Last Updated: 21.7.2026

1. Introduction & Purpose

This document outlines the Technical and Organizational Measures (TOMs) implemented by Superhack to safeguard the secure operation of our platform and to protect the confidentiality, integrity, and availability of the information entrusted to us by our customers. It supports compliance with relevant laws and regulations, including the German Federal Data Protection Act (BDSG) and the EU General Data Protection Regulation (GDPR), particularly Article 32, which mandates appropriate technical and organizational measures to protect data.

2. Scope

The measures outlined in this document apply to Superhack's internal processes and to the operation of the Superhack platform, including the customer data and the testing data we process when delivering our services. The scope covers Superhack's internal systems, the platform infrastructure, the data our AI agents gather from customer systems during authorized testing, and any third-party systems used as part of service delivery.

3. Roles & Responsibilities

Superhack and its customers share the goal of improving the customer's security, but responsibility is clearly divided. Superhack is responsible for the secure operation of its platform and for protecting the information entrusted to it; customers are responsible for acting on the findings and insights that Superhack provides.

4. Organizational and Technical Measures

Superhack employs a comprehensive blend of organizational and technical controls to secure its applications, systems, and information, and everything connected to the operation of the platform and the data we process on behalf of our customers.

4.1 Security Governance & Policies

4.2 Staffing and Security