platform – used daily in highly regulated industries.
TÜV-certified
Passed a full penetration test – audited by TÜV Rheinland i-sec GmbH.
Audited multiple times
Successfully reviewed by German and international insurance companies.
100% Germany
Development, hosting and data processing exclusively in Germany.
Proven IT security
Audited by an independent authority.
DEPLAW underwent a comprehensive penetration test and passed it successfully. The audit was carried out by TÜV Rheinland i-sec GmbH as an independent, recognized authority. The focus:
- Access protection and permissions model
- Web application security
- Protection of sensitive data
- Resilience against common attack vectors
- Auditor
- TÜV Rheinland i-sec GmbH
- Type
- Comprehensive penetration test
- Scope
- Entire platform
- Compliance
- GDPR · BDSG · AI Act
Proven in enterprise environments
Every regulatory requirement — met.
Our software has been audited multiple times as part of onboarding and risk assessments by German and international insurance companies – suitable for use even in highly sensitive business areas.
Beyond the external certifications and audits below, we operate our own information security management system (ISMS), aligned with ISO/IEC 27001:2022, with documented risk management, a named information security officer and an annual management review.
| Standard | Description | Status |
|---|---|---|
| GDPR | EU General Data Protection Regulation | Met |
| BDSG | German Federal Data Protection Act | Met |
| AI Act | EU regulation on artificial intelligence | Met |
| § 43e BRAO | Confidentiality of engaged service providers (law firms) | Contractually secured |
| ISO 27001 | Hosting infrastructure (Deutsche Telekom OTC) | Certified |
| SOC 2 Type II | Hosting infrastructure (Deutsche Telekom OTC) | Certified |
| TÜV penetration test | TÜV Rheinland i-sec GmbH | Passed |
| Insurer audits | Onboarding and risk assessments | Passed |
| External DPO review | External data protection officer | Regular |
German regulatory practice, not global generics
Certificates are standard. Regulatory practice is the difference.
International legal-AI platforms mostly advertise global certifications like SOC 2 or ISO 27001 — important, but industry-agnostic evidence. For the German insurance and law-firm market, the concrete regulatory classification matters just as much:
| Criterion | International platform | DEPLAW |
|---|---|---|
| Data location | Often globally distributed infrastructure, partly outside the EU | Exclusively Germany/EU |
| Regulatory law for insurers | General SOC 2/ISO certification, globally oriented | DORA (Art. 28–30) & § 32 VAG publicly assessed |
| Professional law for law firms | Cross-industry, not BRAO-specific | § 43e BRAO specifically documented, incl. subcontractor list |
| Point of contact | International support organization | German-speaking team, direct contact to the information security and data protection officers |
For insurers
DORA, BaFin and § 32 VAG.
For insurers commissioning DEPLAW to review and assess their claims files, this is also relevant: data processing exclusively within the EU, no data shared with external AI providers, evidence aligned with Art. 28–30 DORA, and — in our assessment — typically no outsourcing within the meaning of § 32 VAG.
DORA, BaFin & § 32 VAG in detail →Servers & Development
Data sovereignty as a decision criterion.
Operated on Deutsche Telekom (OTC) servers – comprehensively audited and certified to, among others, ISO 27001 and SOC 2 Type II. All data processing is subject to German law, European data protection standards, and in particular the GDPR. No critical components are outsourced to third countries, and there is no dependency on non-European cloud providers – complex cross-border data protection reviews are eliminated entirely.
For elevated security and compliance requirements, the platform can be run on your own servers – on a scalable Kubernetes cluster. That means full control over all data, clear accountability and easy integration into existing security frameworks.
The platform is developed entirely in Germany and runs exclusively on servers located in Germany. Every line of code, every development step happens in Germany – no offshore or nearshore development, and therefore no exposure of the IT systems to other countries.
Hidden dependencies on third-party software, plug-ins or external platform services are an often underestimated risk. Our platform is built entirely in-house – with no critical dependencies on third-party vendors and no external core components. That reduces security risks, update dependencies and compliance complexity, and creates long-term technical stability.
We continuously and automatically check for available security updates to software components, so that any discovered vulnerabilities are closed as quickly as possible. DEPLAW is continuously developed further to respond to new threats and attack vectors and to protect sensitive case data as effectively as possible.
