Skip to main content

Tacto Technology GmbH – Security Concept & Compliance Overview

Updated over a month ago

Summary

Tacto operates a highly secure SaaS solution for industrial procurement. Security and data protection are top priorities. Our architecture is based on the “security-by-design” principle and leverages the certified infrastructure of Microsoft Azure within the European Union.

This document confirms that communication with the Tacto portal is secure and complies with current industry standards (in accordance with ISO 27001, SOC 2, and BSI recommendations).

Infrastructure & Certifications

Tacto does not host any on-premises servers, but instead relies entirely on a cloud architecture that meets the most stringent compliance requirements.

Cloud provider: Microsoft Azure (regions: “Germany West Central” and “West Europe”)

Data center certifications: The underlying infrastructure is certified according to ISO/IEC 27001, SOC 2 Type II, and TISAX

Data location: Guaranteed data storage exclusively within the European Union (EU). No data is transferred to third countries

Tacto compliance: Tacto operates in accordance with ISO 27001 standards and is preparing for its own certification in Q2 2026. All subcontractors are already certified

Network and Transmission Security

To justify whitelisting our domain, we rely on comprehensive protection mechanisms against attacks and malware:

Transmission encryption: All data traffic between the user’s browser and our servers is strictly encrypted using TLS 1.3 (Transport Layer Security). We use SSL certificates issued by Let’s Encrypt

Malware protection: All files uploaded to the portal are automatically scanned using Azure Storage Malware Scanning. This prevents malicious files from being distributed via our platform

Network protection: Use of anti-DDoS layers, web application firewalls (WAF), and continuous network monitoring to defend against attacks

Data Security & Encryption (Data at Rest)

The confidentiality of data is ensured through strong cryptographic mechanisms:

Encryption at rest: All databases, backups, and file storage systems are encrypted using AES-256-bit encryption

Key management: Centralized management of cryptographic keys via Azure Key Vault with strict rotation and access control

Backups: Encrypted backups are stored redundantly within Germany and the Netherlands (30-day retention, point-in-time recovery)

Status: December 2025 – Tacto Technology GmbH

Did this answer your question?