Security is not a feature.
Security is our service.
In the healthcare sector, there is no room for error. We transparently document our standards so you can fully concentrate on your applications.
The Pillars of Our Trust
Complete transparency about our infrastructure, certifications, and legal framework.
Certification
ISO 27001:2022
Our Information Security Management System (ISMS) is certified by TÜV Rheinland according to ISO 27001:2022. We guarantee the highest standards in the processing of sensitive data and the development of our products.
Download Certificate (PDF)Audit Interval
Annual
Status
Certified
Privacy
Privacy by Design
Data minimization and privacy by default are deeply rooted in our architecture and corporate culture. We place great importance on ensuring that our products and services meet the highest data protection standards. 100% hosting in Germany on C5-certified servers.
Privacy Policy Website Privacy Policy ApplicationsRegulatory
BSI TR-03161 Compliance
Our architecture strictly adheres to the technical guidelines of the BSI for health apps (Device Binding & Crypto Agility).
Infrastructure
Service Health & SLA
We guarantee 99.9% API availability. Check our real-time metrics at any time.
Check System StatusLegal Transparency
Legal Portal
We make our legal framework transparently available.
Legal PortalResponsibility we can measure
Transparency is our business model — in security as in sustainability. We measure our footprint, name the limits of that measurement, and expand it step by step.
Green Cloud
Renewable-Backed Cloud
azuma doa and azuma mimoto run entirely on Microsoft Azure, whose electricity demand Microsoft states it covers fully with renewable energy on a net basis. Our CO₂ footprint calculated per the Greenhouse Gas Protocol — covering exclusively our cloud operations — was around 174 kg CO₂e in the twelve months to June 2026; the market-based Scope 2 share (electricity) was consistently zero throughout. Home office, hardware, and travel are not yet included — we say so openly rather than advertising a seemingly complete figure.
Efficiency
Efficient by Design
Digital health needs secure identity infrastructure — but not rebuilt at every vendor. Instead of each manufacturer building, operating, and maintaining its own IAM, our customers share a single, highly optimized platform. Shared infrastructure means fewer redundant systems, less energy, less overhead.
Data Minimization
Data-Minimal by Architecture
azuma nori, our agentic compliance analysis, runs locally on the developer's machine — source code never leaves the device. For us, data minimization isn't a sustainability fig leaf but an architectural principle. When it comes to AI, too: as much compute as necessary, as little as possible.
More about azuma noriRemote-First
Low-Footprint Company
azuma works 100% remotely — with no office space of its own and no daily commuting. That keeps our direct footprint structurally small and enables a location-independent team.
Social Responsibility
Security & Access
Protecting sensitive health data and providing a reliable, accessible path into digital care are core to responsible conduct, in our view. azuma is certified to ISO 27001:2022, and our products (including azuma doa and azuma mimoto) are in use at customers whose applications have been successfully certified to BSI TR-03161 — meeting those requirements in production.
Outlook. We keep our emissions data current based on Azure's reports and are evaluating expanding our data basis with further emission sources in the future.
Basis of emissions figures: Microsoft Azure Carbon Optimization (Scope 1–3, GHG Protocol methodology, market-based Scope 2 accounting), period July 2025 – June 2026.
gemspec, BfArM & BSI requirements
Our compliance team supports you in meeting the requirements of gemspec, BfArM & BSI. Sign an NDA to get insight into our audit tables for DiGAs, DiPAs and BSI-TR03161 candidates.
