Information Security
preeco | informationssicherheit
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by preeco GmbH & Co. KG · www.preeco.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
preeco | informationssicherheit is an ISMS suite from a German vendor based in Ulm, strongest on the security-management core: information security management scores a flat 8, with protection needs assessed through the IT-Grundschutz damage-scenario matrix and maximum principle, risks linked to the measures that reduce them, and incidents carrying nine ready BSI, KRITIS and GDPR report templates with automatically monitored deadlines. Controls and statement of applicability follow at 7-8, where exclusion justifications flow automatically into immutable, dated statements per catalog. Audit readiness spans 6-7, where SHA-256-verified revisions and filterable activity logs sit against no public information on auditor access roles or audit-scoped evidence packs. Framework coverage splits at 5-6 — the higher marks credit the breadth and substance of the NIS2 content, the lower ones the single active catalog per organization and no public information on cross-framework mapping. Weakest are integrations and automation, uniform at 3: the vendor describes a closed system with no public REST API. Sovereignty holds at 7 (Hetzner hosting in Nürnberg and Falkenstein, named subprocessors in Germany and Finland, an on-premises option), and no prices are public.
Speaks for it
- Protection-needs assessment follows the IT-Grundschutz damage-scenario matrix with the maximum principle, accumulation across linked systems, and inheritance updates on asset release
- Incidents carry nine ready report templates for BSI, KRITIS and GDPR notifications, with reporting deadlines monitored automatically
- The statement of applicability is built from the live assessed state per catalog, exclusion justifications flowing in automatically and filed versions held immutable with date and author
- Every approval creates an immutable revision with SHA-256 integrity verification and visual comparison, alongside complete activity logs filterable by time period and user
- Hosting runs exclusively in ISO 27001-certified Hetzner data centers in Nürnberg and Falkenstein with no third-country transfer, a DPA signable online on GDPR Article 28 standard clauses, and an on-premises option
Held against it
- The vendor states the application is a closed, self-contained system with no public REST API, customer-specific endpoints being developable only for Private Cloud and On-Premises
- We found no public information on directory, CMDB, ticketing or scanner connectors, webhooks or SCIM, with data exchange shown as PDF, DOCX and XLSX exports and an XLSX import for training participants
- Exactly one requirement catalog is active per organization, no public information appears on mapping one control across frameworks, and the captured pages give different figures for catalog operation
- We found no public information on continuity planning, on delegation and escalation in measure tracking, on findings management inside audit workflows, or on auditor access roles and audit-scoped evidence packs
- The DPA's complete subprocessor list sits in an appendix the captured pages do not show, ownership is not publicly documented, and optional DeepL or OpenAI-compatible integrations would add content-touching processors
Best for
- You are building a first ISMS for the German market around ISO 27001, NIS2 or BSI C5 and want guided step-by-step implementation with BSI and GDPR incident reporting built in
- You audit against BSI IT-Grundschutz, CISIS12 or VdA ISA and want the statement of applicability filled automatically with audit-proof revisions
- Your compliance data must stay in German data centers, or on your own infrastructure through the on-premises option offered to public-sector and enterprise buyers
- You accept residual risks formally and want accepted exceptions tracked separately from your fulfilment metrics
Avoid if
- You need the ISMS to interoperate with your existing estate — directory, CMDB, ticketing or vulnerability scanners — over a public API
- You must run several frameworks simultaneously in one organization and answer each control once across them
- You expect evidence to be collected automatically from the live IT estate rather than uploaded or requested via links
- Your supplier rules require the vendor itself to hold ISO 27001 certification, which the captured pages state it does not — the certification covers its hosting data centers
The scores
Asset & risk management depth
Show reasoningHide reasoning
How this is scored
The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.
0 — No ISMS substance; "information security" is a chapter in the marketing site.
3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.
5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.
8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.
10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.
The CISO
A genuine risk backbone: protection needs follow IT-Grundschutz methodology (damage-scenario matrix, maximum principle, accumulation across linked systems), inheritance information updates across asset relations, and incidents carry reporting-obligation assessment with automatically monitored deadlines plus ready-made report templates to the BSI under NIS2 and § 25 BSIG and to Art. 33/34 GDPR. Accepted residual risk is counted separately in the cockpit metrics. We found no public information on continuity planning, and the evidence does not show who owns an accepted residual risk. 12 13 14 17 8
The GRC Consultant
The risk backbone is real: protection needs follow the IT-Grundschutz damage-scenario matrix with maximum principle and accumulation across linked assets, releasing an asset creates a revision and updates inheritance information, and incidents carry severity and a reporting-duty assessment with automatic monitoring of reporting deadlines, backed by nine ready templates covering BSI early-warning, notification and final reports plus GDPR Articles 33 and 34. Risks link directly to measures with a freely definable methodology and residual risks can be formally accepted with their own treatment in the degree-of-fulfilment metrics. I found no public information on continuity planning, which is what the highest bar adds. 2 14 17 12 2 13
The Drafted IT Officer
This is a real risk backbone, not a spreadsheet: protection needs come from a damage-scenario matrix using the maximum principle with accumulation across linked systems, risks link directly to the measures that reduce them, and incident handling ships with nine ready-made report templates for BSI, KRITIS and GDPR whose reporting deadlines are monitored automatically. The guided step-by-step implementation is exactly what someone doing this alongside the day job needs. We found no public information on business continuity planning, which keeps it off the top mark. 8 2 12 2 13 14 17
The Lead Auditor
The asset-risk-treatment chain is real: protection needs follow the IT-Grundschutz method (damage-scenario matrix, maximum principle, accumulation across linked systems, inheritance information updated on release), the risk methodology is freely definable, risks link directly to the measures that reduce them, and consciously accepted residual risks are tracked as accepted and taken out of the fulfilment metric. Incidents carry categories, severity, reporting-duty assessment with automatically monitored deadlines, and nine ready report templates for BSI early warning, NIS2 and KRITIS filings. I found no public information on continuity planning, which is what keeps this short of the top. 8 2 12 13 14 17
The Evidence Integrator
A real risk backbone is on the pages: protection-needs assessment follows BSI IT-Grundschutz methodology with maximum principle and accumulation across linked assets, inheritance information is updated on asset release, and incidents carry automatic statutory deadline monitoring with nine ready report templates for BSI and GDPR notifications. Risk acceptance appears as consciously accepted residual-risk exceptions counted separately in the cockpit, with risk methodology freely definable and risks linked to measures; we found no public information on continuity planning. 17 14 12 2 8 13
The Skeptic
The risk backbone is genuinely documented: protection needs follow the IT-Grundschutz damage-scenario matrix with the maximum principle, accumulation effects across linked systems and inheritance information updated on release, while incidents carry automatically monitored reporting deadlines and nine ready BSI, KRITIS and GDPR report templates. Residual risks can be consciously accepted as tracked exceptions, and events, damage assessment and risk levels are freely definable. We found no public information on continuity planning or authority-side export of incident reports. 8 2 12 13 14 17
Controls, SoA & measures
Show reasoningHide reasoning
How this is scored
Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.
0 — A static control checklist; applicability, implementation status and evidence are the consultant's spreadsheet.
3 — Control catalogs with status fields, but no SoA generation, no measure ownership, no link between controls and risks.
5 — Controls linked to risks and measures with owners and due dates; SoA producible with manual assembly; internal audit supported by checklists.
8 — SoA on demand from live control status, measure tracking with delegation and escalation, internal audit workflows with findings management, controls carrying their own evidence.
10 — The control fabric as a living system: catalog updates versioned, SoA always current, audit programs with recurring schedules, and every control answerable with linked evidence at any moment.
