Skip to main content
ISMS – Information Security Management System

preeco | information security

The complete ISMS for German organizations – from risk analysis through technical and organizational controls and audits to continuous improvement. ISO 27001, BSI IT-Grundschutz, CISIS12 and VdA ISA in one integrated system, hosted in Germany.

Hosting ISO 27001
BSI IT-Grundschutz
CISIS12 & VdA ISA
Hosted in Germany
app.preeco.de

ISMS

One complete ISMS in a single system

preeco | information security connects assets, risks, controls, audits, and training into one seamless information security management system – built for continuous improvement.

A management system, not data silos

Every ISMS building block interlocks: assets, risks, TOMs, audits, and training are directly linked – no spreadsheet chaos, no media breaks.

Built to the standards

BSI IT-Grundschutz, CISIS12, and VdA ISA are ready to use as predefined audit catalogs. ISO 27001 conformity is steered via requirement catalogs with a heatmap cockpit, maturity level and Statement of Applicability.

Audit-proof and revision-safe

Seamless activity logs and automatic version control make every change verifiable at any time – for internal and external audits alike.

Continuous improvement

Assess risks, implement controls, conduct audits, adjust – follow-ups, recurring reports, and automatic version control keep your ISMS up to date.

Audits

Audits and Audit Catalogs

Plan, conduct, and document information security audits in a structured way. Ready-to-use audit catalogs for German-recognized standards: BSI IT-Grundschutz, CISIS12, and VdA ISA.

Audit Catalogs

Predefined and customizable questionnaire catalogs as the foundation for your audits. Structured, reusable, and applicable across multiple tenants.

Audits

Structured execution and audit-proof documentation of information security audits. Hierarchical audit object management with direct asset linking. Graphical progress display, export as PDF or DOCX.

Requirement Catalogs & Cockpit

Steer ISO 27001 conformity via ready-to-use requirement catalogs. Rate each requirement with implementation status and maturity level, document the Statement of Applicability (SoA) and capture exceptions. Use bulk editing for status, responsible persons and resubmissions across multiple requirements at once. Request evidence via link, have expiring evidence checked automatically and track the fulfillment progress in the cockpit as a heatmap, list or board – with dedicated tabs for open tasks and upcoming deadlines.

Risks

Risk Analyses

Assess risks systematically and document protection requirement analyses, resource assessments, and threat analyses. With graphical risk mapping and automatic versioning.

Risk Analyses

Flexible risk analyses for any scenario – from protection requirement analyses to threat analyses. Free definition of events, assessment of damage and risk levels. Automatic versioning of all approved documents.

Controls

Security Controls and Policies

Manage policies and technical as well as organizational measures centrally. Link TOMs directly with assets and audits for comprehensive security documentation.

Policies

Create, version, and keep policies up to date through regular reviews – with follow-ups, linking to other documents, and a complete activity log for seamless traceability.

Technical and Organizational Measures

Documentation and versioning of TOMs with automatic revision control. Linking with data processing systems and audits – always audit-ready.

Assets

Asset Management

Manage assets as the central view of your organization's entire system inventory. Record responsibilities, provider details, and link assets directly with TOMs, audits, and risk analyses.

Assets

Central view of the entire system inventory with responsibilities, provider details, purpose descriptions, encryption, availability, NIS2 relevance, and vulnerabilities. Linking with TOMs, audits, and risk analyses. Automatic versioning and export for internal and external audits. The supplementary "Data Processing Systems" view optionally shows privacy-relevant systems in combination with the data protection module.

Protection Needs Assessment

Determine protection needs for confidentiality, integrity, and availability via a damage-scenario matrix based on the maximum principle – including the cumulative effect of linked systems, manually or AI-assisted.

Training

Training and Qualification

Plan, conduct, and document information security training for your employees. Training participation is automatically tracked and certified.

Training

Conduct online training directly in the software. Learning units with image and video content, multiple-choice and single-choice exam questions with configurable minimum score.

Training Participation

Recording and verification of all training participation. Overview of the training status of all employees at a glance. Add participants manually or import via XLSX.

Training Templates

Predefined training templates as a starting point. Customizable to your organization-specific requirements and ready to use.

Reporting

Reporting and Activities

Create comprehensive status reports and keep track of all activities. Complete documentation of all changes for maximum transparency and audit security.

Activities

Automatic log of all document changes. Seamless traceability with timestamp, user, and performed action – for audits and compliance verification.

Reports

Status reports with details on all documents and automatically generated table of contents.

Revision Security

Every approval creates an immutable revision. Two revisions can be compared visually, with changes highlighted by color (additions green, removals red). Stored SHA-256 checksums make the integrity of each revision verifiable, detecting any subsequent tampering.

Incidents

Incident Management

Capture, assess, and document security incidents and data breaches in a structured way. Keep reporting obligations, deadlines, and measures in view at all times.

Incident Capture

Capture security incidents and data breaches centrally via a structured form – with categories, severity, and automatic assessment of statutory reporting obligations and deadlines.

Measures, Reports, and Lessons Learned

Steer the handling of an incident from intake to follow-up. A hierarchical measure structure, custom report templates, and graphical risk mapping bring all steps together in one place.

Features

Collaboration and Task Management

Manage tasks, checklists, files, and messages centrally in one place. All stakeholders stay informed – thanks to dashboard and follow-ups.

Tasks

Create and assign tasks directly within documents. The dashboard shows all open tasks at a glance. Email notifications ensure timely action.

Checklists

Multiple-choice checklists for quality assurance. Use template checklists or create your own. Results exportable as PDF or DOCX.

