# ISMS FAQ

Normalized security questionnaire for domainsearch24.eu, operated by
botBrains GmbH. Companion to the [compliance](/legal/compliance) page.

**Are you currently certified to ISO/IEC 27001? If yes, please provide the certificate and its scope.**
The service itself is not ISO/IEC 27001 certified. It is hosted
exclusively in Hetzner Online GmbH data centers that are ISO 27001
certified (certificate available from Hetzner; scope: data center
operations, Germany/Finland).

**Do you operate a formal information security management programme or ISMS?**
Not a certified ISMS for this service. Security is managed through a
documented, deliberately minimal posture: stateless service, no stored
customer data, least-privilege deployment, hardened systemd units, and
the practices described on the compliance page.

**What information belonging to us will you access, process, store, or transmit?**
Only the domain names you submit for checking. They are processed in
memory; availability results are cached keyed by domain (never by requester) for up
to 24 hours. No accounts, no personal data, no documents.

**In which countries/regions will our data be stored and processed?**
Germany and Finland (EU), in Hetzner data centers.

**How do you control employee and administrator access to customer data?**
There is no stored customer data. Production access (servers, logs) is
limited to named administrators of botBrains GmbH via key-based SSH.

**Is MFA required for privileged accounts and systems containing customer data?**
Administrative access uses SSH public-key authentication; provider
control panels (Hetzner) require MFA. No systems contain customer data.

**Is customer data encrypted in transit and at rest?**
All traffic is TLS-encrypted in transit. At rest there is no customer
data; operational caches contain only public DNS/registry facts.

**Are employees with access to sensitive/customer information subject to appropriate screening, confidentiality obligations, and security training?**
Yes: staff operate under contractual confidentiality obligations; the
operating team is small and senior.

**Do you have documented vulnerability and patch-management processes?**
Yes, proportionate to the footprint: OS security patches are applied
automatically (Ubuntu unattended-upgrades); application dependencies
are reviewed and updated with each deploy.

**Do you perform vulnerability scanning and/or penetration testing regularly?**
Internal adversarial review accompanies feature work. No external
penetration test has been commissioned yet; external findings are
welcome under our [vulnerability disclosure policy](/legal/vulnerability-disclosure-policy).

**Do you maintain and test an information-security incident-response process?**
Yes, sized to the service: on-call operator, journalized logs, and a
redeploy-from-repository recovery path that is exercised with every
release.

**How quickly will you notify us of a security incident affecting our data or services?**
Without undue delay and within 72 hours of confirming a material
incident, via this site and email to known API-key holders.

**Do you maintain and periodically test business continuity and disaster-recovery arrangements?**
The service is stateless; recovery equals redeployment (a single
script) plus automatic cache rebuild from public sources. This path is
exercised with every deployment.

**Are backups performed and tested, and are they appropriately protected?**
There is no customer data to back up. Code and configuration are
version-controlled; caches rebuild automatically.

**Do you use subcontractors/subprocessors to deliver the service?**
One: Hetzner Online GmbH (hosting, EU). See
[subprocessors](/legal/subprocessors).

**How do you assess the information-security risks of your own critical suppliers/subprocessors?**
Suppliers are chosen for certified baselines (Hetzner: ISO 27001, EU
jurisdiction) and reviewed when the service's architecture changes.

**Will you notify us of significant changes to your service, infrastructure, subprocessors, or security controls?**
Yes: changes are published on the compliance and subprocessors pages;
API-key holders are notified by email of breaking or security-relevant
changes.

**What security/privacy regulations and contractual requirements apply to the service?**
GDPR (EU processing, German operator), German DDG for the imprint, and
the service's published terms and privacy policy.

**Can you provide relevant independent assurance reports, such as ISO 27001, SOC 2, penetration-test summaries, or equivalent?**
We can provide Hetzner's ISO 27001 certificate for the hosting layer.
No SOC 2 or service-level penetration-test reports exist yet.

**What happens to our information when the contract ends, including deletion, return, backups, and account termination?**
Nothing needs to happen: no accounts and no stored customer data exist.
API keys are revoked on request; caches expire within 24 hours on their
own.

**How do you monitor the effectiveness of your security controls and address identified deficiencies?**
Service health and logs are monitored continuously; deficiencies feed
directly into the (short) deployment cycle. External reports come in
via the disclosure policy and are triaged within 10 business days.

**Have you experienced any material security incidents relevant to the service in the last 24 months? If yes, what remediation was performed?**
No.

---

Last updated: August 2026.
