Skip to main content
azuma Trust Center

Security is not a feature.
Security is our service.

In the healthcare sector, there is no room for error. We transparently document our standards so you can fully concentrate on your applications.

The Pillars of Our Trust

Complete transparency about our infrastructure, certifications, and legal framework.

Certification

ISO 27001:2022

Our Information Security Management System (ISMS) is certified by TÜV Rheinland according to ISO 27001:2022. We guarantee the highest standards in the processing of sensitive data and the development of our products.

Download Certificate (PDF)

Audit Interval

Annual

Status

Certified

Externally Audited

Privacy

Privacy by Design

Data minimization and privacy by default are deeply rooted in our architecture and corporate culture. We place great importance on ensuring that our products and services meet the highest data protection standards. 100% hosting in Germany on C5-certified servers.

Privacy Policy Website Privacy Policy Applications
C5 HostingExternal DPO

Regulatory

BSI TR-03161 Compliance

Our architecture strictly adheres to the technical guidelines of the BSI for health apps (Device Binding & Crypto Agility).

Security by DesignZero Trust Architecture

Infrastructure

Service Health & SLA

We guarantee 99.9% API availability. Check our real-time metrics at any time.

Check System Status
System Online

Legal Transparency

Legal Portal

We make our legal framework transparently available.

Legal Portal
Transparency
Sustainability & Responsibility

Responsibility we can measure

Transparency is our business model — in security as in sustainability. We measure our footprint, name the limits of that measurement, and expand it step by step.

Green Cloud

Renewable-Backed Cloud

azuma doa and azuma mimoto run entirely on Microsoft Azure, whose electricity demand Microsoft states it covers fully with renewable energy on a net basis. Our CO₂ footprint calculated per the Greenhouse Gas Protocol — covering exclusively our cloud operations — was around 174 kg CO₂e in the twelve months to June 2026; the market-based Scope 2 share (electricity) was consistently zero throughout. Home office, hardware, and travel are not yet included — we say so openly rather than advertising a seemingly complete figure.

Renewable-backedGHG Protocol

Efficiency

Efficient by Design

Digital health needs secure identity infrastructure — but not rebuilt at every vendor. Instead of each manufacturer building, operating, and maintaining its own IAM, our customers share a single, highly optimized platform. Shared infrastructure means fewer redundant systems, less energy, less overhead.

Shared Platform

Data Minimization

Data-Minimal by Architecture

azuma nori, our agentic compliance analysis, runs locally on the developer's machine — source code never leaves the device. For us, data minimization isn't a sustainability fig leaf but an architectural principle. When it comes to AI, too: as much compute as necessary, as little as possible.

More about azuma nori
Local-First

Remote-First

Low-Footprint Company

azuma works 100% remotely — with no office space of its own and no daily commuting. That keeps our direct footprint structurally small and enables a location-independent team.

100% Remote

Social Responsibility

Security & Access

Protecting sensitive health data and providing a reliable, accessible path into digital care are core to responsible conduct, in our view. azuma is certified to ISO 27001:2022, and our products (including azuma doa and azuma mimoto) are in use at customers whose applications have been successfully certified to BSI TR-03161 — meeting those requirements in production.

ISO 27001:2022BSI TR-03161

Outlook. We keep our emissions data current based on Azure's reports and are evaluating expanding our data basis with further emission sources in the future.

Basis of emissions figures: Microsoft Azure Carbon Optimization (Scope 1–3, GHG Protocol methodology, market-based Scope 2 accounting), period July 2025 – June 2026.

gemspec, BfArM & BSI requirements

Our compliance team supports you in meeting the requirements of gemspec, BfArM & BSI. Sign an NDA to get insight into our audit tables for DiGAs, DiPAs and BSI-TR03161 candidates.