Security Certifications
Security is core to VxLabs Security ("VxLabs Security"). Our products and services are built for automotive and cybersecurity use cases, and we know that our customers rely on us to handle their data and systems with great care.
This page summarizes our current security posture and certifications.
1. Security Governance
We maintain an internal security and information management framework that includes:
- defined responsibilities for security and IT operations,
- security policies and standards (e.g. access control, asset management, incident response),
- risk assessment and management processes,
- onboarding and training for people with access to systems and data.
Security is integrated into our overall development and operations lifecycle.
2. TISAX Assessment
VxLabs Security has implemented an information security management framework aligned with the requirements of the automotive industry.
- TISAX (Trusted Information Security Assessment Exchange) is a standard for information security in the automotive sector, based on ISO/IEC 27001 and tailored to automotive OEMs and suppliers.
- VxLabs Security has a TISAX AL3 label available for its assessed scope.
TISAX Assessment Details:
Objectives: Information with Very High Protection Needs and very high availability
Scope-ID: SH57RK
Participation-ID: PRNZMC
Assessment-ID: ATXXH2-1
Details are available to existing or prospective customers upon request, in line with TISAX information sharing rules.
If you require formal TISAX confirmation, please contact us at: hello@threatz.io.
3. Technical and Organisational Security Measures
Without disclosing sensitive details, the following high-level controls are part of our security posture:
3.1 Infrastructure and Network
- Use of reputable cloud and infrastructure providers with strong security baselines.
- Segmentation between environments (e.g. production, staging, development).
- Firewalls and network access rules to restrict inbound and outbound traffic.
- Secure remote access and VPN or equivalent technologies where appropriate.
3.2 Access Control and Identity
- Role-based access control (RBAC) and least-privilege principles.
- Strong authentication for administrative and sensitive access.
- Regular review of accounts, permissions and access logs.
- Immediate revocation of access upon role changes or termination.
3.3 Data Protection
- Encryption of data in transit (e.g. TLS for web and API access).
- Encryption at rest for sensitive data where appropriate.
- Data minimization and separation of customer environments where applicable.
- Secure backup and recovery processes.
3.4 Secure Development and Operations
- Use of modern development practices and tooling (e.g. code review, version control).
- Dependency and vulnerability management for libraries and components.
- Testing and quality assurance processes; secure configuration baselines.
- Logging and monitoring of system events, with alerting for suspicious activity.
3.5 Incident Management
- Defined incident response procedures for security events.
- Detection, triage, containment and remediation steps.
- Post-incident review and continuous improvement.
4. Customer-Specific Security & Compliance Requirements
We understand that many customers, especially in the automotive sector, have their own security and compliance frameworks (e.g. ISO/SAE 21434, UNECE R155, GB 44495-2024, internal supplier security policies).
We can support you by:
- providing security and compliance documentation for our services,
- completing security questionnaires where appropriate,
- participating in customer security reviews and audits within reasonable bounds,
- aligning integration and deployment models with your security architecture.
Where more stringent requirements apply (e.g. on-prem deployments, dedicated environments, integration into your SOC/VSOC), these can be addressed in individual agreements and Statements of Work.
5. Future Certifications and Roadmap
We continually review our security posture and may pursue additional certifications or assessments as our business and product portfolio evolve (e.g. ISO/IEC 27001 or similar standards).
If you have specific certification or framework requirements, please let us know so we can factor them into our roadmap and engagement planning.
6. Security Contact
If you:
- have questions about our security posture,
- need formal proof of our TISAX assessment, or
- would like to report a potential security issue,
please contact:
Franz-Mayer-Str. 1
93053 Regensburg
Germany
Email: hello@threatz.io
For sensitive reports, please do not include confidential or exploit details in the initial message. We will provide a secure channel for follow-up communication.
7. Updates
We may update this Security & Certifications page as our security program evolves or new certifications are obtained. Please refer to this page for the latest high-level information.