Governance, risk & operations
Security as a leadership responsibility, not a side project.
A named information security officer is responsible for building, running and developing our ISMS. A security committee made up of management, IT operations and our data protection officer meets regularly to review measures, risks and incidents.
Information security risks are captured, assessed and treated through a structured, repeatable process. The risk register is reviewed at least annually and whenever circumstances warrant; management decides on the treatment of any residual risk.
Permissions follow the principle of least privilege and need-to-know. Two-factor authentication is mandatory for remote access, privileged accounts and access to case and file data; granted permissions are reviewed regularly and revoked where no longer needed.
Systems and components in use are regularly checked for vulnerabilities; security-relevant updates are applied on a risk-based, time-bound basis. Vendor advisories and relevant security notices are monitored continuously.
A documented reporting process exists for security incidents, involving our external data protection officer — providing the guidance needed to meet data protection notification duties on time.
Production data is backed up daily and stored in geographically separated locations. Recoverability is actually tested on a regular basis, not merely assumed — part of a documented business continuity and recovery plan.
All employees are bound to confidentiality and complete recurring information security and data protection training with a pass/fail check. Suppliers undergo a security and privacy review before being engaged and are bound contractually.
AI security
AI that stays under control.
Using language models is core to how we deliver our service — and is therefore held to its own, strict principles.
- Exclusively self-hosted language models
- AI-assisted processing runs on our own or leased resources within the EU. The data never leaves these systems.
- No training on client data
- Personal data from client and case files is never used to train or improve our own or third-party models.
- No data shared with external AI providers
- Personal data is never transmitted to external AI services — this is categorically excluded.
- Human review before every decision
- Results from AI processes are reviewed by qualified staff before any legally relevant decision — the system provides a suggestion, never a binding decision.
- Pre-deployment assessment under the EU AI Act
- Every new model is classified under the AI Act before deployment. The modules we use have already been classified as non-high-risk systems.
Business ethics & responsibility
Compliance doesn't stop at IT.
Gifts, invitations and conflicts of interest above clearly defined minor thresholds are disclosed rather than concealed; stricter standards apply toward public officials. Business decisions are made solely on objective criteria.
A dedicated reporting mailbox with an anonymous online option is available for breaches of our anti-corruption and code-of-conduct policy, as well as for discrimination, harassment or bullying. Reports are investigated confidentially; retaliation against whistleblowers is prohibited.
We voluntarily align our due-diligence practices with the German Supply Chain Due Diligence Act (LkSG), even below the statutory threshold that would otherwise apply. This rests on internationally recognized human rights, the ILO core labor standards and the UN Guiding Principles on Business and Human Rights. No violations have been identified in the past five years.
New suppliers, business partners and clients are screened against the consolidated EU and UN sanctions lists before any contract is signed — including infrastructure and cloud providers. Critical business relationships are re-screened regularly, since sanctions lists change.
As a pure software and services company with no manufacturing of our own, we keep our environmental footprint low. We expect comparable standards on human rights, working conditions and environmental protection from our suppliers and business partners.
For law firms
§ 43e BRAO: confidentiality — down to the last subcontractor.
Any lawyer engaging an IT provider must, under § 43e BRAO, select them carefully, bind them in writing to confidentiality, and inform them of the criminal confidentiality obligation under § 203 of the German Criminal Code (StGB) — while also ensuring that their subcontractors are bound as well. DEPLAW delivers these building blocks as standard, instead of leaving them to the law firm.
Written confidentiality commitment
Everyone and every system that comes into contact with client and case data is provably bound to confidentiality in writing — documented and included as part of the data processing agreement (DPA).
Notice of the confidentiality obligation
Everyone bound is explicitly informed of the criminal confidentiality obligation under § 203 StGB. This keeps attorney-client confidentiality airtight even when external technology is used.
Subcontractor list
A complete, up-to-date list of every subcontractor in use — with purpose, location (EU/Germany) and proof of their confidentiality commitment. That lets you meet your selection and oversight duty without follow-up questions.
We document this entire chain in full — from the first commitment down to the last subcontractor. You receive the confidentiality declaration, the notice and the subcontractor list as part of the DPA.
Review our security concept in detail.
In the demo, we'll walk through audit documentation, the hosting model and data protection together.
Book a free demo