SecureCloud is independently audited - by TÜV Rheinland, the BMWK and to BSI standards. ISO 27001 certified, BSI C5 attested, Trusted Cloud certified, CIS and GDPR compliant.






SecureCloud is certified to ISO/IEC 27001:2022 - the leading international standard for information security management systems. The certificate is audited annually by TÜV Rheinland and evidences documented processes for risk management, access control and business continuity.
SecureCloud is BSI C5 attested - the highest evidence of cloud security in Germany. The Cloud Computing Compliance Criteria Catalogue (C5) of the Federal Office for Information Security (BSI) is examined by independent auditors and is increasingly a requirement in tenders in regulated industries.


SecureCloud is Trusted Cloud certified, recognised under the Trusted Cloud initiative of the German Federal Ministry for Economic Affairs and Climate Action (BMWK). The seal marks cloud services that meet German-standard transparency, security and legal criteria.
SecureCloud is GDPR compliant: all data is processed exclusively in German data centers, is subject to German law alone and is protected from access under the US CLOUD Act. There is no general GDPR certification - serious providers therefore refer to compliance.


SecureCloud is CIS compliant, configured to the benchmarks of the Center for Internet Security. These define proven hardening guidelines for systems and services and complement the ISO 27001 certification and the BSI C5 attestation with security at the configuration level.
SecureCloud carries the IT-Security made in Germany seal. Company headquarters and servers are located exclusively in Germany, there is no US parent company and no hidden backdoors - our promise: #nobackdoor.

Yes. SecureCloud is certified to ISO/IEC 27001:2022, and the certificate is audited annually by TÜV Rheinland. The standard evidences a systematic information security management system (ISMS) with documented processes for risk management, access control and business continuity. All data is processed exclusively in German data centers operated by noris network AG in Nuremberg.
BSI C5 attested means an independent auditor has examined SecureCloud's cloud security against the Cloud Computing Compliance Criteria Catalogue (C5) of Germany's Federal Office for Information Security (BSI). C5 is an attestation, not a certification: it documents an auditor's examination report and counts as the highest evidence of cloud security in Germany. For regulated sectors such as the public sector and financial services, C5 is increasingly a requirement in tenders.
Yes. SecureCloud is Trusted Cloud certified, recognised under the Trusted Cloud initiative of the German Federal Ministry for Economic Affairs and Climate Action (BMWK). The award marks cloud services that meet German-standard transparency, security and legal criteria. SecureCloud's company headquarters and servers are located exclusively in Germany.
SecureCloud is GDPR compliant. There is no general GDPR certification: the General Data Protection Regulation (GDPR) provides no nationally accredited certification scheme, so no serious provider claims to be GDPR certified. SecureCloud processes all data exclusively in German data centers, is subject to German law alone, and has no US parent company subject to the US CLOUD Act.
Yes. SecureCloud is CIS compliant, meaning it is configured to the benchmarks of the Center for Internet Security (CIS). These benchmarks define proven hardening guidelines for systems and services. Combined with ISO/IEC 27001 certification and the BSI C5 attestation, CIS compliance shows that SecureCloud proves security at the configuration level as well as the process level.
Yes. SecureCloud carries the IT-Security made in Germany seal (issued by TeleTrusT - IT Security Association Germany). Its headquarters (Neumarkt i.d. OPf.) and servers (noris network AG, Nuremberg) are located exclusively in Germany; there is no US parent company and no access under the US CLOUD Act. The seal stands for products free of hidden backdoors, our promise: #nobackdoor.
SecureCloud's certifications (ISO 27001, the BSI C5 attestation, Trusted Cloud, CIS) evidence the technical and organisational measures that regulated companies can rely on directly for DORA, NIS-2, KRITIS and the GDPR. Certifications are credentials SecureCloud itself holds; compliance obligations such as DORA or NIS-2 are your organisation's duties, which SecureCloud supports. The compliance page at securecloud.de/en/compliance shows how the mapping works in detail.
Yes. For tenders in the public sector, healthcare and finance, SecureCloud provides the customary credentials: ISO/IEC 27001 certification (audited annually by TÜV Rheinland), the BSI C5 attestation as Germany's highest cloud-security evidence, Trusted Cloud certification from the BMWK, and CIS compliance. All data remains in Germany and is subject to German law alone, with no access under the US CLOUD Act.
Our experts are happy to answer any questions you may have.
Data centers and company headquarters in Germany
Our promise: #nobackdoor