Technical and organisational security measures
liquidTMS protects financial data through clearly defined technical and organisational measures.
These include secure data processing, controlled access and continuous system monitoring.
All measures are interlinked and ensure a reliable, traceable database.
Measures at a glance
| Measure | Description | Microsoft Azure (Cloud) | liquidTMS (app) |
|---|---|---|---|
| Multi-client capability & data isolation | Strict separation of customer data through tenant IDs and role-based access | ✓ | ✓ |
| Encryption (TLS, AES-256) | TLS 1.2+ for all connections, AES-256 for stored sensitive data and backups. | ✓ | ✓ |
| Least privilege authorisations | Minimum rights per service and user, regular policy reviews. | ✓ | |
| Network & application protection | WAF rules against OWASP top 10 threats, protection against DDoS, secured API endpoints. | ✓ | ✓ |
| Monitoring & logging | Centralised logging of all API calls, real-time monitoring of anomalies, audit trails. | ✓ | ✓ |
| Authentication & authorisation | JWT-based login, optional SSO integration, role- and attribute-based rights management. | ✓ | |
| Secure development process (SDLC) | Code reviews, automated security scans (SAST/DAST), dependency checks. | ✓ | |
| Backup & recovery | Daily backups with geographical redundancy, regular recovery tests. | ✓ |
Compliance and legal protection
liquidTMS complies with all important data protection regulations such as the GDPR and the requirements of BaFin. We guarantee that your data is processed securely and protected at all times.
Thanks to our German cloud infrastructure, all data remains under your control at all times - it is not passed on to third parties.
FAQ - Data, data protection & compliance
Your data is processed in a separate, isolated system environment.
Thanks to clear client separation and role-based access concepts, your database remains completely separate and protected at all times.
All data is encrypted both during transmission and storage.
This ensures that sensitive information is protected from unauthorised access at all times.
Access is controlled in a targeted manner and limited to what is necessary.
Role and authorisation-based concepts ensure that users can only access the data they need for their tasks.
The platform is protected by multi-level security mechanisms.
These include protective measures at network and application level as well as the protection of interfaces.
System processes and data access are continuously monitored.
Anomalies can therefore be recognised and tracked at an early stage, allowing risks to be assessed and contained more quickly.
Regular backups and tested recovery processes ensure that data remains reliably available even in the event of unexpected events.
The platform is continuously developed and reviewed.
Structured development processes and regular security checks ensure that new requirements and potential risks are taken into account at an early stage.
Processing is carried out on the basis of clearly defined rules and standards.
This ensures that legal requirements are met and data is processed in a traceable and controlled manner.