Trust Center

We hold ourselves to the standard we sell.

Security governance, our own SBOM, and a public vulnerability disclosure program — in one place.

Assessment

TISAX AL3 assessed

Information security assessed at Assessment Level 3 — the level automotive OEMs require of their suppliers. ISO 27001 alignment is on the roadmap. Assessment details →
Transparency

Our own platform SBOM

We publish the SBOM of ThreatZ itself — CycloneDX, updated per release. If we ask your suppliers for one, you can ask us for ours. Request platform SBOM →
Disclosure

Public VDP with safe harbor

48-hour response commitment, coordinated disclosure, and credit for researchers. Security events are documented and communicated. Read the disclosure policy →

Security measures

Private cloud or on-premise deployment; air-gapped installs supported for classified programs
Encryption in transit (TLS 1.3) and at rest; customer data segregated per tenant
RBAC with entity-level permissions; SAML SSO; full audit logging of security-relevant events
EU hosting available; GDPR-compliant processing with signed DPAs and listed sub-processors
Secure development lifecycle: code review, SAST/SCA gates, dependency monitoring on our own SBOM
Offices and support in Germany, the United States and Egypt — EU data stays in the EU

Found a vulnerability?

We run a public vulnerability disclosure program and respond within 48 hours. Report to security@threatz.io — safe harbor applies for good-faith research.

Questions your security team will ask?

We'll answer them in the demo — bring your procurement checklist.

Book a demo