Eviworx
Eviworx

Security & Compliance

Eviworx Enterprise ITSM

As of: September 2026

Eviworx Software UG

This document summarizes the technical and organizational measures (TOM) of Eviworx and maps them to common requirements (GDPR, NIS2, supply chain security). It documents the current product and process status and does not replace a formal certification. Further evidence is available on request (see section 5).

Core Principle: On-Premise

Eviworx runs entirely within the customer's infrastructure. In regular operation, the vendor has no access to the customer's data. Data sovereignty therefore remains fully with the customer — a key advantage over SaaS solutions, especially for GDPR and NIS2 assessments.

1. GDPR

Technical measures implemented in the product:

RequirementImplementation in Eviworx
Data sovereigntyOn-premise operation, no vendor access in regular operation
Access controlRole-based access control (RBAC) with dynamic roles; server-side enforcement
AuthenticationMFA/TOTP, password hashing (PBKDF2-SHA512), optional Entra ID SSO
Encryption of sensitive dataAES-256-GCM for sensitive fields (e.g. TOTP secrets, license keys)
Accountability (Art. 5, 30)Tamper-evident, SHA-256 hash-chained audit trail (DB trigger against tampering)
Data minimization in logsAutomatic PII scrubbing (email, phone, IBAN, tokens) in audit events
Data subject rights (access/erasure)Self-service export (Art. 15/20, machine-readable JSON) and admin export; anonymization instead of deletion (Art. 17) with preflight blocker check and erasure hold (legal hold); configurable retention periods; direct DB access on-prem
Privacy organizationDedicated "Data Protection Officer" role; data breach flow for incidents

2. NIS2

Beyond technical security, NIS2 primarily requires traceable security processes. Eviworx addresses this as follows:

3. Supply Chain Security

Eviworx is built on established open-source components (incl. Node.js, React, PostgreSQL, Redis). For transparency about the included components:

4. Technical Security (Overview)

5. Evidence & Documents on Request

Through the security contact we provide the following documents after review:

6. Security Contact & Vulnerability Reporting

Please report security vulnerabilities confidentially to: security@eviworx.com

Target response times (first acknowledgement):

SeverityFirst acknowledgement
Critical24 hours
High72 hours
Medium7 days

We ask for responsible disclosure and no publication before a coordinated remediation.

© 2026 Eviworx Software UG • Schillerstraße 96, 63263 Neu-Isenburg

info@eviworx.com • security@eviworx.com