Security at a glance

Highest standards of data protection and data security

netfiles gives top priority to the security of your sensitive data. Leading-edge data encryption, authentication and access control technologies guarantee that your data is safely protected against unauthorized access. Redundant data storage, back-ups and regular security checks guard against the loss of data – and all with 99.9% guaranteed system availability.

High-security data centers in Germany

Our georedundant servers are located at two highly secure data centers in Munich and Nuremberg. Both data centers are operated by German provider noris network AG. Go here for detailed information.

Independent certifications (ISO, C5, SOC 2)

German technical service provider TÜV has certified our compliance with ISO/IEC 27001:2022 and ISO 22301:2019 , while an independent auditor has certified our compliance with the internationally recognized SOC (System and Organization Controls) standard. netfiles also meets the requirements for C5 certification as promulgated by Germany’s Federal Office for Information Security (BSI). To learn more about netfiles’ independent certifications, go here.

Failure security

All servers and applications are observed by netfiles GmbH and its partners 24/7 using redundantly designed monitoring systems. If a problem should occur with a component, it will be repaired immediately by a service team that is also available round-the-clock. All systems and components are designed redundantly. If some unforeseeable event causes a complete failure of the data center, the entire functionality can be taken over in a short time by a hot stand-by system in another data center.

Protection against unauthorized access

We use a highly available firewall cluster. The work environment consists of double firewall protection and a physically separated, dedicated management server. This provides highest level of security and optimal protection against third party attacks.

Security begins the moment you log in

Access to the data room in netfiles is possible only with a valid combination of user name and password or with a valid passkey. After login, all data communication between the user’s web browser and our data servers is encrypted over the Internet using 256-bit SSL. In addition, 2-factor authentication is available (via text message or the Authenticator/OTP app) as an extra security option for logging into the data room.

(red) Feature icon AES 256 encryption

256-bit AES encryption

netfiles uses the 256-bit Advanced Encryption Standard (AES) to securely encrypt your data as soon as you upload it to the data room. This algorithm provides excellent security and is widely regarded as one of the most secure encryption algorithms in the world. It is the solution of choice for governments and banks.

SSL/TLS encryption for data transmission

All data communication between the user’s web browser and the netfiles application servers is protected by 256-bit encryption based on the SSL/TLS protocol. SSL/TLS is also used to handle authentication, check for data integrity and transmit data securely using swapped keys. The security of the netfiles servers can be validated at any time via the well-known Qualys SSL Labs Test. Here, netfiles regularly achieves the best A+ rating.

The most up-to-date virus scanners

To reliably prevent all forms of malware, files are scanned for viruses, ransomware and/or any other malicious software when they are uploaded to netfiles data rooms. To maximize security, virus signatures are updated on an hourly basis.

Data protection in compliance with the GDPR and Germany’s Federal Data Protection Act

netfiles GmbH is subject to the strict regulations of the EU’s General Data Protection Regulation (GDPR) and Germany’s Federal Data Protection Act (BDSG) to ensure the protection of personal data. netfiles guarantees a GDPR-compliant way of working and the highest level of security in the processing of personal data.

Regular security check

The netfiles application undergoes rigorous security checks that are carried out by SySS GmbH in Tübingen, Germany. SySS GmbH specializes in security and penetration testing.

IT Security made in Germany

netfiles GmbH is a member of TeleTrusT – Bundesverband IT-Sicherheit e.V. (the IT Security Association Germany) and bears the TeleTrusT quality seal "IT Security made in Germany". TeleTrusT, a wide-ranging network of excellence for IT security, is committed to the goal of promoting and strengthening IT security in Germany.

To qualify for TeleTrusT’s “IT Security made in Germany” seal, a company must be domiciled in Germany and operate its IT security research and development in this country. Solutions or products must not contain “backdoors”, and the company must commit to compliance with the requirements of German data protection law.

By satisfying all these criteria, netfiles guarantees its customers and users the highest standards of security, transparency and data protection.

Single sign-on (SSO)

netfiles Enterprise gives users the option of the single sign-on (SSO) feature. SSO is a secure but simple and user-friendly method of authentication. Users require only a single set of registration data with which they can then log into different applications or systems.

Certifications

ISO 27001 certification logo

ISO/IEC 27001:2022 Certification

The certification unit of TÜV SÜD Management Service GmbH certifies that netfiles GmbH complies with the requirements of ISO/IEC 27001:2022, attesting that netfiles GmbH has introduced and uses a documented information security management system which covers its “marketing, operational and support activities for the netfiles application for virtual project and data rooms”.

ISO 22301:2019 logo

ISO 22301:2019 Certification

The Business Continuity Management System of netfiles GmbH has been certified by TÜV Rheinland according to ISO 22301:2019.

HIPAA compliance logo

HIPAA

With netfiles, you have an easy-to-use and highly secure solution for exchanging health information that enables your organization to comply with HIPAA regulations.

C5 certification logo

BSI C5 Certificate

netfiles meets the requirements for the security of cloud services defined by the German Federal Office for Information Security (BSI) in the Cloud Computing Compliance Criteria Catalogue (C5).

IT Security made in EU logo

IT Security made in EU

On the occasion of the German EU Council Presidency 2020 and against the background of the debate on European digital sovereignty, TeleTrusT established the optional labelling option "IT Security made in EU" for products and services of its members. This TeleTrusT labelling initiative complements the introduced TeleTrusT trust mark "IT Security made in Germany" and thus ties in with the demand to focus on "IT Security made in Germany" or "IT Security made in EU", e.g. in government tenders for IT infrastructure key components.

The “IT Security Made in EU” trust seal is awarded to companies that are headquartered in the EU, offering trustworthy IT security solutions, are not offering solutions that contain non-declared backdoors, are conducting IT security reasearch and development in the EU and are compliant with the requirements of the European General Data Protection Regulation (GDPR).

Trusted Cloud logo

Trusted Cloud

netfiles is recognized by the German Trusted Cloud Network (Kompetenznetzwerk Trusted Cloud e.V) as a trusted secure cloud service and hold the “Trusted Cloud” seal of approval. The Trusted Cloud Project is funded by the German Ministry of Economic Affairs and Energy.

Cloud Services made in Germany icon

Cloud Services Made in Germany

netfiles is a member of the “Cloud Services Made in Germany” initiative. The aim of this initiative is to provide companies with professional support and more security when selecting cloud services.

SOC2 logo

SOC 2

netfiles GmbH has been successfully audited by an independent auditing firm for compliance with the "Trusted Criteria" of data security and data protection according to the internationally recognized standard SOC (System and Organization Controls). The internationally recognized SOC standard is issued by the renowned auditing body American Institute of Certified Public Accountants (AICPA).

DSGVO compliance logo

DSGVO

The netfiles data room enables GDPR-compliant storage and the exchange of personal data across location and company boundaries.

Alliance for cyber security logo

Alliance for Cyber Security

netfiles GmbH is a member of the Alliance for Cyber Security. With the Alliance for Cyber Security, the BSI has been pursuing the goal of strengthening Germany's resistance to cyber attacks since 2012.

The netfiles security concept

Would you like to know more?

We would be happy to send you our detailed netfiles security concept, which is available on request.

Simply send us an e-mail or call us: