preeco | information security
The complete ISMS for German organizations – from risk analysis through technical and organizational controls and audits to continuous improvement. ISO 27001, BSI IT-Grundschutz, CISIS12 and VdA ISA in one integrated system, hosted in Germany.
ISMS
One complete ISMS in a single system
preeco | information security connects assets, risks, controls, audits, and training into one seamless information security management system – built for continuous improvement.
A management system, not data silos
Every ISMS building block interlocks: assets, risks, TOMs, audits, and training are directly linked – no spreadsheet chaos, no media breaks.
Built to the standards
BSI IT-Grundschutz, CISIS12, and VdA ISA are ready to use as predefined audit catalogs. ISO 27001 conformity is steered via requirement catalogs with a heatmap cockpit, maturity level and Statement of Applicability.
Audit-proof and revision-safe
Seamless activity logs and automatic version control make every change verifiable at any time – for internal and external audits alike.
Continuous improvement
Assess risks, implement controls, conduct audits, adjust – follow-ups, recurring reports, and automatic version control keep your ISMS up to date.
Audits
Audits and Audit Catalogs
Plan, conduct, and document information security audits in a structured way. Ready-to-use audit catalogs for German-recognized standards: BSI IT-Grundschutz, CISIS12, and VdA ISA.
Audit Catalogs
Predefined and customizable questionnaire catalogs as the foundation for your audits. Structured, reusable, and applicable across multiple tenants.
Audits
Structured execution and audit-proof documentation of information security audits. Hierarchical audit object management with direct asset linking. Graphical progress display, export as PDF or DOCX.
Requirement Catalogs & Cockpit
Steer ISO 27001 conformity via ready-to-use requirement catalogs. Rate each requirement with implementation status and maturity level, document the Statement of Applicability (SoA) and capture exceptions. Use bulk editing for status, responsible persons and resubmissions across multiple requirements at once. Request evidence via link, have expiring evidence checked automatically and track the fulfillment progress in the cockpit as a heatmap, list or board – with dedicated tabs for open tasks and upcoming deadlines.
Risks
Risk Analyses
Assess risks systematically and document protection requirement analyses, resource assessments, and threat analyses. With graphical risk mapping and automatic versioning.
Risk Analyses
Flexible risk analyses for any scenario – from protection requirement analyses to threat analyses. Free definition of events, assessment of damage and risk levels. Automatic versioning of all approved documents.
Controls
Security Controls and Policies
Manage policies and technical as well as organizational measures centrally. Link TOMs directly with assets and audits for comprehensive security documentation.
Policies
Create, version, and keep policies up to date through regular reviews – with follow-ups, linking to other documents, and a complete activity log for seamless traceability.
Technical and Organizational Measures
Documentation and versioning of TOMs with automatic revision control. Linking with data processing systems and audits – always audit-ready.
Assets
Asset Management
Manage assets as the central view of your organization's entire system inventory. Record responsibilities, provider details, and link assets directly with TOMs, audits, and risk analyses.
Assets
Central view of the entire system inventory with responsibilities, provider details, purpose descriptions, encryption, availability, NIS2 relevance, and vulnerabilities. Linking with TOMs, audits, and risk analyses. Automatic versioning and export for internal and external audits. The supplementary "Data Processing Systems" view optionally shows privacy-relevant systems in combination with the data protection module.
Protection Needs Assessment
Determine protection needs for confidentiality, integrity, and availability via a damage-scenario matrix based on the maximum principle – including the cumulative effect of linked systems, manually or AI-assisted.
Training
Training and Qualification
Plan, conduct, and document information security training for your employees. Training participation is automatically tracked and certified.
Training
Conduct online training directly in the software. Learning units with image and video content, multiple-choice and single-choice exam questions with configurable minimum score.
Training Participation
Recording and verification of all training participation. Overview of the training status of all employees at a glance. Add participants manually or import via XLSX.
Training Templates
Predefined training templates as a starting point. Customizable to your organization-specific requirements and ready to use.
Reporting
Reporting and Activities
Create comprehensive status reports and keep track of all activities. Complete documentation of all changes for maximum transparency and audit security.
Activities
Automatic log of all document changes. Seamless traceability with timestamp, user, and performed action – for audits and compliance verification.
Reports
Status reports with details on all documents and automatically generated table of contents.
Revision Security
Every approval creates an immutable revision. Two revisions can be compared visually, with changes highlighted by color (additions green, removals red). Stored SHA-256 checksums make the integrity of each revision verifiable, detecting any subsequent tampering.
Incidents
Incident Management
Capture, assess, and document security incidents and data breaches in a structured way. Keep reporting obligations, deadlines, and measures in view at all times.
Incident Capture
Capture security incidents and data breaches centrally via a structured form – with categories, severity, and automatic assessment of statutory reporting obligations and deadlines.
Measures, Reports, and Lessons Learned
Steer the handling of an incident from intake to follow-up. A hierarchical measure structure, custom report templates, and graphical risk mapping bring all steps together in one place.
Features
Collaboration and Task Management
Manage tasks, checklists, files, and messages centrally in one place. All stakeholders stay informed – thanks to dashboard and follow-ups.
Tasks
Create and assign tasks directly within documents. The dashboard shows all open tasks at a glance. Email notifications ensure timely action.
Checklists
Multiple-choice checklists for quality assurance. Use template checklists or create your own. Results exportable as PDF or DOCX.
File Storage
Central upload and structured storage of documents. Tags and nestable folders facilitate organization. Files optionally shareable via public URL.
Messages
Internal communication directly in the system. Attach files, email notifications for new messages. Complete tracking of all communication.
Surveys
Create your own surveys with various question types. Analysis and download as PDF or DOCX. Usable independently or linked to documents.
