ISMS FAQ#
Normalized security questionnaire for domainsearch24.eu, operated by botBrains GmbH. Companion to the compliance page.
Are you currently certified to ISO/IEC 27001? If yes, please provide the certificate and its scope. The service itself is not ISO/IEC 27001 certified. It is hosted exclusively in Hetzner Online GmbH data centers that are ISO 27001 certified (certificate available from Hetzner; scope: data center operations, Germany/Finland).
Do you operate a formal information security management programme or ISMS? Not a certified ISMS for this service. Security is managed through a documented, deliberately minimal posture: stateless service, no stored customer data, least-privilege deployment, hardened systemd units, and the practices described on the compliance page.
What information belonging to us will you access, process, store, or transmit? Only the domain names you submit for checking. They are processed in memory; availability results are cached keyed by domain (never by requester) for up to 24 hours. No accounts, no personal data, no documents.
In which countries/regions will our data be stored and processed? Germany and Finland (EU), in Hetzner data centers.
How do you control employee and administrator access to customer data? There is no stored customer data. Production access (servers, logs) is limited to named administrators of botBrains GmbH via key-based SSH.
Is MFA required for privileged accounts and systems containing customer data? Administrative access uses SSH public-key authentication; provider control panels (Hetzner) require MFA. No systems contain customer data.
Is customer data encrypted in transit and at rest? All traffic is TLS-encrypted in transit. At rest there is no customer data; operational caches contain only public DNS/registry facts.
Are employees with access to sensitive/customer information subject to appropriate screening, confidentiality obligations, and security training? Yes: staff operate under contractual confidentiality obligations; the operating team is small and senior.
Do you have documented vulnerability and patch-management processes? Yes, proportionate to the footprint: OS security patches are applied automatically (Ubuntu unattended-upgrades); application dependencies are reviewed and updated with each deploy.
Do you perform vulnerability scanning and/or penetration testing regularly? Internal adversarial review accompanies feature work. No external penetration test has been commissioned yet; external findings are welcome under our vulnerability disclosure policy.
Do you maintain and test an information-security incident-response process? Yes, sized to the service: on-call operator, journalized logs, and a redeploy-from-repository recovery path that is exercised with every release.
How quickly will you notify us of a security incident affecting our data or services? Without undue delay and within 72 hours of confirming a material incident, via this site and email to known API-key holders.
Do you maintain and periodically test business continuity and disaster-recovery arrangements? The service is stateless; recovery equals redeployment (a single script) plus automatic cache rebuild from public sources. This path is exercised with every deployment.
Are backups performed and tested, and are they appropriately protected? There is no customer data to back up. Code and configuration are version-controlled; caches rebuild automatically.
Do you use subcontractors/subprocessors to deliver the service? One: Hetzner Online GmbH (hosting, EU). See subprocessors.
How do you assess the information-security risks of your own critical suppliers/subprocessors? Suppliers are chosen for certified baselines (Hetzner: ISO 27001, EU jurisdiction) and reviewed when the service's architecture changes.
Will you notify us of significant changes to your service, infrastructure, subprocessors, or security controls? Yes: changes are published on the compliance and subprocessors pages; API-key holders are notified by email of breaking or security-relevant changes.
What security/privacy regulations and contractual requirements apply to the service? GDPR (EU processing, German operator), German DDG for the imprint, and the service's published terms and privacy policy.
Can you provide relevant independent assurance reports, such as ISO 27001, SOC 2, penetration-test summaries, or equivalent? We can provide Hetzner's ISO 27001 certificate for the hosting layer. No SOC 2 or service-level penetration-test reports exist yet.
What happens to our information when the contract ends, including deletion, return, backups, and account termination? Nothing needs to happen: no accounts and no stored customer data exist. API keys are revoked on request; caches expire within 24 hours on their own.
How do you monitor the effectiveness of your security controls and address identified deficiencies? Service health and logs are monitored continuously; deficiencies feed directly into the (short) deployment cycle. External reports come in via the disclosure policy and are triaged within 10 business days.
Have you experienced any material security incidents relevant to the service in the last 24 months? If yes, what remediation was performed? No.
Last updated: August 2026.