Skip to content
Nokumo AI Visibility ist im Early Access — so beschreibt KI Ihr Hotel.Warteliste beitreten →
nokumo
Sicherheit

Die Pässe Ihrer Gäste verlassen die EU nicht. Nichts anderes auch.

Azure Frankfurt und Amsterdam. AES-256 im Ruhezustand. TLS 1.3 bei der Übertragung. Jährlicher Penetrationstest durch SEC-Consult. ePorezna und FURS über zertifikatsgebundene Behörden-APIs. Hier steht genau, was das in der Praxis bedeutet.

Microsoft Azure Infrastructure

Nokumo is hosted exclusively on Microsoft Azure in EU data centers. Your guest data never leaves EU jurisdiction.

  • EU data residency (Frankfurt / Amsterdam)
  • 99.9% uptime SLA
  • Automatic failover and disaster recovery
  • Azure DDoS protection

AES-256 Encryption

All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Payment data is tokenised and never stored on Nokumo servers.

  • AES-256 encryption at rest
  • TLS 1.3 for all connections
  • Stripe tokenisation for payment data
  • No plaintext credentials stored

ISO 27001-Aligned

Our information security management follows ISO 27001 principles. We conduct annual security audits and penetration testing.

  • ISO 27001-aligned ISMS
  • Annual penetration testing
  • Vulnerability disclosure programme
  • Incident response under 4 hours

GDPR Compliance

Nokumo acts as a data processor under GDPR. A full Data Processing Agreement (DPA) is available for all customers.

  • Full DPA available on request
  • Data subject rights supported
  • Right to erasure implemented
  • Sub-processor list published

EU Regulatory Security

Croatian eVisitor, ePorezna, and FURS integrations use government-approved secure channels with certificate-pinned APIs.

  • ePorezna certificate-pinned API
  • FURS secure channel integration
  • eVisitor government API compliance
  • Fiscal log integrity guaranteed

Responsible Disclosure

Security researchers can report vulnerabilities via our responsible disclosure programme. We respond within 24 hours.

  • security@nokumo.net
  • PGP key available
  • Hall of fame for researchers
  • No legal action for good-faith disclosure

Zertifizierungen & Compliance-Status

ISO 27001-konform
DSGVO (EU) 2016/679
SOC-2-Kontrollen
PCI DSS über Stripe
CAIQ (auf Anfrage)
Sub-Prozessor-Liste (veröffentlicht)

Wir benötigen einen ausgefüllten CAIQ für unseren Beschaffungsprozess. Ist das verfügbar?

EC
Enterprise customers
Contact sales to request the completed CAIQ under NDA

Sub-Prozessor-Liste

Microsoft Azure — Cloud-Infrastruktur, EU-West-Regionen
Stripe — Zahlungsverarbeitung, PCI-DSS-konform
SendGrid — Transaktionaler E-Mail-Versand
Vollständige Liste verfügbar unter nokumo.com/security

Beschaffungsdokumentation benötigt?

Auftragsverarbeitungsvertrag (AVV) — auf Anfrage erhältlich
Sub-Prozessor-Liste — veröffentlicht und vierteljährlich aktualisiert
ISO-27001-Nachweisschreiben — unter NDA erhältlich
Sicherheitsfragebogen (CAIQ) — auf Anfrage ausgefüllt

CAIQ-Kurzfassung

Verschlüsseln Sie Daten im Ruhezustand?

Ja — AES-256 für alle Produktionsdatenbanken. Schlüssel über Azure Key Vault verwaltet.

Unterstützen Sie MFA?

Ja — MFA für alle Administratorkonten erzwungen. Für alle Mitarbeiterkonten verfügbar.

Wo werden Daten gespeichert?

Microsoft Azure West Europe (Niederlande) und North Europe (Irland). Keine Daten außerhalb der EU.

Jährliche Penetrationstests?

Ja — unabhängiges Drittunternehmen. Berichte für Enterprise-Kunden unter NDA verfügbar.

Sicherheits-FAQ

In einer Woche live gehen?

Schließen Sie sich Hunderten von Beherbergungsbetreibern in unseren Kernmärkten an. 14 Tage kostenlos. Keine Kreditkarte erforderlich.

Keine Kreditkarte erforderlich · In einer Woche live · EU-Compliance inklusive

50% off for early accessNo commitmentCancel anytime

Be first in line for Nokumo AI Visibility

Future-proof your digital presence directly within Nokumo AI Visibility and discover exactly how AI engines view and recommend your booking engine.