File Storage

Central upload and structured storage of documents. Tags and nestable folders facilitate organization. Files optionally shareable via public URL.

Messages

Internal communication directly in the system. Attach files, email notifications for new messages. Complete tracking of all communication.

Surveys

Create your own surveys with various question types. Analysis and download as PDF or DOCX. Usable independently or linked to documents.

Follow-ups

Scheduled reminders for all due tasks. Observers are automatically notified. No deadline is missed.

Contacts

Central management of all contacts with structured forms. Linking with other documents, tags, and follow-ups.

Tags

Flexible tagging of all documents. Tags can be created per team and are filterable in all overviews.

Text Modules

Reusable text modules in a filterable, tabular overview. Creation and maintenance controllable via user permissions. Make modules available to specific organizations or to all organizations.

AI Functions

AI-assisted enrichment and revision of content in policies, TOMs and incidents. Multi-edit in overviews for efficient work. Optionally configurable via LLM provider integration.

DeepL Integration

Automatic translation of document content into all 25 available languages via the DeepL API. Optional add-on.

Multilingual

The user interface and documents are available in 25 languages – ideal for international teams and multilingual organizations.

Confidentiality Classes

Optional confidentiality classes for documents – configurable per user group. Sensitive content receives additional access protection.

Monthly Updates

Roughly monthly updates deliver new features, improvements, and short-notice security updates when needed – distributed automatically, without prior notice and without downtime. All hosting options are always kept up to date.

Global Search & Customizable Overviews

Invoke global search via the ⌘/Ctrl+K shortcut from anywhere in the application. Customize overview tables individually – column order and width are saved per view.

Switch Product View

Information security and data protection on one shared platform: with both products licensed, switch your working environment between the information security and data protection views with a single toggle.

Designed for Accessibility

Keyboard operability, semantically structured HTML, sufficient contrast, scalable font sizes and alternative texts for graphics. Accessibility is continuously reviewed and improved. Read our accessibility statement

Security

Security in Development and Operations

preeco | information security is developed following the Security by Design and Security by Default principles – backed by regular security reviews.

Internal Penetration Tests

Regular internal security reviews of the application uncover vulnerabilities before they become a risk.

Security Updates

Continuous monitoring and prompt remediation of security vulnerabilities – distributed as short-notice security updates when needed.

Code Reviews

Regular review of the program code for security vulnerabilities as an integral part of the development process.

Choose Your Hosting Option

Flexible, secure, and tailored to your needs — choose the right hosting solution.

Cloud and Private Cloud options are hosted in ISO 27001-certified data centers of Hetzner Online GmbH in Germany (Nuremberg, Falkenstein). The data centers run on 100% green electricity. Daily backups with 7-day retention, AES-256 encrypted as password-protected archives, and daily off-site backup at the Hetzner Falkenstein data center. Guaranteed availability: 99.0% per calendar month. Deployment within 48 hours (business days). No setup fees and no cancellation periods. All data transmissions are continuously SSL/TLS-encrypted.

Support

Deployment, Support & Service Level

Fast deployment, personal assistance and clearly defined service hours – from onboarding to daily operations.

Fixed Service Hours

Our support team is available Monday to Friday from 9:00 a.m. to 5:00 p.m. in German and English (except on public holidays in Germany) – via email, ticket system and, subject to availability, online chat. Phone and video-conference support can be added as optional premium support.

Guaranteed Response Times

Clearly defined response times by priority – identical in Cloud and Private Cloud: from 2 business hours for critical incidents to 3 working days for general inquiries. Extended 24/7 on-call support is optionally available. If response times are not met, a multi-level escalation process applies, up to executive management.

Deployment within 48 Hours

Cloud and Private Cloud instances are provisioned within 48 hours (on working days); On-Premises installations by individual agreement. Get started without long lead times.

Updates without Downtime

The software is generally available 24/7. Updates are rolled out automatically about once a month without downtime; security updates are applied at short notice when needed. After each update, a pop-up in the application transparently shows the changes made. Longer maintenance work is announced in advance.

Onboarding and Training

A dedicated contact person accompanies your onboarding: setup of the organizational structure, configuration of user groups and permissions, and individual adjustments such as corporate design and email templates. Data migration and training are optionally available.

Interfaces and API

The application is designed as a self-contained system; a public REST API is currently not available. For Private Cloud and On-Premises variants, customer-specific API endpoints can be developed and provided.

Professionalize your ISMS now

In a personal consultation, we'll show you how preeco | information security simplifies your security management.

FAQ

Frequently Asked Questions

You will receive your login credentials by email after registration. Go to the login page and enter your email address and password. If you encounter any issues, please contact our support at support@preeco.de or +49 731 280 651 0.

Navigate to the 'Audits' module and select the 'BSI IT-Grundschutz' audit catalog. The wizard will guide you through all modules and requirements. You can document the degree of fulfillment, assign measures, and record deviations. Detailed instructions can be found in our user manual.

The generic risk analysis function enables flexible assessments. Create a new risk analysis, define risks, assess probability of occurrence and damage severity, and document measures. The risk analysis can be linked to assets, TOMs, and audits. The user manual contains step-by-step instructions.

Yes, preeco | information security supports multi-tenancy. As an external information security officer, you can manage multiple tenants centrally in one system. Each tenant has its own settings and documents. Switching between tenants is done with a single click. More information can be found in the user manual in the 'Tenant Management' section.

In the 'Training' module, you can conduct online training for your employees. Create training templates, assign participants, and monitor progress. Upon successful completion, certificates of participation are automatically generated. Follow-ups remind you of due refresher training. Detailed instructions can be found in our user manual.