Technical & Organizational Measures (TOMs)

Security at every level

Information security at awork isn't a one-time project for us - it's part of what we do every single day.

We protect your customer data through a combination of technical, organizational, and procedural measures that meet the requirements of ISO 27001.

All measures are regularly reviewed, documented, and continuously improved as part of our Information Security Management System (ISMS).

Technical Measures

AreaMeasures
Access ControlData centers are operated by Microsoft Azure in Germany (Frankfurt & Berlin) and meet ISO 27001, SOC 2, and BSI C5 standards. Physical access is strictly regulated.
AuthenticationSystem access is exclusively through individual accounts with two-factor authentication. Access rights are role-based and regularly reviewed.
Authorization / Permission ManagementTeam members only get access to the systems and data they need for their work (need-to-know principle). All changes are logged and approved.
EncryptionAll data is encrypted both at rest and in transit (AES-256 / TLS 1.2+). Customer data in awork is logically separated from each other.
Backup & RecoveryAutomated daily backups in separate Azure storage areas; regular restore tests; defined recovery time objectives.
Network SecuritySegmentation through firewalls and access restrictions; continuous monitoring for unauthorized activities.
System Hardening & Patch ManagementRegular updates, automated security scans, vulnerability management through centralized tools.
Incident Response & Monitoring24/7 monitoring of critical systems; defined incident response process with escalation procedures and documentation of all incidents.

Organizational Measures

AreaMeasures
Information Security Management (ISMS)Implementation and documentation of all security policies in accordance with ISO 27001; regular internal audits.
Data Protection ManagementExternal Data Protection Officer (PROLIANCE GmbH) guides processes; annual reviews and Data Protection Impact Assessments as needed.
Awareness & TrainingAll team members complete mandatory security training and phishing simulations; new hires get onboarding plus awareness training.
Access & Role ManagementLinked to HR processes (onboarding/offboarding). Access is immediately revoked upon exit and reviewed every six months.
Supplier & Sub-processor ControlAll partners evaluated through Privacy & Security checks before engagement; annual recertification.
Business Continuity & Disaster RecoveryEmergency plans for system outages; regular testing and lessons learned sessions.
Continuous ImprovementSecurity incidents, findings, and customer feedback flow into our ISMS; measures are tracked centrally.

Certifications & Frameworks

  • ISO 27001 - awork and the data center where we host the app are certified to ISO 27001:2022
  • BSI C5 / SOC 2 (Azure) - covered by Microsoft
  • GDPR Compliance - continuously verified by our external Data Protection Officer

In a nutshell

Security is just as important to us as great usability or clean processes.

We handle all the complex stuff behind the scenes so you can focus on your team and your projects.

Reliable, pragmatic, and committed to getting a little bit better every day.

Last updated HappySupportPowered by happysupport.ai
© 2026 HappySupport. All rights reserved.