Compliance
Quality management & information security
Your HR data in safe hands – certified, audited and hosted exclusively on German servers.
Documented and continuously improved
Quality management
Our quality management system aims to continuously improve the quality of our services and processes. It is based on a comprehensive system in accordance with the principles of DIN EN ISO 9001. This includes regular audits, customer surveys and internal process evaluations to ensure that our services meet the highest quality standards. Through continuous improvement and optimisation of our processes, we guarantee the highest quality and reliability for our customers.
Quality management
We continuously monitor and improve our processes and services and ensure a smooth flow of information via a company-wide intranet.
Compliance Management
Through a well-maintained legal register and membership in established industry committees, we ensure compliance with laws, regulations and industry standards.
Audit and monitoring process
Our processes and services are regularly checked and monitored by internal and external audits conducted by independent external inspection bodies.
Comprehensive reporting
All customer documents and reports are available in full and updated daily via our document cloud. This means that all details can be accessed and checked right from the acquisition phase.
Protecting your data – in every case
Information security
Our information security management system, which complies with the controls of DIN EN ISO 27001:2022, ensures that all processed data is accurate, up to date and protected. It covers the classification, storage, processing and backup of information, as well as clear access control and monitoring. This enables us to guarantee the highest standards of security and data protection and to store our customers’ information reliably.
Data security
Strict adherence to confidentiality, integrity and availability. Through regular security audits and penetration tests, as well as geo-redundant backups and no data transfer outside the EEA.
Development in Germany
Our software is developed entirely in Germany and complies with high documented and audited quality standards. Our experienced developers follow proven best practices in the respective industries.
Access control
Authentication is carried out using secure login procedures, while role-based access controls and restrictions on certain data and functions ensure targeted authorisation.
Hosting in Germany
Hosting takes place exclusively in German data centres, such as noris network, which meet the highest information security requirements and are certified in accordance with German law.
Not a stopgap solution, but experience
Industry standards
When it comes to HR management tools, we strive to set the highest standards in the industry. We understand that the security and protection of your data is of utmost importance, which is why we have designed our solutions to meet the most stringent requirements of banks, government agencies and private sector companies. Our goal is not to provide makeshift solutions, but to focus on proven best practices and optimise our services to meet your needs.
Banking sector
Compliance with MaRisk, KWG, GWG and other banking-specific regulations. As a member of the DSGV Sounding Board, we are always up to date.
Authorities
Strict compliance with the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and other authority-specific regulations.
Free market
Compliance with industry standards such as ISO 27001:2022, ISO 9001 and other cross-industry regulations.
Best practices
Compliance with security and data protection best practices, such as the OWASP Top 10, the NIST Cybersecurity Framework, and other recognised best practices.
Frequently Asked Questions
FAQ on Compliance & Data Protection
ISO 27001 is the international standard for information security. It demonstrates that Perbility has verifiably implemented processes to protect your data from unauthorised access, loss and misuse – verified and certified by independent external bodies. You don’t have to rely on promises; you can view the certificate.
Our ISMS in accordance with DIN EN ISO 27001:2022 covers the classification, storage, processing and backup of your data, as well as clear access control and monitoring. In practice: strict adherence to confidentiality, integrity and availability, regular security audits and penetration tests, and geo-redundant backups – with no data transfer outside the EEA.
Your HR data is hosted exclusively in German data centres – such as noris network – which meet the highest information security requirements and are certified in accordance with German law. No data is transferred outside the European Economic Area (EEA).
No. Your HR data runs exclusively on German servers – Perbility does not use US cloud providers such as AWS, Microsoft Azure or Google Cloud.
The US CLOUD Act allows US authorities to access data held by US companies, even when stored on European servers. Because Perbility does not use any US-based services in our products, this does not apply to us. Your data remains fully under European law.
We protect your data through strict adherence to confidentiality, integrity and availability. In practice: regular security audits and penetration tests, geo-redundant backups, role-based access control and secure login procedures – with no data transfer outside the EEA.
GDPR compliance is a legal obligation – but Perbility goes further: by hosting exclusively in Germany, with no dependency on US cloud providers and ISO 27001 certification, you receive a level of data protection that goes well beyond the legal minimum. This reduces your liability risk as a data controller and makes it easier to demonstrate compliance to authorities or auditors.
“Made in Germany” describes where the software is developed – but it says nothing about the infrastructure on which your data runs. Perbility develops in Germany (among others: Bamberg, Cologne, Hamburg and Berlin) and hosts exclusively in German data centres such as noris network – without any US hyperscaler. On top of that: ISO 27001 and ISO 9001 certifications and regular independent external audits.
Entirely in Germany – at our locations including Bamberg, Cologne, Hamburg and Berlin. Software development complies with high documented and audited quality standards. Our experienced developers follow proven best practices in their respective industries.
Blog & Insights
More on data protection, security and compliance.
Personal Support
We’re here for you!
In a personal demo, our experts will show you how to further optimise your processes with Helix – and answer all your questions.
Christian
Henry
Daniel
Tiago
Michael
Jana
Can
Lennart
Felix
Benjamin
Rainer
Karina
Tobias
Bastian
Franziska
Jessica
Serena





