innoscripta

Trust Center

Security, privacy & compliance at innoscripta

Data protection and information security are at the core of Innoscripta's products and services. Protecting your data and earning your trust is pivotal for us.

ISO 27001 certifiedISO 27001 certified
GDPR alignedGDPR aligned
GoBD compliantGoBD compliant
EU data hostingEU data hosting

Our security program

Our comprehensive security program protects your data at every layer.

Information security management

Our ISO 27001 certified ISMS ensures systematic management of sensitive information through continuous risk assessment, policy enforcement, and improvement processes.

Access control

Strict access control measures ensure only authorized personnel can access systems and data, implementing the principle of least privilege alongside required MFA.

Risk management

Proactive identification and mitigation of security risks through comprehensive risk assessments and treatment plans aligned with international industry standards.

Incident management

24/7 security monitoring with defined incident response procedures to quickly detect, respond to, and recover from security events, followed by post-incident analysis.

Monitoring & logging

Centralized logging and continuous monitoring provide visibility into critical activities, support auditability, and help detect suspicious behavior in a timely manner.

Vulnerability management

Regular internal and external vulnerability scanning, supported by penetration testing, helps identify, prioritize, and remediate security weaknesses across our environment.

Meeting international standards

ISO 27001 certificate

Protecting your data is a top priority for innoscripta SE. With our ISO 27001 certification, we meet strict international standards to ensure the confidentiality, integrity, and availability of your information at all times.

Download
ISO 27001

Why is ISO 27001 certification so important?

As an innovation-driven company with clients from various industries, we understand how critical it is to protect confidential information. The ISO 27001 certification confirms that we follow the highest international security standards – providing our clients and partners with clear benefits:

Security guarantee

Our clients can be confident that their data is protected according to the highest security standards.

Risk minimization

Through comprehensive information security risk management, we ensure that potential threats are detected and mitigated early.

Legal compliance

ISO 27001 certification helps us meet regulatory requirements and systematically comply with applicable data protection laws.

Trust & transparency

With an ISO 27001‑certified ISMS, we show our clients that data protection and information security matter to us.

ISAE 3402 Type II (SOC 1 Report) and IDW PS 951 Type II Certification

Our company is currently undergoing the audit and certification process to obtain the ISAE 3402 Type II (SOC 1 report) as well as the IDW PS 951 Type II certification. As part of these audits, the design and effectiveness of our internal control system will be evaluated by independent auditors over the period 01.01.2026 – 31.12.2026, in order to ensure transparency, security, and reliable processes for our customers and partners. The corresponding reports will likely be available for request from us at the beginning of 2027.

What is the difference between ISAE 3402 Type II (SOC 1 report) and IDW PS 951 Type II certification?
  • ISAE 3402 is an international auditing standard for service organizations.
  • IDW PS 951 is a German audit report concerning the internal control system for outsourced processes.
What does Type II mean?

A distinction is made between two types of audits:

  • Type I: Verifies whether controls are properly designed and documented (a snapshot in time).
  • Type II: Verifies whether controls actually function effectively over a period of time (usually 6–12 months).

European data hosting

innoscripta's services and customer data are hosted entirely within the European Union. Data never leaves EU jurisdiction, giving procurement and legal teams immediate clarity on where information lives and which laws govern it.

European data residency

Sensitive customer data is retained exclusively within the European Union.

Stronger procurement confidence

Immediate clarity on physical data location and sovereign jurisdiction.

Regional governance

Infrastructure governance strictly aligned with regional legal paradigms.

European data residency

Sensitive customer data is retained exclusively within the European Union.

Stronger procurement confidence

Immediate clarity on physical data location and sovereign jurisdiction.

Regional governance

Infrastructure governance strictly aligned with regional legal paradigms.

Privacy Policy
Legal Imprint
Information Security Guideline
Penetration Test Summary
Statement of Applicability

Frequently asked questions

Management and board responsibilities are formally defined within the ISMS framework.
Yes. The program is approved by senior management and the board.
Yes. Employees receive regular training on risk awareness, security obligations, and their responsibilities.
Yes. Risk assessments consider both inherent and residual risk to validate the effectiveness of controls.
No. Any exclusion would be documented and approved in the Statement of Applicability, and currently no specific controls are excluded.
Yes. The program is documented, approved by management, communicated internally, and continually improved.
Yes. Information security objectives are defined, monitored, and communicated.
Yes. The Information Security Officer (ISB) is formally appointed as the program owner.
The ISB reports on cybersecurity performance and material risks every six months.
Yes. Roles and responsibilities are clearly defined and acknowledged before personnel receive access.
Yes. Compliance policies and procedures are formally maintained.
Yes. Regulatory changes are identified, assessed, and monitored.
Yes. It includes alerting, monitoring, logging, and implementation of required changes.
Yes. Employees with access to scoped systems or data receive regular training on legal and regulatory requirements.
Yes. Compliance issues are logged, tracked, and reported internally.
Yes. An environmental policy is in place and includes improvement commitments.
Yes. Climate-related risks are incorporated into governance and oversight.
Yes. The policy has executive and board-level endorsement.
Yes. Health and safety policies and procedures are documented.
Yes. ESG performance is monitored at board level.

Contact our trust team

Questions about our security program, privacy practices, or compliance posture? Reach out to us directly.

innoscripta

The data layer for R&D, a continuous, verifiable record of the work your teams actually do, captured at source. Publicly listed, ISO 27001-certified, in 20+ countries.

innoscripta provides software solutions, documentation support, and general information on R&D funding. Our services do not include individual tax, legal, or financial advice.

Eligibility, funding rates, and potential outcomes depend on the applicable laws and regulations as well as the specific circumstances of the company and the respective project. Before submitting an application, we therefore recommend seeking qualified tax, legal, or financial advice where appropriate.

For further information, please refer to our information notice.



Copyright © 2026 - innoscripta SE

Handelskai 94/96, Vienna, Austria

+43 1 928 800 704

info@innoscripta.com

Trust Center | innoscripta