The CISO
The Statement of Applicability is produced from live assessment status: setting a requirement to not-applicable forces a justification that flows automatically into the SoA, which can be filed as an immutable version with date and author per catalog and stays traceable over time. Measures carry owners, status and versioning and link to risks and protection needs, with evidence permanently attached to each requirement. We found no public information on delegation or escalation in measure tracking, or on findings management inside the audit workflows. 15 16 20 17
The GRC Consultant
The statement of applicability is the strongest part: marking a requirement not applicable forces an exclusion justification that flows automatically into the SoA, which can be filed per catalog as an immutable, dated version that stays traceable over time. Measures carry owners, status, versioning and links to risks and protection needs, and audits run structured and on schedule with centrally available evidence. I found no public information on measure delegation or escalation, on audit findings management, or on versioned catalog updates — the difference between a good control register and a living control fabric. 16 7 15 8 2
The Drafted IT Officer
The statement of applicability is genuinely automatic: setting a requirement to not applicable forces a justification that flows into the SoA, filed as an immutable dated version per catalog, while measures carry owners, status and versioning and link to risks and protection needs. Audits recur on schedule with central evidence and controls answer with their own evidence. We found no public information on delegating measures with escalation or on tracking audit findings to closure, so it sits just under the next mark. 7 7 15 16 17
The Lead Auditor
This is the strongest part: the Statement of Applicability is produced per catalog from the live assessed state, the exclusion justification is a mandatory field that flows into the SoA automatically, and filed SoA versions are immutable with date and author and remain traceable over time. Measures carry owners, status and versioning and link to risks and protection needs, every requirement has its own evidence tab with validity dates, and cockpit fulfilment updates in real time. I found no public information on findings management inside audit workflows or on escalation paths for overdue measures. 8 12 7 15 16
The Evidence Integrator
Measures carry owners, status and versioning and link to identified risks and protection needs, and every requirement has its own evidence tab; exclusion justifications flow automatically into a Statement of Applicability that files as an immutable, dated version per catalog. We found no public information on measure delegation and escalation or on findings management inside internal audit workflows, and the captured pages state exactly one catalog can be active per organization. 15 16 20 2
The Skeptic
The statement of applicability is produced from the live assessed state per catalog, with exclusion justifications flowing into it automatically and filed versions immutable with date and author — more than manual assembly. Measures carry owners, status and versioning and link to risks and protection needs, requirements carry their own evidence, and audits recur on schedule. We found no public information on delegation and escalation in measure tracking, or on findings management inside the audit workflow. 2 7 15 16 17
Framework & standard coverage
Show reasoningHide reasoning
How this is scored
Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.
0 — One framework, hard-coded; anything else is "on the roadmap".
3 — Two or three frameworks as separate checklists; the same control is answered once per framework.
5 — The major regimes for its market with partial cross-mapping; newer regimes (NIS2, DORA) present as content packs of varying depth.
8 — Broad current coverage including NIS2/TISAX/DORA where relevant, one-control-many-frameworks mapping, and visible maintenance as regimes evolve.
10 — Framework coverage as a living product: dozens of regimes, genuine multi-compliance mapping on one data basis, per-industry profiles, and documented update cadence when the standard moves.
The CISO
The German market's regimes are present as ready content: ISO 27001, NIS2 and BSI C5 as requirement catalogs, BSI IT-Grundschutz, CISIS12 and VdA ISA as optional paid audit catalogs, plus a municipal SiKoSH catalog. The product pages state exactly one catalog is activated per organization, and we found no public information on one-control-many-frameworks mapping; DORA appears only as a commitment that new requirements are implemented promptly. The captured pages give different figures on catalog operation — one catalog per organization on the product pages, a Statement of Applicability per loaded catalog in the guide. 12 7 2 1 18
The GRC Consultant
For the German market the breadth is genuinely there — ISO 27001, NIS2 and BSI C5 as loadable catalogs plus BSI IT-Grundschutz, CISIS12 and VdA ISA as optional paid ones, a communal SiKoSH catalog, monthly updates, and DORA only promised as timely implementation. Answering a control once and mapping it across regimes, the thing that makes client twelve cheaper than client one, is not evidenced: the captured pages give different signals, one stating exactly one catalog is activated per organization while the SoA guide describes a certification document created separately for each loaded catalog. I found no public information on cross-framework mapping or SOC 2 content. 7 2 2 18 17 1 12
The Drafted IT Officer
The German-market regimes are there as ready catalogs — ISO 27001, NIS2 and BSI C5 plus optional paid BSI IT-Grundschutz, CISIS12 and VdA ISA and a municipal SiKoSH catalog — though the captured pages give different figures for which catalogs are included where. Only one catalog is active per organization and we found no public information on one control answering several frameworks, so regimes read as separate islands rather than shared compliance data; DORA appears only as a statement that new requirements will be implemented promptly. 2 12 2 7 17 18
The Lead Auditor
The German-market regimes are genuinely there — ISO 27001, BSI IT-Grundschutz, BSI C5, NIS2, CISIS12, VdA ISA (TISAX) and the municipal SiKoSH catalog — and NIS2 has substance (incident templates, management training) rather than being a thin content pack. But the captured pages state that exactly one catalog is activated per organization and the SoA is created separately per catalog, and I found no public information on answering one control across several frameworks; DORA appears solely as a commitment to implement new requirements promptly. That is breadth without the one-control-many-frameworks mapping. 1 2 12 7 18
The Evidence Integrator
Seven regimes are evidenced as ready catalogs — ISO 27001, NIS2, BSI C5, BSI IT-Grundschutz, CISIS12, VdA ISA and the communal SiKoSH — with monthly product updates as visible maintenance. Mapping one control answer across frameworks is not something we found public information on, and the captured pages state exactly one catalog is active per organization, so each regime reads as its own island; DORA appears only as a statement that new requirements are implemented promptly. 7 12 2 1
The Skeptic
The German-market regimes are present — ISO 27001, NIS2 and BSI C5 load, SiKoSH serves municipalities, and BSI IT-Grundschutz, CISIS12 and VdA ISA come as paid add-ons — but exactly one catalog is active per organization, and we found no public information on mapping one control across frameworks. The captured pages give different figures for which requirement catalogs are loadable, and DORA appears publicly only as a commitment to implement new requirements in good time. A broad regime list, run as separate islands. 1 2 2 7 18
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators, evidence attachments per control; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous evidence status per framework and scope, exportable proof packs an external auditor accepts as-is, and a defensible answer to "show me the state on date X".
The CISO
Revision safety is real: every approval creates an immutable revision with SHA-256 integrity verification and visual comparison, activity logs are filterable by time period and user including administrative actions, and evidence sits on each requirement with validity dates, expiry warnings and a request link for external holders. Status and audit reports, dashboards with a weekly compliance trend, and recurring reports with notification are current at a click. We found no public information on audit-scoped evidence-pack exports or dedicated auditor access roles, and integrity verification only reaches back to that feature's introduction. 19 20 7
The GRC Consultant
Revision safety is the strongest card: every approval creates an immutable revision with SHA-256 integrity verification and visual comparison, activity logs are complete and filterable by period and user, and evidence carries validity dates whose expiry the cockpit flags ahead of the next audit, with filed SoA versions keeping exclusions traceable to a point in time. I found no public information on auditor access roles or audit-scoped evidence packs an external auditor accepts as-is. Integrity verification of revisions predating that feature is documented as not retroactive, which tempers the answer to "show me the state on date X". 19 20 7 2
The Drafted IT Officer
Evidence sits directly on each requirement with a validity date, cockpit expiry warnings and a request link for people without an account, and every approval creates an immutable revision with SHA-256 integrity checks plus complete activity logs filterable by time and user. Management and audit reports recur automatically. We found no public information on external auditor access roles or audit-scoped evidence packs, and revisions older than the feature cannot be verified retroactively, so this stays just below the next mark. 2 2 19 20
The Lead Auditor
Revision security is genuinely built in: every approval creates an immutable revision with SHA-256 integrity verification and visual comparison, activity logs cover document changes and administrative actions on user accounts, and evidence sits permanently on each requirement with validity dates and cockpit expiry warnings. Status and audit reports, recurring reports, and management dashboards with a compliance-level weekly trend are documented. What holds it back for me: the SoA filing date is chosen by the user rather than set by the system, older revisions cannot be verified retroactively since the feature was introduced, and I found no public information on auditor access roles or audit-scoped evidence packs at a click. 2 7 13 19 20
The Evidence Integrator
Revision safety is documented in depth: immutable revisions with SHA-256 integrity checks, visual revision comparison, and complete activity logs filterable by time period and user; evidence stays permanently attached to requirements with validity dates and early-renewal warnings, and filed Statement of Applicability versions remain traceable over time. We found no public information on auditor access roles or audit-scoped evidence packs on demand, and the pages state integrity verification applies only from the feature's introduction. 19 20 16
The Skeptic
Revision safety is taken seriously: every approval creates an immutable revision with SHA-256 integrity check and visual comparison, activity logs are complete and filterable by time and user including administrative actions, and each requirement carries evidence with validity dates, cockpit expiry warnings and a request link for people without accounts. Status and audit reports recur automatically, and risk reports address management and auditors. Integrity verification applies only from the feature's introduction, and we found no public information on dedicated auditor access roles or audit-scoped evidence packs. 2 12 13 19 20
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing, CMDB or SSO); automation is reminders and recurrence.
