Information security

Secure software development and IT services

With BCS, you get a secure ERP and project management system that has been developed in Germany to the highest standards. That's why we place great importance on holistic information security management. Thanks to ISO/IEC 27001 certification, regular security updates, and comprehensive measures for hosting, software development, interfaces, support portal, and BCS app, BCS ensures maximum confidentiality, integrity, and availability of your data—both in the cloud (SaaS) and on-premises. Here you can find out what measures we have implemented to provide you with secure hosting services and a secure product in the form of BCS.


TÜV-certified quality – secure product BCS

Projektron GmbH places a high value on information security and has therefore implemented a comprehensive information security management system (ISMS). With the introduction of this system, we have anchored information security in the company's organizational structure and established central processes such as risk management. Our overarching goals in this regard are always the following:

 Confidentiality  Integrity Availability

A central element of our information security and quality management is our ISO 27001 certification by TÜV Rheinland. This certification confirms that our processes, systems and controls meet the strict requirements of the ISO 27001 standard. Our ISO/IEC 27001:2022 A1 certification covers not only the operation of development and IT services but also our support and IT administration. Our ISMS is regularly reviewed and adapted to respond to new threats and challenges. This guarantees that our security measures are always up to date and that your data is continuously protected.

Regular security updates and bug fixes

The regular installation of updates is one of the most important security measures that users of Projektron BCS should pay attention to. We are constantly working to identify potential security vulnerabilities and fix them immediately. Updates to our software therefore always include bug fixes and eliminated security risks. Therefore, update your BCS installation regularly to be protected against potential risks in the best possible way.
 

View the latest security-related changes

Product development

Secure software development – secure software: Information security in the development process is essential to offering a software product with BCS that provides a secure basis for your business requirements and ensures the confidentiality, integrity and availability of your information.

Our Measures for Secure Software Development

Access Control and Authentication

Role and Permission Model

A customer-specific, customizable role and permission model provides the basis for restricting access to data or information to authorized individuals.

Single Sign-On

BCS supports authentication via SAML, Active Directory (LDAP/KERBEROS), or OAuth 2.0 with OpenID Connect.

Password Policies

BCS supports password policies for password complexity and change frequency.

Two-Factor Authentication

Sign-in can be additionally secured using a second factor generated through the TOTP method.

Passkeys

BCS supports passkeys, a passwordless authentication method that replaces passwords with asymmetric cryptography. This improves usability while addressing vulnerabilities such as phishing, password theft, and weak passwords.

Secure sensitive account changes

Password changes and resets can be further protected by requiring users to authenticate again with a passkey.

Data Security and Safeguards

Encrypted Connections

Encrypted communication is available for secure data transmission between BCS and users or external systems (HTTPS, IMAPS, SMTPS).

Password Vault

Passwords required for third-party systems can be stored cryptographically securely in a password vault.

Secure Passwords

Passwords in BCS are secured using the PBKDF2 algorithm as well as salt and pepper.

Brute-Force Attacks

User accounts are protected by wait times or account lockout after multiple failed sign-in attempts. Access to individual accounts can be restricted to specific IP addresses and IP ranges.

Testing and Verification

Vulnerability Scanning

The software is regularly scanned for known security vulnerabilities.

Penetration Tests

Penetration tests are conducted regularly in collaboration with our customers. The results of these tests are continuously incorporated into the development and protection of BCS.

Automated Testing

BCS is tested for both functionality and usability. Common attack patterns can be checked automatically. Automated tests are integrated into the Continuous Integration (CI) pipeline to ensure that every code change is tested immediately.

Integration Tests

We perform integration tests to ensure that different software components work together securely and that no new security vulnerabilities are introduced.

Unit Tests

For every user story, we develop unit tests to verify correct functionality and security at the code level.

Test Coverage Reports

We create test coverage reports that show the coverage of user stories by tests and ensure that no security-critical areas remain untested.

End-to-End Tests

We create end-to-end tests that cover the entire user story and ensure that the application works as expected and is secure.

Internal Security Measures

Definition of Security Requirements

Security objectives and requirements are clearly defined at the beginning of the project.

Security Planning

We follow a detailed security plan that describes the security measures and procedures.

Expert Team in Product Development

A specialized team continuously addresses current IT security topics and implements the latest security measures in BCS. This ensures that our software always meets the highest security standards.

Internal “Secure Software Development” Policy

The internal policy aims to minimize security deficiencies and vulnerabilities in the development of BCS and respond to them appropriately. This is done by taking into account the SANS Top 25, which lists the 25 most dangerous and relevant software vulnerabilities, as well as the OWASP Top 10, which describes the ten most widespread and important vulnerabilities for web applications.

Employee Training

Our developers are regularly trained and made aware of security aspects and best practices.

Awareness Programs

We conduct programs to promote security awareness throughout the entire development team.

