Skip to main content

Technical & Organisational Measures (TOMs)

Last updated: December 2025

Max Raschke avatar
Written by Max Raschke
Updated this week

Security on every level

At awork, information security isn’t a one-time project – it’s part of how we work every day.

We protect customer data through a combination of technical, organisational and procedural controls aligned with ISO 27001.

All measures are reviewed regularly and documented within our Information Security Management System (ISMS).

Technical Measures

Area

Measures

Physical access control

Data centres operated by Microsoft Azure Germany (Frankfurt & Berlin), certified to ISO 27001, SOC 2 and BSI C5; strictly limited physical access.

System access control

Individual accounts with mandatory 2FA; role-based permissions reviewed regularly.

Data access control

Principle of least privilege; changes logged and approved.

Encryption

All data encrypted at rest and in transit (AES-256 / TLS 1.2+); logical separation of customer data.

Backup & recovery

Automated daily backups in separate Azure storage; restore tests; defined recovery objectives.

Network security

Firewall segmentation, access restrictions, continuous monitoring for suspicious activity.

System hardening & patching

Regular updates, vulnerability scans, managed patch cycles.

Incident response & monitoring

24/7 system monitoring; documented incident process with escalation path.

Organisational Measures

Area

Measures

Information Security Management

Policies and procedures maintained under ISO 27001; regular internal audits.

Data Protection Management

Supported by external DPO (PROLIANCE GmbH); annual reviews and DPIAs as needed.

Awareness & Training

Mandatory security training and phishing simulations; onboarding includes awareness module.

Access & Role Management

Linked to HR processes (on/offboarding); immediate revocation on exit; semi-annual reviews.

Vendor & Sub-processor Management

Privacy & Security checks before engagement; annual re-certification.

Business Continuity & Disaster Recovery

Defined plans; regular tests and post-mortems.

Continuous Improvement

Security events, audit findings and customer feedback feed into ISMS action tracking.

Certifications & Frameworks

  • ISO 27001 – awork is ISO-27001 certified; same goes for our hosting provider

  • BSI C5 / SOC 2 (Azure) – covered by Microsoft

  • GDPR compliance – continuously monitored by our external DPO

In summary

For us, security is as much a part of awork as great usability or well-designed processes.

We take care of the complex stuff behind the scenes so you can focus on your team and your projects.

Reliable, pragmatic, and always improving a little every day.

Did this answer your question?