Skip to main content
ISMS – Information Security Management System

preeco | information security

The complete ISMS for German organizations – from risk analysis through technical and organizational controls and audits to continuous improvement. ISO 27001, BSI IT-Grundschutz, CISIS12 and VdA ISA as ready-to-use catalogs in one integrated system – available as Cloud, Private Cloud, or On-Premises, hosted exclusively in Germany.

Hosting ISO 27001
BSI IT-Grundschutz
CISIS12 & VdA ISA
Hosted in Germany
app.preeco.de

ISMS

One complete ISMS in a single system

preeco | information security connects assets, risks, controls, audits, and training into one seamless information security management system – built for continuous improvement.

A management system, not data silos

Every ISMS building block interlocks: assets, risks, TOMs, audits, and training are directly linked – no spreadsheet chaos, no media breaks.

Built to the standards

BSI IT-Grundschutz, CISIS12, and VdA ISA are ready to use as predefined, instantly deployable audit catalogs – no assembly and no lead time. ISO 27001 conformity is steered via requirement catalogs with a heatmap cockpit, maturity level and Statement of Applicability.

Audit-proof and revision-safe

Seamless activity logs and automatic version control make every change verifiable at any time – for internal and external audits alike.

Continuous improvement

Assess risks, implement controls, conduct audits, adjust – follow-ups, recurring reports, and automatic version control keep your ISMS up to date.

Audits

Audits and Audit Catalogs

Plan, conduct, and document information security audits in a structured way. Ready-to-use audit catalogs for German-recognized standards: BSI IT-Grundschutz, CISIS12, and VdA ISA.

Audit Catalogs

Predefined and customizable questionnaire catalogs as the foundation for your audits. Structured, reusable, and applicable across multiple tenants.

Audits

Structured execution and traceable documentation of information security audits. Hierarchical audit object management with direct asset linking. Graphical progress display, export as PDF or DOCX.

Requirement Catalogs & Cockpit

Steer standards conformity via ready-to-use requirement catalogs – e.g. ISO 27001 or SiKoSH, the dedicated catalog for municipal information security. Exactly one catalog is activated per organization; its requirements are then available for assessment. Rate each requirement with implementation status and maturity level, document the Statement of Applicability (SoA) and capture exceptions. Use bulk editing for status, responsible persons and resubmissions across multiple requirements at once. If a catalog is available in several languages, the language is indicated in the selection. Upload evidence directly or request it via link – a dedicated evidence tab on each requirement shows existing evidence and open evidence requests. Have expiring evidence checked automatically and track the fulfillment progress in the cockpit as a heatmap, list or board – with dedicated tabs for open tasks and upcoming deadlines, an evidence worklist for outdated and open evidence, and an activities tab. The entire cockpit can be scoped to a single catalog or a single responsible person.

Risks

Risk Analyses

Assess risks systematically and document protection requirement analyses, resource assessments, threshold analyses, and threat analyses. With graphical risk mapping and automatic versioning.

Risk Analyses

Flexible risk analyses for any scenario – from protection requirement analyses to threat analyses. Free definition of events, assessment of damage and risk levels. Automatic versioning of all approved documents.

Controls

Security Controls and Policies

Manage policies and technical as well as organizational measures centrally. Link TOMs directly with assets and audits for comprehensive security documentation.

Policies

Create, version, and keep policies up to date through regular reviews – with follow-ups, linking to other documents, and a complete activity log for seamless traceability.

Technical and Organizational Measures

Documentation and versioning of TOMs with automatic revision control. Linking with data processing systems and audits – always audit-ready.

Assets

Asset Management

Manage assets as the central view of your organization's entire system inventory. Record responsibilities, provider details, and link assets directly with TOMs, audits, and risk analyses.

Assets

Central view of the entire system inventory with responsibilities, provider details, purpose descriptions, encryption, availability, NIS2 relevance, and vulnerabilities. Linking with TOMs, audits, and risk analyses. Automatic versioning and export for internal and external audits. The supplementary "Data Processing Systems" view optionally shows privacy-relevant systems in combination with the data protection module.

Protection Needs Assessment

Determine protection needs for confidentiality, integrity, and availability via a damage-scenario matrix based on the maximum principle – including the cumulative effect of linked systems, manually or AI-assisted.

Training

Training and Qualification

Plan, conduct, and document information security training for your employees. Training participation is automatically tracked and certified.

Training

Conduct online training directly in the software. Learning units with image and video content, multiple-choice and single-choice exam questions with configurable minimum score.

Training Participation

Recording and verification of all training participation. Overview of the training status of all employees at a glance. Add participants manually or import via XLSX.

Training Templates

Predefined training templates as a starting point. Customizable to your organization-specific requirements and ready to use.

Reporting

Reporting and Activities

Create comprehensive status reports and keep track of all activities. Complete documentation of all changes for maximum transparency and audit security.

Activities

Automatic log of all document changes – including administrative actions on user accounts such as inviting, removing, activating and deactivating. Seamless traceability with timestamp, user, and performed action – for audits and compliance verification.

Reports

Status reports with details on all documents and automatically generated table of contents.

Revision Security

Every approval creates an immutable revision (as PDF/ZIP or HTML). Two revisions can be compared visually, with changes highlighted by color (additions green, removals red). Stored SHA-256 checksums make the integrity of each revision verifiable, detecting any subsequent tampering. Comparison and integrity verification are available for revisions created from the introduction of this feature onwards; older revisions cannot be compared or verified retroactively.

Incidents

Incident Management

Capture, assess, and document security incidents and data breaches in a structured way. Keep reporting obligations, deadlines, and measures in view at all times.

Incident Capture

Capture security incidents and data breaches centrally via a structured form – with categories, severity, and automatic assessment of statutory reporting obligations and deadlines.

Measures, Reports, and Lessons Learned

Steer the handling of an incident from intake to follow-up. A hierarchical measure structure, custom report templates, and graphical risk mapping bring all steps together in one place.

Features

Collaboration and Task Management

Manage tasks, checklists, files, and messages centrally in one place. All stakeholders stay informed – thanks to dashboard and follow-ups.

Tasks

Create and assign tasks directly within documents. The dashboard shows all open tasks at a glance. Email notifications ensure timely action.

Checklists

Multiple-choice checklists for quality assurance. Use template checklists or create your own. Results exportable as PDF or DOCX.

File Storage

Central upload and structured storage of documents. Tags and nestable folders facilitate organization. Files optionally shareable via public URL.

Messages

Internal communication directly in the system. Attach files, email notifications for new messages. Complete tracking of all communication.

Surveys

Create your own surveys with question types such as selection, multiple choice, text and date. Analysis and download as PDF or DOCX. Usable independently or linked to documents.

Follow-ups

Scheduled reminders for all due tasks. Observers are automatically notified. No deadline is missed.

Contacts

Central management of all contacts with structured forms. Linking with other documents, tags, and follow-ups.

Tags

Flexible tagging of all documents. Tags can be created per team and are filterable in all overviews.

Text Blocks

Reusable text blocks in a filterable, tabular overview. Creation and maintenance controllable via user permissions. Make blocks available to specific organizations or to all organizations.

AI Functions

AI-assisted enrichment and revision of content in policies, TOMs and incidents. Multi-edit in overviews for efficient work. Optionally configurable via LLM provider integration – with a selection list of the models available at the provider or free entry of a model name. In addition, all AI activities are logged in a traceable protocol with function, executing person, model, status, duration, and token consumption.

DeepL Integration

Automatic translation of document content into all 25 available languages via the DeepL API. Optional add-on.

Multilingual

The user interface and documents are available in 25 languages – ideal for international teams and multilingual organizations. Each user selects their own interface language, independently of the language of the documents they create.

Confidentiality Classes

Optional confidentiality classes for documents – configurable per user group and fully disableable for individual user groups, in addition to role permissions. This protects sensitive ISMS content such as risk analyses, audit results, or incidents from unauthorized access. The display of the implementation status on documents is also enabled per user group (disabled by default). This is complemented by a multi-level permission concept with granular rights at module, document and function level.

Monthly Updates

Roughly monthly updates deliver new features, improvements, and short-notice security updates when needed – distributed automatically, without prior notice and without downtime. All hosting options are always kept up to date.

Global Search & Customizable Overviews

Invoke global search via the ⌘/Ctrl+K shortcut from anywhere in the application. Customize overview tables individually – column order and width are saved per view. Every document also displays its links in the Relationships tab as a graphical origin view – including counters for linked entries that are inaccessible to the user.

Switch Product View

Information security and data protection on one shared platform with a common data basis: with both products licensed, you work with a unified data set – for example for assets and data processing systems – and switch your working environment between the information security and data protection views with a single toggle.