8 — Real connector set (Jira/ServiceNow-class ticketing, CMDB, cloud and endpoint sources), webhooks, SSO/SCIM, automated evidence tests with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, continuous control monitoring against the live estate, and automation that measurably removes the recurring toil rather than renaming it.
The CISO
The vendor describes the application as a closed system with no public REST API; customer-specific endpoints can be developed for Private Cloud and On-Premises only, and SAML2 single sign-on is limited to those variants. Data movement is by file — XLSX import for training participants, PDF/DOCX/XLSX exports, migrations run as individual projects. We found no public information on directory, CMDB, ticketing or scanner connectors, webhooks, SCIM, or automated evidence tests against the live estate. 12 2 2
The GRC Consultant
The vendor itself states the application is designed as a self-contained system and that no public REST API is currently available; customer-specific endpoints and SAML2 single sign-on exist only for Private Cloud and On-Premises variants, import is XLSX for training participants against PDF, DOCX and XLSX exports, and migrations run as individual paid projects. I found no public information on directory or CMDB import, ticketing connectors, webhooks, SCIM or automated evidence collection — evidence arrives by manual upload or a request link, so nothing here feeds from the live IT estate. 12 2 2 20
The Drafted IT Officer
The vendor states plainly that the application is designed as a closed system with no public REST API; custom endpoints exist only as bespoke development on private cloud or on-premises hosting. Feeds are XLSX import and exports in PDF, DOCX and XLSX, and automation means reminders, recurring reports and deadline monitoring. That works for a first ISMS but means re-typing what my directory and ticket system already know. 2 12 2 19
The Lead Auditor
The vendor describes the application as a closed system and states that no public REST API is currently available; customer-specific endpoints can be developed only on Private Cloud and On-Premises variants. What the pages do show is PDF/DOCX export with XLSX for tables and participant imports, optional SAML2 single sign-on on the higher hosting tiers, and optional DeepL and OpenAI-compatible language-model services. I found no public information on directory import, ticketing, CMDB or scanner connectors, webhooks, or automated evidence testing. 9 2 12 2
The Evidence Integrator
The vendor's own specification describes the application as a closed, self-contained system with no public REST API currently available, customer-specific endpoints being developable only for private cloud and on-premises — a data island entered by manual work, with PDF, DOCX and XLSX exports and an Excel import for training participants as the drawbridge. We found no public information on directory, CMDB, ticketing, cloud or SCIM connectors, single sign-on exists only outside the standard cloud, and what automation is shown is reminders, deadline monitoring and recurring reports, with evidence arriving by upload or link request rather than automated collection from the estate. 12 2 2 20
The Skeptic
The vendor states the application is conceived as a self-contained system and a public REST API is currently not available; custom API endpoints are developed as customer-specific work for Private Cloud and On-Premises only. What remains is PDF/DOCX/XLSX export, an XLSX import for training participants, optional DeepL and LLM connections, and SAML2 single sign-on on the upper hosting tiers. We found no public information on directory import, CMDB, ticketing or scanner connectors, webhooks or SCIM. 2 12 2
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your risk register.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The CISO