Security Documentation

All security requirements, measures, and tests are documented in detail.

Reporting

Regular reporting on the security status and incidents that have occurred is provided to relevant stakeholders.

Secure Coding and Development Guidelines

Coding Standards and Guidelines

We follow proven coding standards and guidelines to avoid security vulnerabilities.

Code Reviews and Peer Reviews

The code is regularly reviewed by colleagues to identify potential security issues early.

Static Code Analysis

Tools are used for static code analysis to find vulnerabilities in the source code.

Risk Assessment

Potential security risks are identified and assessed throughout the entire development process.

Vulnerability Management

A corresponding process has been implemented to detect, assess, and remediate security vulnerabilities.

Version Control and Configuration Management

Version Control

We use version control systems, such as Git, to track code changes and ensure traceability.

Configuration Management

We ensure that all configurations are securely managed and documented.

Incident Response and Emergency Planning

Emergency Plans

Emergency plans have been created and are continuously maintained to enable a quick and effective response in the event of a security incident.

Incident Response

We have established a process for responding to security incidents, including root cause analysis and remediation.

   

Hosting / SAAS

We know that a secure system is important to you, especially if you host BCS with us or our service provider.

Our Measures for Secure Hosting

Location and Availability

Data Center in Germany

The data center is located in Germany and meets high security standards. It belongs to the Tier IV class and has redundant ISP PoPs.

Backup and Recovery

The hosting service provides backups and, when needed, rapid recovery.

ISO 27001 Certified

Our data center and Projektron’s security-relevant areas are certified according to ISO 27001. The data center also holds additional certificates: VdS ISO 9001 NSL and IS, DIN 14675 for fire alarm systems, and DIN EN 50518.

Availability

We guarantee the agreed availability, which is monitored continuously.

ISO/IEC 27017 & ISO/IEC 27018

Our cloud services are certified according to ISO/IEC 27017 for cloud security and ISO/IEC 27018 for the protection of personal data in the cloud. This enables us to specifically supplement our existing security standards with requirements for cloud environments and to strengthen data protection, transparency, and the clear definition of responsibilities in cloud operations.

C5 Attestation

In addition, our hosting meets the requirements of the Cloud Computing Compliance Controls Catalogue (C5) of the German Federal Office for Information Security with a C5 Type 1 attestation. This confirms the appropriateness of the implemented security measures at the time of the audit. A C5 Type 2 attestation, which additionally verifies the effectiveness of these measures over a defined period, is currently being planned and is expected to be completed in March 2027.

Physical Security and Access Control

Access Control

The data center may only be entered by authorized persons assigned to perform the relevant tasks and only after prior registration.

Security Service

The data center is staffed by on-site security personnel 24/7, 365 days a year.

Security Testing and Updates

Automated Updates

The virtual machines and BCS are updated automatically so that you are always on the latest and most secure version.

Maintenance Windows

Regular scheduled maintenance windows are used to install updates and patches. In the event of an acute security vulnerability, unscheduled updates are carried out with two hours’ prior notice.

Penetration Test

Our hosting is subjected to a penetration test annually.

Data and Access Security

Separate Database Servers

Customer data is stored on separate database servers. This enables better performance and the setup of individual interfaces.

SSL

With hosting, you access BCS through an encrypted connection with an SSL certificate.

VPN Tunnel

The virtual machines cannot be reached via the internet. Projektron accesses them only through VPN tunnels.

Firewall

A centralized firewall with strict filtering rules tailored individually for each customer protects you against external attacks. A web application firewall can be provided upon request.

Secure Connections via HTTPS/SFTP/SSH & SCP

You generally access your virtual machine only through secure connections via HTTPS/SFTP/SSH, for example to create backups or data copies via SCP.

Additional Services and Training

KVD

Our customers are automatically connected to the Configuration Versioning Service (KVD). This means that their configurations are managed within an SVN repository.

Training

Employees receive needs-based training on the security of hosting services.

   

Companies in the IT security industry trust BCS

Companies in the IT security and software industry also rely on BCS to manage their projects securely, efficiently, and transparently.
Our web-based solutions meet the highest standards of information security and data protection—a crucial factor for organizations that work with sensitive data.

 

Support portal & BCS-App

The following measures provide an overview of the most important security and configuration settings that make the BCS support portal and BCS-App even more secure and efficient. Find out how to optimally protect your data and customize the platform to suit your needs.

Our Security Measures for the Support Portal and the BCS App

Support Portal

Transport Security

Transport security in the Support Portal is ensured through the optional, but recommended, use of HTTPS.

Message Exchange and Authentication

Message exchange is performed via SOAP, with authentication secured through the username and password in the SOAP header. The synchronization user should be protected with a strong password, as this user has extensive permissions. This password should be stored in the password vault.

Configuration of Attributes to Be Synchronized

The attributes to be synchronized can be configured, allowing sensitive attributes to be excluded from synchronization.