Follow-ups
Scheduled reminders for all due tasks. Observers are automatically notified. No deadline is missed.
Contacts
Central management of all contacts with structured forms. Linking with other documents, tags, and follow-ups.
Tags
Flexible tagging of all documents. Tags can be created per team and are filterable in all overviews.
Text Modules
Reusable text modules in a filterable, tabular overview. Creation and maintenance controllable via user permissions. Make modules available to specific organizations or to all organizations.
AI Functions
AI-assisted enrichment and revision of content in policies, TOMs and incidents. Multi-edit in overviews for efficient work. Optionally configurable via LLM provider integration.
DeepL Integration
Automatic translation of document content into all 25 available languages via the DeepL API. Optional add-on.
Multilingual
The user interface and documents are available in 25 languages – ideal for international teams and multilingual organizations.
Confidentiality Classes
Optional confidentiality classes for documents – configurable per user group. Sensitive content receives additional access protection.
Monthly Updates
Roughly monthly updates deliver new features, improvements, and short-notice security updates when needed – distributed automatically, without prior notice and without downtime. All hosting options are always kept up to date.
Global Search & Customizable Overviews
Invoke global search via the ⌘/Ctrl+K shortcut from anywhere in the application. Customize overview tables individually – column order and width are saved per view.
Switch Product View
Information security and data protection on one shared platform: with both products licensed, switch your working environment between the information security and data protection views with a single toggle.
Designed for Accessibility
Keyboard operability, semantically structured HTML, sufficient contrast, scalable font sizes and alternative texts for graphics. Accessibility is continuously reviewed and improved. Read our accessibility statement
Security
Security in Development and Operations
preeco | information security is developed following the Security by Design and Security by Default principles – backed by regular security reviews.
Internal Penetration Tests
Regular internal security reviews of the application uncover vulnerabilities before they become a risk.
Security Updates
Continuous monitoring and prompt remediation of security vulnerabilities – distributed as short-notice security updates when needed.
Code Reviews
Regular review of the program code for security vulnerabilities as an integral part of the development process.
Choose Your Hosting Option
Flexible, secure, and tailored to your needs — choose the right hosting solution.
Cloud Hosting
RECOMMENDEDStandard multi-tenant solution with quick setup. Ideal for getting started right away.
Private Cloud
Dedicated instance with custom domain and Single Sign-On (SAML2). For organizations with advanced requirements.
On-Premises
Installation on the customer's own infrastructure in their own data center. Maximum control and full data sovereignty. Optional Single Sign-On (SAML2).
Cloud and Private Cloud options are hosted in ISO 27001-certified data centers of Hetzner Online GmbH in Germany (Nuremberg, Falkenstein). The data centers run on 100% green electricity. Daily backups with 7-day retention, AES-256 encrypted as password-protected archives, and daily off-site backup at the Hetzner Falkenstein data center. Guaranteed availability: 99.0% per calendar month. Deployment within 48 hours (business days). No setup fees and no cancellation periods. All data transmissions are continuously SSL/TLS-encrypted.
Support
Deployment, Support & Service Level
Fast deployment, personal assistance and clearly defined service hours – from onboarding to daily operations.
Fixed Service Hours
Our support team is available Monday to Friday from 9:00 a.m. to 5:00 p.m. in German and English (except on public holidays in Germany) – via email, ticket system and, subject to availability, online chat. Phone and video-conference support can be added as optional premium support.
Guaranteed Response Times
Clearly defined response times by priority – identical in Cloud and Private Cloud: from 2 business hours for critical incidents to 3 working days for general inquiries. Extended 24/7 on-call support is optionally available. If response times are not met, a multi-level escalation process applies, up to executive management.
Deployment within 48 Hours
Cloud and Private Cloud instances are provisioned within 48 hours (on working days); On-Premises installations by individual agreement. Get started without long lead times.
Updates without Downtime
The software is generally available 24/7. Updates are rolled out automatically about once a month without downtime; security updates are applied at short notice when needed. After each update, a pop-up in the application transparently shows the changes made. Longer maintenance work is announced in advance.
Onboarding and Training
A dedicated contact person accompanies your onboarding: setup of the organizational structure, configuration of user groups and permissions, and individual adjustments such as corporate design and email templates. Data migration and training are optionally available.
Interfaces and API
The application is designed as a self-contained system; a public REST API is currently not available. For Private Cloud and On-Premises variants, customer-specific API endpoints can be developed and provided.
Professionalize your ISMS now
In a personal consultation, we'll show you how preeco | information security simplifies your security management.
FAQ
Frequently Asked Questions
You will receive your login credentials by email after registration. Go to the login page and enter your email address and password. If you encounter any issues, please contact our support at support@preeco.de or +49 731 280 651 0.
Navigate to the 'Audits' module and select the 'BSI IT-Grundschutz' audit catalog. The wizard will guide you through all modules and requirements. You can document the degree of fulfillment, assign measures, and record deviations. Detailed instructions can be found in our user manual.
The generic risk analysis function enables flexible assessments. Create a new risk analysis, define risks, assess probability of occurrence and damage severity, and document measures. The risk analysis can be linked to assets, TOMs, and audits. The user manual contains step-by-step instructions.
Yes, preeco | information security supports multi-tenancy. As an external information security officer, you can manage multiple tenants centrally in one system. Each tenant has its own settings and documents. Switching between tenants is done with a single click. More information can be found in the user manual in the 'Tenant Management' section.
In the 'Training' module, you can conduct online training for your employees. Create training templates, assign participants, and monitor progress. Upon successful completion, certificates of participation are automatically generated. Follow-ups remind you of due refresher training. Detailed instructions can be found in our user manual.