The contracting entity sits in Ulm under Amtsgericht Ulm with a German VAT ID, hosting runs exclusively in ISO 27001-certified Hetzner datacenters in Nürnberg and Falkenstein with no third-country transfer, and a DPA on GDPR Art. 28 standard clauses with downloadable TOMs and two weeks' written subprocessor change notice is publicly signable online; on-premises is offered for public-sector and enterprise buyers. Named processors are Hetzner in Germany and UpCloud in Finland for infrastructure monitoring, and the AI is off by default, activated per team. The DPA's full subprocessor list sits in an appendix we did not see, optional OpenAI-compatible LLM and DeepL integrations are customer-configured, and the captured pages give different figures for the entity's legal form — clean, but not documented end to end. 4 5 10 11 12 2
The GRC Consultant
The chain is largely European: a German entity registered at the Ulm district court, hosting exclusively at Hetzner in Nürnberg and Falkenstein with the data centers named, a published DPA with online signing, downloadable TOMs, stated freedom from third-country transfer for product data, and an on-premises variant in which data never leaves the customer's data center. It stops short of the highest bar because the DPA's full subprocessor list sits in an appendix the captured pages do not show, ownership is not documented publicly, and the optional DeepL and OpenAI-compatible LLM integrations would add content-touching processors whose jurisdictions are not constrained in what is published. 4 9 10 12 5
The Drafted IT Officer
My risk register would live with a German vendor in named ISO 27001 data centers at Hetzner in Nürnberg and Falkenstein, no third-country transfer, a published DPA with GDPR standard clauses and downloadable TOMs, and an on-premises option where data never leaves my datacenter. Named sub-processors are Hetzner in Germany and UpCloud in Finland, both EU. The full sub-processor list sits in a DPA appendix the captured pages do not show, ownership is not publicly documented, and optional DeepL or OpenAI-compatible integrations would add further processors, so the chain is not verifiably clean end to end. 9 10 11 12 2
The Lead Auditor
The visible chain is European: a German company registered in Ulm, hosting exclusively in the named ISO 27001 data centers of Hetzner in Nuremberg and Falkenstein, UpCloud in Finland for internal monitoring, a published DPA with Article 28 standard clauses, downloadable TOMs, two weeks' written notice on subprocessor changes, no third-country transfer, and an on-premises option where data never leaves the customer's datacenter. The DPA's full sub-processor list sits in an appendix the captured pages do not show, and the optional customer-configurable OpenAI-compatible providers sit outside the documented chain. I found no public information on the ownership structure. 4 5 9 10 12
The Evidence Integrator
A German entity is evidenced by the Ulm register court and the online-signable DPA, hosting runs exclusively in named Hetzner data centers in Nürnberg and Falkenstein with EU-only named subprocessors (Hetzner, UpCloud Finland), TOMs are downloadable and an on-premises option gives full data sovereignty. The captured pages do not show the DPA's subprocessor appendix, we found no public information on ownership, and optional customer-configured AI and translation integrations (OpenAI-compatible LLM providers, DeepL) could expose content to further providers. 5 10 12 9 2
The Skeptic
The chain looks European end to end: a German entity registered in Ulm, hosting exclusively in Hetzner data centers in Nuremberg and Falkenstein with no third-country transfer, a published DPA on GDPR Article 28 standard clauses, downloadable TOMs, two weeks' written notice on subprocessor changes, EU-only named subprocessors, and an on-premises option. Two reservations hold it back: the DPA's complete subprocessor list sits in an appendix the captured pages do not show, and the optional DeepL and LLM integrations are content-touching processors whose location is not documented — softened by the AI being off by default and activated per team. 4 5 9 10 11 2
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, scale steps or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a certification project is a two-minute exercise.
