Skip to content
Back

// Trust & Security

Trust & Security

Skopion runs its own infrastructure with the same diligence applied in client engagements — transparently documented, without overstated claims.

Transport & web security

  • TLS 1.3, externally rated SSL Labs A+
  • HTTPS enforced, HSTS (1 year, includeSubDomains)
  • Modern security headers: CSP, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy

Application security

  • OWASP ASVS v5.0 Level 1 — internal self-verification (OWASP does not issue confirmations; self-verification)
  • Contact form protected against automated abuse (Cloudflare Turnstile)
  • No unnecessary internal infrastructure disclosure; sanitized error handling

Data protection (GDPR)

  • Technical and organizational measures; no third-party trackers or analytics
  • Only a strictly-necessary language cookie; contact solely via the secured form

Secure communication

  • Published security.txt (RFC 9116) and PGP key for encrypted first contact
  • Responsible disclosure welcome

Readiness & training

  • Self-assessment against CIS Controls v8 (Implementation Group 1)
  • Ongoing awareness and skills training (Global Cyber Alliance, EC-Council, Linux Foundation); completion records kept internally

Operations

  • Hardened operational baseline with multi-factor protection, role-based access and controlled deployments.
  • Backup and recovery processes are maintained internally and reviewed regularly.
  • Security-relevant updates and operational events are monitored internally and documented traceably.

Technical transparency

  • Secure connection via HTTPS with HSTS
  • HTTP security headers configured, including CSP, X-Frame-Options and Referrer-Policy
  • Email protection for skopion.de: SPF, DKIM and DMARC with p=reject
  • Responsible disclosure channel and security.txt available
  • Legal notices, privacy information and clear service limitations

Cyber Security Network

SKOPION Intelligence is registered as a Digital First Responder in the German Cyber Security Network (CSN). The registration supports structured first response and incident reporting in the CSN context; it does not represent BSI certification, auditing or endorsement.

Open CSN entry

Public professional profiles

Cyberhive EUROPE

SKOPION Intelligence is listed with a public vendor profile and the solution profile “SKOPION Digital Risk & Exposure Analysis” on Cyberhive EUROPE. Publishing the vendor and solution profile does not constitute ECSO membership, a certification or a ‘CYBERSECURITY MADE IN EUROPE’ label.

Marktplatz IT-Sicherheit

SKOPION Intelligence is listed with a public vendor profile on Marktplatz IT-Sicherheit. The entry supports discoverability within the IT security ecosystem and does not constitute a certification, an audit or a recommendation.

Open vendor profile

Regional company presence

IHK Mittlerer Niederrhein

SKOPION Intelligence is listed with a public company profile (“Mein Unternehmen”) at IHK Mittlerer Niederrhein. The public company profile supports regional visibility and does not constitute a professional review, a certification or a recommendation by the IHK.

Open company profile

// Institutional trust layer

These points are internal self-assessments and readiness measures — not a third-party endorsement or external audit. External ratings (e.g. SSL Labs) are independently verifiable.