The technical and organisational measures set out here relate to the business premises, other facilities and operating resources of DeepMask GmbH as processor.
The platform runs on the Schwarz Group's sovereign German cloud (STACKIT). Where processing activities take place on the business premises, in other facilities or using the operating resources of a subprocessor — in particular in STACKIT's data centres — DeepMask adopts the measures implemented there as its own.
Physical access control
Denying unauthorised persons physical access to data processing facilities
Implemented measures:
- Operation exclusively in certified data centres in Germany (STACKIT, ISO 27001 and BSI C5)
- Physical protection of the data centres through multi-level access controls
- 24/7 security staffing and video surveillance of security-relevant areas
- Visitor management with registration and mandatory escorting
- No own server rooms: DeepMask operates no on-premise processing facilities
System access control
Preventing unauthorised persons from using data processing systems
Implemented measures:
- Multi-factor authentication for all administrative access
- SSO and SAML for enterprise customers with central user management
- Role-based access control (RBAC) separating user, admin and operations roles
- Automatic locking of inactive accounts and session timeouts
- Password policies following BSI recommendations, stored as hashes only
Data access control
Ensuring that only authorised persons can access the relevant data
Implemented measures:
- Granular authorisation concepts at organisation, team, project and chat level
- Principle of least privilege for all operational access
- No access by DeepMask staff to chat and project content during normal operations
- Support access only after explicit customer approval and fully logged
- Regular access reviews and recertification of permissions
Transfer control
Ensuring that personal data cannot be read without authorisation during transmission
Implemented measures:
- TLS 1.3 for all connections between client, platform and model endpoints
- Encryption of data at rest (AES-256) in databases, object storage and backups
- Central key management with regular rotation
- Transmission to model providers exclusively via secured, contractually bound endpoints
- Regular review of the cipher suites and certificates in use
Input control
Traceability of who entered, changed or removed which data and when
Implemented measures:
- Audit logs for logins, permission changes and administrative operations
- Logging of model selection and usage per organisation for traceability and billing
- Technical logs are deleted automatically after seven days
- Tamper-resistant storage of logs with restricted access
- Analysis for anomalies and automatic alerting on unusual patterns
Instruction control
Ensuring that data is processed solely in accordance with the controller's instructions
Implemented measures:
- Data processing agreement pursuant to Art. 28 GDPR with every customer
- DPA pursuant to Art. 28 GDPR with every subprocessor engaged
- Careful selection and regular assessment of all model providers and cloud partners
- All staff bound to confidentiality and data secrecy
- Regular data protection and security awareness training
Availability control
Ensuring that data is protected against accidental destruction or loss
Implemented measures:
- Redundant infrastructure across several availability zones within Germany
- Regular, encrypted backups with defined RTO and RPO targets
- Restore tests to verify backup integrity
- Failover to alternative EU model endpoints if a provider fails
- Monitoring, alerting and a documented incident response process
Separation control
Ensuring that data from different controllers is processed separately
Implemented measures:
- Multi-tenant architecture with strict separation per organisation
- Enforcement of the tenant boundary at application and database level
- Separate environments for development, testing and production
- No production data in test and development environments
- Regular review of the separation measures as part of security testing
AI-specific measures
Protecting inputs and outputs during processing by AI models
Implemented measures:
- No training: inputs and outputs are contractually excluded from any further development of the models
- No prompt retention at the model providers beyond the duration of the response
- Preferred routing to model endpoints hosted in Germany and the EU
- Transparent labelling of model, hosting region and knowledge cut-off in the interface
- Human final decision: results are presented as suggestions, not as automated individual decisions within the meaning of Art. 22 GDPR
Certification and review
Procedures for regularly testing, assessing and evaluating effectiveness (Art. 32(1)(d) GDPR)
Implemented measures:
- Establishment of an information security management system (ISMS) to ISO 27001 — certification in progress
- External data protection officer regularly reviewing the processing activities
- Record of processing activities pursuant to Art. 30 GDPR
- Regular security testing of the platform and remediation of identified vulnerabilities
- Assessment of the certifications and audit reports of all subprocessors