Summary
Tacto operates a highly secure SaaS solution for industrial procurement. Security and data protection are top priorities. Our architecture is based on the “security-by-design” principle and leverages the certified infrastructure of Microsoft Azure within the European Union.
This document confirms that communication with the Tacto portal is secure and complies with current industry standards (in accordance with ISO 27001, SOC 2, and BSI recommendations).
Infrastructure & Certifications
Tacto does not host any on-premises servers, but instead relies entirely on a cloud architecture that meets the most stringent compliance requirements.
Cloud provider: Microsoft Azure (regions: “Germany West Central” and “West Europe”)
Data center certifications: The underlying infrastructure is certified according to ISO/IEC 27001, SOC 2 Type II, and TISAX
Data location: Guaranteed data storage exclusively within the European Union (EU). No data is transferred to third countries
Tacto compliance: Tacto operates in accordance with ISO 27001 standards and is preparing for its own certification in Q2 2026. All subcontractors are already certified
Network and Transmission Security
To justify whitelisting our domain, we rely on comprehensive protection mechanisms against attacks and malware:
Transmission encryption: All data traffic between the user’s browser and our servers is strictly encrypted using TLS 1.3 (Transport Layer Security). We use SSL certificates issued by Let’s Encrypt
Malware protection: All files uploaded to the portal are automatically scanned using Azure Storage Malware Scanning. This prevents malicious files from being distributed via our platform
Network protection: Use of anti-DDoS layers, web application firewalls (WAF), and continuous network monitoring to defend against attacks
Data Security & Encryption (Data at Rest)
The confidentiality of data is ensured through strong cryptographic mechanisms:
Encryption at rest: All databases, backups, and file storage systems are encrypted using AES-256-bit encryption
Key management: Centralized management of cryptographic keys via Azure Key Vault with strict rotation and access control
Backups: Encrypted backups are stored redundantly within Germany and the Netherlands (30-day retention, point-in-time recovery)
Status: December 2025 – Tacto Technology GmbH