Tenant and Organization Structure

Manage multiple organizations or sites in one team and switch with a single click via the organization selector. On Private Cloud and On-Premises, multiple teams can be operated on one platform with physical separation.

Email Communication in Your Own Name

Email signatures and sender address are customizable. In Private Cloud and On-Premises you can optionally use your own mail server.

Document Branding

Custom logos per organization, an adjustable font and freely configurable headers and footers for exported documents. The legal notice (imprint) of the responsible organization can be output optionally. Per document type you control whether the names and positions of the information security and data protection officers appear – company name, address, telephone and email are always fully included.

Designed for Accessibility

Keyboard operability, semantically structured HTML, sufficient contrast, scalable font sizes and alternative texts for graphics. Accessibility is continuously reviewed and improved. Read our accessibility statement

Security

Security in Development and Operations

preeco | information security is developed following the Security by Design and Security by Default principles – backed by regular security reviews.

Internal Penetration Tests

Regular internal security reviews of the application uncover vulnerabilities before they become a risk.

Security Updates

Continuous monitoring and prompt remediation of security vulnerabilities – distributed as short-notice security updates when needed.

Code Reviews

Regular review of the program code for security vulnerabilities as an integral part of the development process.

Network and Data Centre Security

Firewall, DDoS protection and network segmentation protect the systems in the ISO 27001-certified data centres of Hetzner Online GmbH in Germany. Continuous monitoring of system availability plus physical security, fire protection and power supply via uninterruptible UPS and diesel generators.

Choose Your Hosting Option

Three options – Cloud, Private Cloud, or On-Premises on your own infrastructure. Cloud and Private Cloud are operated exclusively in ISO 27001-certified data centers in Germany; On-Premises gives you full data sovereignty.

Cloud and Private Cloud options are hosted in ISO 27001-certified data centers of Hetzner Online GmbH in Germany (Nuremberg, Falkenstein). The data centers run on 100% green electricity. Personal data is not transmitted to third countries. Daily backups with 7-day retention, AES-256 encrypted as password-protected archives, and daily off-site backup at the Hetzner Falkenstein data center. Guaranteed availability: 99.0% per calendar month. Deployment within 48 hours (business days). No setup fees and no cancellation periods. All data transmissions are continuously SSL/TLS-encrypted.

Support

Deployment, Support & Service Level

Fast deployment, personal assistance and clearly defined service hours – from onboarding to daily operations.

Fixed Service Hours

Our support team is available Monday to Friday from 9:00 a.m. to 5:00 p.m. in German and English (except on public holidays in Germany) – via email, ticket system and, subject to availability, online chat. Phone and video-conference support can be added as optional premium support.

Guaranteed Response Times

Clearly defined response times by priority: in the Private Cloud from 2 business hours for critical incidents to 3 working days for general inquiries, in the Cloud from 4 business hours to 5 working days. Extended 24/7 on-call support is optionally available. If response times are not met, a multi-level escalation process applies, up to executive management.

Deployment within 48 Hours

Cloud and Private Cloud instances are provisioned within 48 hours (on working days); On-Premises installations by individual agreement. Get started without long lead times.

Updates without Downtime

The software is generally available 24/7. Updates are rolled out automatically about once a month without downtime; security updates are applied at short notice when needed. After each update, a pop-up in the application transparently shows the changes made. Longer maintenance work is announced in advance.

Onboarding and Training

A dedicated contact person accompanies your onboarding: setup of the organizational structure, configuration of user groups and permissions, and individual adjustments such as corporate design and email templates. Data migration and training are optionally available.

Interfaces and API

The application is designed as a self-contained system; a public REST API is currently not available. For Private Cloud and On-Premises variants, customer-specific API endpoints can be developed and provided.

Professionalize your ISMS now

In a personal consultation, we'll show you how preeco | information security simplifies your security management.

What makes good ISMS software for ISO 27001?

Good ISMS software for ISO 27001 brings requirements, evidence, measures and audits together in one place and makes the degree of fulfillment visible at any time — instead of maintaining documents in scattered spreadsheets and shared drives. preeco | information security meets these needs with ready-to-use requirement catalogs for ISO/IEC 27001, BSI IT-Grundschutz, CISIS12 and VdA ISA in one integrated system.

  • Control standard compliance: every requirement is rated with implementation status and maturity, including a documented Statement of Applicability (SoA) with justifications and exceptions.

  • Manage evidence: upload evidence directly on the requirement or request it via link — expiring evidence is checked automatically.

