Quality and security

Holistic quality and information security management

Quality and security are of the utmost importance to us. Because your trust is important to us and we strive for a high security standard, we have been certified according to DIN EN ISO/IEC 27001.


Certified Management System

Projektron has an integrated management system that covers comprehensive quality and information security measures. Since 2008, we have been operating a quality management system based on ISO 9001 that covers the entire value chain and product life cycle – from the product idea to development, testing, documentation, and commissioning at the customer's site, as well as customer support. In 2017, we also implemented an information security management system (ISMS) according to ISO 27001.

At the beginning of 2018, we received ISO 27001 certification from TÜV SÜD and in 2021 we received renewed certification according to DIN EN ISO/IEC 27001:2017. In 2025, we were awarded the certification ISO/IEC 27001:2022 by TÜV Rheinland with the scope of application of development, support, IT services and internal IT administration. We strive to be an excellent company in the sense of the EFQM model and plan to achieve ISO 9001 certification.

The general goals of information security apply to all areas of our company:

Confidentiality Integrity Availability

Our management systems include all relevant provisions and guidelines for data protection, health protection, environmental protection, occupational safety and fire protection, as well as information security. The ISMS has anchored information security in the company's organizational structure and established important processes such as risk management.

Organizational Measures for Information Security

Employee Training and Continuing Education

All employees are regularly made aware of and trained in information security. These training sessions are used to refresh and update knowledge on current topics. New employees receive appropriate training during onboarding. In addition, employees receive needs-based continuing education to raise awareness of information security objectives and risks.

Emergency Management and System Audits

To enable a rapid response to security incidents and limit potential damage, emergency response concepts have been developed and documented in emergency manuals. In addition, annual system audits are conducted to ensure a structured security review of all IT services. The focus is on risk assessment, access rights, and encryption.

Data Protection and Information Security Management

Projektron uses a data protection management system (DPMS) in accordance with the EU General Data Protection Regulation (EU GDPR). A dedicated team of ISMS officers actively works on information security and the related processes. This team continuously ensures compliance with security objectives. In addition, an expert team has been established within the company to address current topics in IT security and security in development.


Highest security standards – TISAX® certification process

The ENX Association supports with TISAX (Trusted Information Security Assessment Exchange) on behalf of VDA the common acceptance of Information Security Assessments in the automotive industry. The TISAX Assessments are conducted by accredited audit providers that demonstrate their qualification at regular intervals. TISAX and TISAX results are not intended for general public.

For Projektron GmbH confidentiality, availability and integrity of information have great value. We have taken extensive measures on protection of sensitive and confidential information. Therefore, we follow the question catalogue of information security of the German Association of the Automotive Industry (VDA ISA). The Assessment was conducted by an audit provider, in this case the TISAX audit provider TÜV SÜD Management Service GmbH. The result is exclusively retrievable over the ENX Portal.

Quality management

We systematically survey and evaluate customer wishes and requirements regarding BCS and our services to ensure that the quality demands of our customers of all sizes and in all industries are fully met to their satisfaction. Regular recording and analysis serves as a starting point for the continuous improvement of our products, services and our company as a whole. This is how we continue to develop as a learning organization.

IT administration

Our internal IT administration also takes information security very seriously. We use state-of-the-art technology to secure our systems and continuously update our security measures.

Our Measures for Securing Our Systems in IT Administration

Centralized Software Deployment and Endpoint Security

Centralized Software Distribution

Required software is deployed centrally to operational workstations and kept up to date.

Antivirus and Antimalware Software

The antivirus and antimalware programs continuously used on all endpoint devices are updated regularly.

Patch Management

Security updates and patches for operating systems and applications are installed regularly.

Network and Perimeter Security

Redundant Network Technology

The internet connection, firewall, and core switches are redundant.

Firewalls

Firewalls are used to control network traffic.

Network Segmentation

Networks are separated into different segments to restrict access to critical systems and prevent attacks from spreading.

VPN

VPN access is available to employees for mobile work. VPNs are used to provide secure remote access to internal systems.

Monitoring / Security Monitoring

Internal services are continuously monitored to ensure availability and enable a rapid response in the event of issues.

