Technical & Organizational Measures (TOMs)
Understand how awork protects your customer data through ISO 27001-aligned security measures including encryption, access controls, and continuous monitoring
Security at every level
Information security at awork isn't a one-time project for us - it's part of our daily operations.
We protect your customer data through a combination of technical, organizational, and procedural measures that meet the requirements of ISO 27001.
All measures are regularly reviewed, documented, and further developed as part of our Information Security Management System (ISMS).
Technical Measures
| Area | Measures |
|---|---|
| Access Control | Data centers are operated by Microsoft Azure in Germany (Frankfurt & Berlin) and comply with ISO 27001, SOC 2, and BSI C5. Physical access is strictly regulated. |
| Login Control | System access is exclusively through individual accounts with two-factor authentication. Access rights are role-based and regularly reviewed. |
| Access Control / Permission Management | Employees only receive access to the systems and data they need for their work (need-to-know principle). Changes are logged and approved. |
| Encryption | All data is encrypted both at rest and in transit (AES-256 / TLS 1.2+). Customer data in awork is logically isolated from each other. |
| Data Backup & Recovery | Automated daily backups in separate Azure storage areas; regular restore tests; defined recovery times. |
| Network Security | Segmentation through firewalls and access restrictions; continuous monitoring for unauthorized activity. |
| System Hardening & Patch Management | Regular updates, automated security scans, vulnerability management through centralized tools. |
| Incident Response & Monitoring | 24/7 monitoring of critical systems; defined incident response process with escalation chain and documentation of all incidents. |
Organizational Measures
| Area | Measures |
|---|---|
| Information Security Management (ISMS) | Implementation and documentation of all security policies according to ISO 27001; regular internal audits. |
| Data Protection Management | External data protection officer (PROLIANCE GmbH) guides processes; annual reviews and data protection impact assessments as needed. |
| Awareness & Training | All employees complete mandatory security training and phishing simulations; new employees complete a mandatory awareness module during onboarding. All employees also receive ongoing training in secure development and use of AI systems. |
| Access & Role Management | Linked to HR processes (onboarding / offboarding). Access is immediately revoked upon departure and reviewed every six months. |
| Supplier & Sub-Processor Control | All partners are evaluated through Privacy & Security checks before deployment; annual re-certification. Providers of AI infrastructure and AI models also go through a risk-based Privacy and Security review before approval. |
| Business Continuity & Disaster Recovery | Emergency plans for system outages; regular testing and lessons-learned sessions. |
| Continuous Improvement | Security incidents, findings, and customer feedback feed into our ISMS; measures are tracked centrally. |
Certifications & Frameworks
- ISO 27001 - awork and the data center where we host the app are certified according to ISO-27001:2022
- BSI C5 / SOC 2 (Azure) - covered by Microsoft
- GDPR Compliance - continuously reviewed by external data protection officer
In a nutshell
Security is just as much a part of awork for us as great usability or clean processes.
We take care of all the complex stuff in the background so you can focus on your team and your projects.
Reliable, pragmatic, and with the ambition to get a little better every single day.
