Last Updated: 21.7.2026
1. Introduction & Purpose
This document outlines the Technical and Organizational Measures (TOMs) implemented by Superhack to safeguard the secure operation of our platform and to protect the confidentiality, integrity, and availability of the information entrusted to us by our customers. It supports compliance with relevant laws and regulations, including the German Federal Data Protection Act (BDSG) and the EU General Data Protection Regulation (GDPR), particularly Article 32, which mandates appropriate technical and organizational measures to protect data.
2. Scope
The measures outlined in this document apply to Superhack's internal processes and to the operation of the Superhack platform, including the customer data and the testing data we process when delivering our services. The scope covers Superhack's internal systems, the platform infrastructure, the data our AI agents gather from customer systems during authorized testing, and any third-party systems used as part of service delivery.
3. Roles & Responsibilities
Superhack and its customers share the goal of improving the customer's security, but responsibility is clearly divided. Superhack is responsible for the secure operation of its platform and for protecting the information entrusted to it; customers are responsible for acting on the findings and insights that Superhack provides.
- Superhack: Is responsible for the secure operation of the platform and everything connected to it, and for safeguarding the confidentiality, integrity, and availability of the information entrusted to us — including the vulnerabilities and findings our AI agents discover in customer systems. We deliver these findings, together with context and remediation guidance, through the platform.
- Customers: Retain full responsibility for their own environments, systems, and data. Superhack identifies and surfaces security weaknesses, but it does not remediate them. Customers are responsible for handling the findings and insights we provide responsibly and confidentially, prioritizing them, and driving the identified issues through to remediation — as well as for meeting their own regulatory and compliance obligations.
4. Organizational and Technical Measures
Superhack employs a comprehensive blend of organizational and technical controls to secure its applications, systems, and information, and everything connected to the operation of the platform and the data we process on behalf of our customers.
4.1 Security Governance & Policies
- Governance: Security oversight is managed by our Managing Director(s), ensuring that Superhack consistently adheres to its own high standards.
- Policies: Superhack implements strict internal security policies, covering topics such as incident management, access control, and data security. We hold our own operations to the same rigorous security standards that our platform helps our customers achieve, ensuring alignment with best practices and demonstrating our commitment to security excellence.
4.2 Staffing and Security
- Trusted Employees: Superhack exclusively works with employed personnel, ensuring that everyone involved in operating the platform and delivering our services is well-trained, accountable, and fully integrated into our internal security processes.
- Limited Use of Freelancers: Superhack does not typically engage freelancers in the delivery of its services. If demand arises and external resources are required, freelancers are only brought in under explicit controls and agreements, ensuring that they meet the same rigorous security standards as our employees.
- Background Checks: Employees undergo background checks when required by regulatory standards or customer agreements, ensuring trustworthiness and adherence to security protocols.
- Small, Contained Team: Superhack operates as a small, contained team, allowing for tighter oversight and higher control over all security-related activities, ensuring the quality and confidentiality of all services provided.
- Employee Training: Adequate training on data protection, secure coding, and incident response ensures all employees follow best practices.