Access Controls and Authentication

Least Privilege Principle

Access rights are granted based on the principle of least privilege, ensuring that users can access only the resources they actually need.

Role-Based Access Control (RBAC)

Role-based access controls have been implemented to restrict access to sensitive information.

Data Encryption and Security

Cryptography

The recommendations of the BSI Technical Guidelines (BSI TR-02102) are reviewed annually.

Internal Certificate Authority

Internal services are encrypted through our own certificate authority.

Encryption in Transit

Encryption technologies are used to protect data during transmission.

Email Security & Backups

Email

Incoming email traffic is monitored and, in case of doubt, initially placed in quarantine.

Backup & Recovery

Internal services are backed up daily and can be quickly restored to the state of the most recent backup. The recovery process is tested semiannually.

Organizational Measures

Regular Training

We provide training for IT staff and end users on the latest security threats and best practices.

Security Awareness Programs

We conduct ongoing programs to raise employee awareness of information security.

Documented Security Policies

Security policies and procedures are created, documented, and updated regularly.

Compliance

We ensure compliance with relevant legal and regulatory requirements as well as internal security policies.

Process-Related Measures

Incident Response and Emergency Management

We have emergency plans that include measures for restoring systems in the event of an incident. To prepare for security incidents, we conduct regular exercises and review the effectiveness of the emergency plans.

Risk and Vulnerability Management

We regularly conduct risk assessments to identify and evaluate potential threats. We have implemented a process to detect, assess, and remediate vulnerabilities in the IT infrastructure.


Support

We use our own support portal to provide technical support to our customers. In doing so, we always pay attention to the quality and, above all, the security of the information we handle.

Our Measures for Information Security in Support

Support Portal and Configuration Management

Support Portal

The customer support portal is used for the secure exchange of information and the transfer of data. Communication takes place via tickets with a system-internal storage area for data exchange.

Configuration Versioning Service (KVD)

The Configuration Versioning Service (KVD) is a central configuration repository for customers and Projektron itself. Configurations are managed within an SVN repository.

Authentication and Access Control

Access Authorization

The customer’s designated contacts have personalized access to the support portal.

Strong Authentication

Two-factor authentication (2FA) is used for access to the support portal.

Role-Based Access Control (RBAC)

Access rights are assigned based on user roles in order to restrict access to sensitive information.

Secure Password Policies

We have implemented policies for secure passwords, including minimum length, complexity, and regular changes.

Encryption and Data Protection

Encryption

Access to the support portal is only possible via an encrypted connection.

Data Minimization

Only the customer data required for commissioned data processing is collected and stored in the system.

End-to-End Encryption

It is ensured that data remains encrypted throughout the entire communication via the support portal between customers and support staff.

Data Protection-Compliant Processes

Processes have been implemented in accordance with the General Data Protection Regulation (GDPR) and other relevant data protection laws. These processes are consistently followed.

Employee Training and Security Information

Security Information for Customers

We regularly provide customers with security-relevant information within the support portal.

Training for Our Employees

Our support staff receive regular, needs-based training related to the security of the software in use and the interfaces to third-party systems that can be connected to BCS.

Regular Training

Support staff are regularly trained and made aware of information security, data protection, and the secure handling of customer data.

Awareness Programs

We continuously conduct programs to promote security awareness and compliance with security policies.

Process-Related Measures and Emergency Management

Logging and Monitoring

All activities in the support portal are logged in detail, and the logs are regularly reviewed for suspicious activity.

Security Policies and Procedures

Policies and procedures for information security in the support portal are consistently enforced and continuously updated. In addition, regular security reviews and audits are conducted to ensure compliance with security standards.

Incident Response and Emergency Plans

We follow a clear process for reporting, analyzing, and resolving security incidents. Emergency plans are in place in the event of a security incident and are updated regularly.

Customer Data Management and Anonymization

To increase the protection of customer data, we anonymize or pseudonymize data wherever possible.


Information security in BCS development and hosting

In addition to efficient business processes, secure software development is the core of our company and our web-based project management software.

 

Measures for information security in product development and hosting

Software Made in GermanyOMR 2026 Top RatedTÜV Rheinland ISO/IEC 27001:2022TISAX Result availableSHiG 2026