  • See the degree of fulfillment: the cockpit shows the status as a heatmap, list or board — with dedicated tabs for open tasks, upcoming deadlines and a worklist for outdated evidence.

  • Link everything: assets, risk analyses, TOMs, audits and training are directly connected instead of being maintained in isolated tools.

  • Document verifiably: every approval creates an immutable revision with a SHA-256 checksum, and the activity log keeps all changes traceable — as the basis for internal and external audits.

  • Host with sovereignty: Cloud, Private Cloud or On-Premises — Cloud and Private Cloud exclusively in ISO 27001-certified data centers in Germany. preeco GmbH itself is not ISO 27001 certified; the software supports you in building and operating an ISO/IEC 27001-conformant ISMS.

This makes preeco | information security suitable for organizations building, operating or preparing for certification of an ISO 27001-conformant information security management system — from mid-sized companies to large enterprises.

FAQ

Frequently Asked Questions

You will receive your login credentials by email after registration. Go to the login page and enter your email address and password. If you encounter any issues, please contact our support at support@preeco.de or +49 731 280 651 0.

Navigate to the 'Audits' module and select the 'BSI IT-Grundschutz' audit catalog. The wizard will guide you through all modules and requirements. You can document the degree of fulfillment, assign measures, and record deviations. Detailed instructions can be found in our user manual.

The generic risk analysis function enables flexible assessments. Create a new risk analysis, define risks, assess probability of occurrence and damage severity, and document measures. The risk analysis can be linked to assets, TOMs, and audits. The user manual contains step-by-step instructions.

Yes, preeco | information security supports multi-tenancy. As an external information security officer, you can manage multiple tenants centrally in one system. Each tenant has its own settings and documents. Switching between tenants is done with a single click. More information can be found in the user manual in the 'Tenant Management' section.

In the 'Training' module, you can conduct online training for your employees. Create training templates, assign participants, and monitor progress. Upon successful completion, certificates of participation are automatically generated. Follow-ups remind you of due refresher training. Detailed instructions can be found in our user manual.

Yes. preeco | information security ships with ready-to-use requirement catalogs for ISO/IEC 27001: you rate each requirement with implementation status and maturity, document the Statement of Applicability (SoA) and record justified exceptions. A cockpit shows the degree of fulfillment as a heatmap, list or board, evidence is requested via link or uploaded directly, and expiring evidence is checked automatically. preeco GmbH itself is not ISO 27001 certified — the software supports you in building and operating an ISO/IEC 27001-conformant ISMS and is hosted in ISO 27001-certified data centers in Germany.

Yes. preeco | information security is built for the mid-market: the asset module lets you inventory your system landscape including protection needs and NIS2 relevance, TOMs and risk analyses can be created from templates with optional AI support, and the CISIS12 catalog provides a practice-oriented SME standard with all 12 modules ready to use. The software is multi-tenant, so external information security officers can manage multiple clients in one system; Cloud and Private Cloud instances are typically provisioned within 48 hours. With both products licensed, information security and data protection run in one shared software.

Yes. Via the ISO/IEC 27001 requirement catalog you document the Statement of Applicability (SoA) directly in the software: each requirement is rated with implementation status and maturity, applicability and exceptions are recorded with justifications, and evidence can be uploaded directly on the respective requirement or requested via link. The degree-of-fulfillment history remains traceable in the cockpit as a heatmap, list or board, and reports can be exported as PDF or DOCX.

preeco | information security supports mid-sized companies in implementing NIS2: TOMs are documented continuously and linked to assets and risk analyses, NIS2 relevance is flagged per asset, and cyber incidents are recorded and reported in a structured way. Nine reporting templates are included — early warning, notification and final report to the BSI (NIS-2, § 32 BSIG) plus the KRITIS disruption notification (§ 25 BSIG) — and the NIS2 deadlines (24-hour early warning, 72-hour notification, 1-month final report) are monitored automatically. An included NIS2 training for management serves as proof of the training obligation for management bodies. Whether your organization falls within the scope of the NIS2 Directive requires a legal assessment that the software does not replace.

preeco | information security builds the evidence base for your certification project: via the ISO/IEC 27001 requirement catalog you rate each requirement by status and maturity, document the Statement of Applicability with justifications and exceptions, and link evidence directly to the relevant requirement. Every approval creates an immutable revision with a SHA-256 checksum, the activity log keeps all changes traceable, and reports can be exported as PDF or DOCX. The certificate itself is issued by an accredited certification body — the software provides the audit-ready documentation for it.