Port Restrictions

Port restrictions can be applied to specifically limit HTTP communication between the participating systems.

BCS App

Transport Security

Transport security for the BCS App is ensured because it can only be used in conjunction with HTTPS.

Authentication and Cookie Management

Authentication is performed using a username and password, followed by the use of a long-lived cookie that is securely kept in memory and removed from the app upon explicit logout.

Permission Enforcement During Synchronization

During synchronization from the BCS App to BCS, the permissions configured in BCS are applied.

   

Interfaces

This is where you will find an overview of the central security aspects when using interfaces in BCS. Regardless of whether you are integrating Microsoft Exchange, Microsoft 365 (Exchange Online) or Jira, this is where you will learn how to ensure transport security and which authentication and authorization methods are used.

Our Interfaces from a Security Perspective

Support Portal

Transport Security

Transport security in the Support Portal is ensured through the optional, but recommended, use of HTTPS.

Message Exchange and Authentication

Message exchange is performed via SOAP, with authentication secured through the username and password in the SOAP header. The synchronization user should be protected with a strong password, as this user has extensive permissions. This password should be stored in the password vault.

Configuration of Attributes to Be Synchronized

The attributes to be synchronized can be configured, allowing sensitive attributes to be excluded from synchronization.

Port Restrictions

Port restrictions can be applied to specifically limit HTTP communication between the participating systems.

BCS App

Transport Security

Transport security for the BCS App is ensured because it can only be used in conjunction with HTTPS.

Authentication and Cookie Management

Authentication is performed using a username and password, followed by the use of a persistent cookie that is securely retained in memory and removed from the app upon explicit logout.

Permission Enforcement During Synchronization

During synchronization from the BCS App to BCS, the permissions configured in BCS are applied.

  

Information security you can rely on – BCS

BCS is ERP and project management software developed in Germany for service providers with comprehensive information security management. ISO/IEC 27001 certified, regularly updated, and consistently designed for confidentiality, integrity, and availability – available as SaaS (cloud) or on-premises. This ensures that your projects, processes, and data remain protected at all times.

Test BCS securely and experience it live

Steffen Späthe

Chief Technology Officer | Navimatix GmbH

At Navimatix, we use BCS for all core processes within our company—from quote generation, project management, and customer and contact management to employee management and our information security management. BCS provides us with a reliable foundation for efficiently handling our day-to-day challenges.

Tanja Maier

Controlling, SSC-Services GmbH

“[The] risk management of [Projektron] helps us, among other things, to meet the requirements of the TISAX and ISO labels. We store agreements such as service level agreements and non-disclosure agreements for the corresponding projects, record whether relevant information values are processed in the project and whether scheduling has been contractually agreed. Risks and, if applicable, opportunities are stored in the project by the project manager.”

Michael Schäfer

Managing Director, Schutzwerk GmbH

"We wanted an all-in-one solution that covers our high security requirements and supports us in handling our audit projects in the area of cyber security. In addition to the use of basic project management functions, especially for many smaller projects, cross-project resource management and automation from service recording to invoicing are essential for us. Projektron BCS also supports us in the efficient implementation of our internal projects, such as certifications."

Carsten Münch

First Business Partner & Team Coordinator Application Management, TÜV Rheinland Service GmbH

"We have implemented single sign-on so that our employees don't have to enter a password and can use a secure and modern login procedure."

Thomas Hackenbuchner

Head of Finance & Administration, MicroNova AG

"When it comes to information security, BCS provides support through the option of assigning additional attributes to projects. For example, we can classify projects in terms of their need for protection or mark whether it is a project with prototype protection. Based on these markings, we can derive and initiate further process steps."

Kevin Botsch

BCS Technical Product Management, Finanz Informatik Solutions Plus GmbH

"As a consulting, development and integration service provider for business applications in the financial sector, software security and transparent processes are important to us. Due to our growth to date and the constantly increasing number of users, user-friendliness and intuitive operation have also become important factors. With Projektron BCS, we have found a system that meets these requirements exactly. In addition, BCS can also be flexibly adapted to our needs and enables us to make numerous process improvements."

Quality and information security management at Projektron GmbH

In addition to secure software development and secure hosting, efficient business processes are at the core of our project management software and our company. That is why we have implemented a comprehensive quality and information security management system.

 

Quality and information security management at Projektron GmbH

GetApp ReviewsGetApp BadgeTrusted BCS sehr gutCapterra ReviewsOMR - Rating WidgetOMR - Badge

Your contact

Projektron helpdesk

is your contact point
about BCS.

+49 30 3 47 47 64-200
helpdesk(at)projektron.de

Free online presentation

See Projektron's business coordination software in action and start your BCS trial.

Sign up

Software Made in GermanyOMR 2026 Top RatedTÜV Rheinland ISO/IEC 27001:2022TISAX Result availableSHiG 2026