The CISO
No public prices at all: the license and pricing model is prepared as a separate individual offer depending on employee count, chosen modules and hosting variant, and the optional paid items — BSI IT-Grundschutz, CISIS12 and VdA ISA catalogs, DeepL, migration, premium support — carry no figures. Structure is at least stated: annual subscription with monthly or yearly billing, updates, maintenance and support included, no setup fees and no cancellation notice periods. Even the entry configuration is a sales conversation. 12 2
The GRC Consultant
There are no public price figures — the license and pricing model is prepared as a separate individual offer depending on employee count, modules and hosting variant, while optional catalogs, data migration and premium support remain unpriced line items. Credit where due for structure: an annual subscription with monthly or yearly billing, updates, maintenance and support included, and no setup fees or cancellation notice periods are stated publicly. 12 2 2
The Drafted IT Officer
There are no public prices: the license and pricing model is prepared as a separate individual offer depending on employee count, chosen modules and hosting variant. Public statements about the model are helpful — annual subscription, monthly or yearly billing, updates and support included, no setup fees, no notice periods — but add-ons like the audit catalogs, DeepL and premium support carry no figures, so the real total cannot be computed from public pages. 2 12
The Lead Auditor
Every price is an individual offer: the vendor states the licensing and price model is prepared separately per customer depending on employee count, chosen modules and hosting variant, and no figures appear anywhere on the captured pages. The model structure is public — annual subscription with monthly or yearly payment, updates and support included, no setup fees, no notice periods — and several add-ons (audit catalogs, DeepL, migration, trainings, premium support) are declared optional and paid without amounts. I found no public information on any actual price. 2 12 2
The Evidence Integrator
The licensing and pricing model is created as a separate, individual offer depending on employee count, modules and hosting variant, and we found no public price for any edition or module anywhere on the captured pages. The surrounding mechanics are published — annual subscription with monthly or yearly billing, no setup fees or cancellation periods, updates and support included, and the IT-Grundschutz, CISIS12 and VdA ISA catalogs named as optional paid add-ons — so a buyer can describe the invoice's shape but not compute it. 12 2
The Skeptic
The public pages carry no figures at all: the licensing and pricing model is prepared as a separate individual offer depending on employee count, chosen modules and hosting variant. The model's shape is at least stated plainly — annual subscription with monthly or yearly payment, updates, maintenance and support included, no setup fees, no notice periods — while the add-ons that shape a real budget (BSI IT-Grundschutz, CISIS12, VdA ISA catalogs, DeepL, data migration, premium support) are each marked optional and paid without a number. The invoice is computable only after a sales conversation, which is the market norm here but leaves the buyer without a single public price. 2 12
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 9 Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 24 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The EU-only statement covers the hosted Cloud/Private Cloud offers on marketing and hosting pages, while On-Premises runs in the customer's own datacenter; optional customer-configured integrations (DeepL, OpenAI-compatible LLM providers) could expose content to further providers.
- Weak sourcing — Subprocessors, Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 146 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 24 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 21 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 18 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 15 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 9 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (20)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.preeco.de Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 24 Aug 2026 Details →
- 2 Information security product page www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 16 Sep 2026, 15 Sep 2026, 24 Aug 2026 Details →
- 3 About page www.preeco.de Checked 5 Oct 2026 Details →
- 4 Imprint www.preeco.de Checked 5 Oct 2026 Details →
- 5 Privacy policy www.preeco.de Checked 5 Oct 2026 Details →
- 6 Product documentation library www.preeco.de Checked 5 Oct 2026 +2 earlier captures: 16 Sep 2026, 24 Aug 2026 Details →
- 7 SoA automation doc www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 15 Sep 2026, 24 Aug 2026, 24 Aug 2026 Details →
- 8 ISMS cockpit metrics doc www.preeco.de Checked 5 Oct 2026 +1 earlier capture: 24 Aug 2026 Details →
- 9 Hosting variants page www.preeco.de Checked 5 Oct 2026 +1 earlier capture: 16 Sep 2026 Details →
- 10 Published DPA (AVV) for cloud customers www.preeco.de Checked 5 Oct 2026 Details →
- 11 Multi-entity use case page www.preeco.de Checked 5 Oct 2026 Details →
- 12 Full product specification (Leistungsbeschreibung) www.preeco.de Checked 5 Oct 2026 +2 earlier captures: 16 Sep 2026, 24 Aug 2026 Details →
- 13 Asset & risk management depth — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 14 Asset & risk management depth — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 15 Controls, SoA & measures — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 16 Controls, SoA & measures — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 17 Framework & standard coverage — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 18 Framework & standard coverage — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 19 Audit readiness & evidence — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 20 Audit readiness & evidence — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →