Trust Center
We hold ourselves to the standard we sell.
Security governance, our own SBOM, and a public vulnerability disclosure program — in one place.
Assessment
TISAX AL3 assessed
Information security assessed at Assessment Level 3 — the level automotive OEMs require of their suppliers. ISO 27001 alignment is on the roadmap. Assessment details →
Transparency
Our own platform SBOM
We publish the SBOM of ThreatZ itself — CycloneDX, updated per release. If we ask your suppliers for one, you can ask us for ours. Request platform SBOM →
Disclosure
Public VDP with safe harbor
48-hour response commitment, coordinated disclosure, and credit for researchers. Security events are documented and communicated. Read the disclosure policy →Security measures
✓
Private cloud or on-premise deployment; air-gapped installs supported for classified programs
✓
Encryption in transit (TLS 1.3) and at rest; customer data segregated per tenant
✓
RBAC with entity-level permissions; SAML SSO; full audit logging of security-relevant events
✓
EU hosting available; GDPR-compliant processing with signed DPAs and listed sub-processors
✓
Secure development lifecycle: code review, SAST/SCA gates, dependency monitoring on our own SBOM
✓
Offices and support in Germany, the United States and Egypt — EU data stays in the EU
Found a vulnerability?
We run a public vulnerability disclosure program and respond within 48 hours. Report to security@threatz.io — safe harbor applies for good-faith research.
Questions your security team will ask?
We'll answer them in the demo — bring your procurement checklist.
Book a demo