AereA GmbH
Discuss your project

Security & compliance

This page is both a trust signal and a template for supplier questionnaires. It describes how we work — not which seals we hold.

Are you certified to ISO 27001 or TISAX?

No, and it is not currently planned. We consider it more honest to say so than to argue process maturity that has not been audited. If your procurement mandates a certificate — with automotive OEMs and tier-1 suppliers, TISAX is regularly a hard precondition — we are the wrong supplier at that point. We prefer to say that before the effort rather than after.

What we do instead: we document our processes to ISO 27001 logic and disclose them here. This page is structured so that it largely answers a supplier questionnaire.

Development location

Development takes place entirely in Germany, at the company location in Wüstenstein, Bavaria. There are no offshore or nearshore components. Project language is German or English.

Handling of client data

  • Data minimisation as a principle. Wherever possible we work with synthetic test data rather than real data. In the public administration projects this was mandatory and has proven itself as a standard.
  • Data processing agreements. We conclude data processing agreements under Art. 28 GDPR. A draft can be provided for review in advance.
  • Access restriction. Access to client systems and data is limited to the people working on the respective project.
  • Return and deletion. Project data is returned or deleted after the end of the contract as agreed.

Sub-processors

We only engage sub-processors after prior agreement. The services used in a given project are named in the DPA.

Hosting options

For systems we operate or whose operation we support, we offer three models:

  1. On premises at the client — the norm where data sovereignty requirements apply.
  2. German cloud with a provider whose data centre is in Germany.
  3. Hybrid — sensitive processing local, uncritical load external.

Security practices in development

  • Threat modeling along system boundaries as part of the architecture design.
  • Encryption and certificates — TLS, PKI, X.509, client certificates, including the lifecycle.
  • Identity and access management — OAuth2, OpenID Connect, Keycloak.
  • Hardening of network and application components, especially at exposed borders.
  • Static analysis as a mandatory CI gate.
  • Dependency review — automated dependency updates backed by tests.

Use of AI tooling on client code

This is actively asked about in 2026, so here in detail:

  • The use of AI tooling on client code is settled in writing before the project starts — up to and including complete abstention, if the client wishes.
  • We assess cloud API, dedicated hosting and full self-hosting per project and disclose which variant is used.
  • We review training-data exclusion, retention periods and confidentiality tiers of the respective provider.
  • For sensitive projects we design the hybrid case: sensitive processing local, uncritical load external.
  • Traceability is preserved: agent-assisted changes pass the same gates and are traceable back to the requirement through the ticket-driven workflow.

This website

No cookies, no tracking, no external fonts, no third-party scripts. Built to WCAG 2.2 AA, with its own accessibility statement.

Information for tenders

Detailed, person-specific expert profiles, reference descriptions and supplementary compliance information are provided for concrete procurements. Get in touch.

Contact

Your contact

Sören Sprenger
Software architecture & technical project management

Wüstenstein 18, 91346 Wiesenttal · Mon–Fri 9:00–18:00 CET