Security & Compliance
Eviworx Enterprise ITSM
As of: September 2026
Eviworx Software UG
This document summarizes the technical and organizational measures (TOM) of Eviworx and maps them to common requirements (GDPR, NIS2, supply chain security). It documents the current product and process status and does not replace a formal certification. Further evidence is available on request (see section 5).
Core Principle: On-Premise
Eviworx runs entirely within the customer's infrastructure. In regular operation, the vendor has no access to the customer's data. Data sovereignty therefore remains fully with the customer — a key advantage over SaaS solutions, especially for GDPR and NIS2 assessments.
1. GDPR
Technical measures implemented in the product:
| Requirement | Implementation in Eviworx |
|---|---|
| Data sovereignty | On-premise operation, no vendor access in regular operation |
| Access control | Role-based access control (RBAC) with dynamic roles; server-side enforcement |
| Authentication | MFA/TOTP, password hashing (PBKDF2-SHA512), optional Entra ID SSO |
| Encryption of sensitive data | AES-256-GCM for sensitive fields (e.g. TOTP secrets, license keys) |
| Accountability (Art. 5, 30) | Tamper-evident, SHA-256 hash-chained audit trail (DB trigger against tampering) |
| Data minimization in logs | Automatic PII scrubbing (email, phone, IBAN, tokens) in audit events |
| Data subject rights (access/erasure) | Self-service export (Art. 15/20, machine-readable JSON) and admin export; anonymization instead of deletion (Art. 17) with preflight blocker check and erasure hold (legal hold); configurable retention periods; direct DB access on-prem |
| Privacy organization | Dedicated "Data Protection Officer" role; data breach flow for incidents |
2. NIS2
Beyond technical security, NIS2 primarily requires traceable security processes. Eviworx addresses this as follows:
- Published security policy with a central security contact (see section 6).
- Defined process for reporting and remediating vulnerabilities with target response times.
- Security updates and tracking of known vulnerabilities (CVE) in the components used.
- Incident handling in the product (incident management incl. data breach flow) and organizationally.
- Hardened architecture: zero-trust virus scan, SSRF protection, rate limiting, security headers, TLS termination at the gateway.
3. Supply Chain Security
Eviworx is built on established open-source components (incl. Node.js, React, PostgreSQL, Redis). For transparency about the included components:
- Software Bill of Materials (SBOM) in the standard formats CycloneDX / SPDX — available per release on request.
- Container images based on slim, hardened base images; regular updates.
- FIPS 140-2 compatible cryptographic algorithms (no official FIPS certification).
4. Technical Security (Overview)
- Tamper-evident SHA-256 hash-chained audit trail with integrity verification.
- RBAC with server-side enforcement; critical actions are freshly revalidated.
- MFA/TOTP, session management (view/terminate sessions), brute-force protection (CAPTCHA).
- Zero-trust virus scan for file uploads (scan worker without direct file access, quarantine).
- Central SSRF protection for outbound connections (webhooks); fail-closed.
5. Evidence & Documents on Request
Through the security contact we provide the following documents after review:
- Full TOM documentation (technical and organizational measures).
- SBOM (CycloneDX / SPDX) for the deployed version.
- Data processing agreement (DPA) — relevant if optional support/maintenance services with data access are used (usually not required for pure on-premise operation).
- Further security-related evidence upon agreement.
6. Security Contact & Vulnerability Reporting
Please report security vulnerabilities confidentially to: security@eviworx.com
Target response times (first acknowledgement):
| Severity | First acknowledgement |
|---|---|
| Critical | 24 hours |
| High | 72 hours |
| Medium | 7 days |
We ask for responsible disclosure and no publication before a coordinated remediation.
© 2026 Eviworx Software UG • Schillerstraße 96, 63263 Neu-Isenburg
info@eviworx.com • security@eviworx.com