Data protection & compliance
at liquidTMS

Financial data requires clear rules for processing, protection and utilisation.

liquidTMS ensures that all data is processed in a structured manner, stored securely and used exclusively in the intended context.

100 % development in Germany
Hosting in German data centres
No disclosure of financial data to third parties
Strict separation of all customer data

Technical and organisational security measures

liquidTMS protects financial data through clearly defined technical and organisational measures.

These include secure data processing, controlled access and continuous system monitoring.

All measures are interlinked and ensure a reliable, traceable database.

Measures at a glance

MeasureDescriptionMicrosoft Azure (Cloud)liquidTMS (app)
Multi-client capability & data isolationStrict separation of customer data through tenant IDs and role-based access
Encryption (TLS, AES-256)TLS 1.2+ for all connections, AES-256 for stored sensitive data and backups.
Least privilege authorisationsMinimum rights per service and user, regular policy reviews. 
Network & application protectionWAF rules against OWASP top 10 threats, protection against DDoS, secured API endpoints.
Monitoring & loggingCentralised logging of all API calls, real-time monitoring of anomalies, audit trails.
Authentication & authorisationJWT-based login, optional SSO integration, role- and attribute-based rights management. 
Secure development process (SDLC)Code reviews, automated security scans (SAST/DAST), dependency checks. 
Backup & recoveryDaily backups with geographical redundancy, regular recovery tests. 

Compliance and legal protection

liquidTMS complies with all important data protection regulations such as the GDPR and the requirements of BaFin. We guarantee that your data is processed securely and protected at all times.

Thanks to our German cloud infrastructure, all data remains under your control at all times - it is not passed on to third parties.

Safe & transparent

With liquidTMS, you retain control over your financial data.

All processes are structured, access is clearly regulated and data is traceable at all times.

This creates a reliable basis for secure decisions in everyday financial life.

FAQ - Data, data protection & compliance

How is it ensured that our financial data is not mixed with other companies?

Your data is processed in a separate, isolated system environment.

Thanks to clear client separation and role-based access concepts, your database remains completely separate and protected at all times.

How is sensitive financial data protected during transmission and storage?

All data is encrypted both during transmission and storage.

This ensures that sensitive information is protected from unauthorised access at all times.

Who has access to our data within the system?

Access is controlled in a targeted manner and limited to what is necessary.

Role and authorisation-based concepts ensure that users can only access the data they need for their tasks.

How does liquidTMS protect against external attacks and security risks?

The platform is protected by multi-level security mechanisms.

These include protective measures at network and application level as well as the protection of interfaces.

How are unusual activities or potential risks recognised?

System processes and data access are continuously monitored.

Anomalies can therefore be recognised and tracked at an early stage, allowing risks to be assessed and contained more quickly.

How is it ensured that data is not lost in an emergency?

Regular backups and tested recovery processes ensure that data remains reliably available even in the event of unexpected events.

How is the security of the software guaranteed in the long term?

The platform is continuously developed and reviewed.

Structured development processes and regular security checks ensure that new requirements and potential risks are taken into account at an early stage.

What role does compliance play in data processing?

Processing is carried out on the basis of clearly defined rules and standards.

This ensures that legal requirements are met and data is processed in a traceable and controlled manner.