// Trust & Security
Trust & Security
Skopion runs its own infrastructure with the same diligence applied in client engagements — transparently documented, without overstated claims.
Transport & web security
- TLS 1.3, externally rated SSL Labs A+
- HTTPS enforced, HSTS (1 year, includeSubDomains)
- Modern security headers: CSP, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy
Application security
- OWASP ASVS v5.0 Level 1 — internal self-verification (OWASP does not issue confirmations; self-verification)
- Contact form protected against automated abuse (Cloudflare Turnstile)
- No unnecessary internal infrastructure disclosure; sanitized error handling
Data protection (GDPR)
- Technical and organizational measures; no third-party trackers or analytics
- Only a strictly-necessary language cookie; contact solely via the secured form
Secure communication
- Published security.txt (RFC 9116) and PGP key for encrypted first contact
- Responsible disclosure welcome
Readiness & training
- Self-assessment against CIS Controls v8 (Implementation Group 1)
- Ongoing awareness and skills training (Global Cyber Alliance, EC-Council, Linux Foundation); completion records kept internally
Operations
- Hardened operational baseline with multi-factor protection, role-based access and controlled deployments.
- Backup and recovery processes are maintained internally and reviewed regularly.
- Security-relevant updates and operational events are monitored internally and documented traceably.
Technical transparency
- Secure connection via HTTPS with HSTS
- HTTP security headers configured, including CSP, X-Frame-Options and Referrer-Policy
- Email protection for skopion.de: SPF, DKIM and DMARC with p=reject
- Responsible disclosure channel and security.txt available
- Legal notices, privacy information and clear service limitations
Cyber Security Network
SKOPION Intelligence is registered as a Digital First Responder in the German Cyber Security Network (CSN). The registration supports structured first response and incident reporting in the CSN context; it does not represent BSI certification, auditing or endorsement.
Open CSN entry →Public professional profiles
Cyberhive EUROPE
SKOPION Intelligence is listed with a public vendor profile and the solution profile “SKOPION Digital Risk & Exposure Analysis” on Cyberhive EUROPE. Publishing the vendor and solution profile does not constitute ECSO membership, a certification or a ‘CYBERSECURITY MADE IN EUROPE’ label.
Marktplatz IT-Sicherheit
SKOPION Intelligence is listed with a public vendor profile on Marktplatz IT-Sicherheit. The entry supports discoverability within the IT security ecosystem and does not constitute a certification, an audit or a recommendation.
Open vendor profile →Regional company presence
IHK Mittlerer Niederrhein
SKOPION Intelligence is listed with a public company profile (“Mein Unternehmen”) at IHK Mittlerer Niederrhein. The public company profile supports regional visibility and does not constitute a professional review, a certification or a recommendation by the IHK.
Open company profile →// Institutional trust layer
These points are internal self-assessments and readiness measures — not a third-party endorsement or external audit. External ratings (e.g. SSL Labs) are independently verifiable.