IndiciumIndicium
Log in
Trust Center For your second line

We check people. Check us — before you sign.

Your second line will not read this page like a brochure. They will check data residency, sub-processors, liability, security controls and exit. This page is built for that review.

This is no promise but a reviewable document package — the Trust Package. We publish the table of contents up front. The detailed documents are available under NDA before signing, so you can hold it point by point against your own MaRisk, DORA or TPRM checklist.

A preliminary note that sets the tone of this page: we deliberately do not claim legal certainty or that a report can be presented as a court-proof instrument. In the same spirit, we claim no attestation we don’t hold and no sovereignty we don’t deliver. What you read below is the honest version, residual risks included.

Documents & evidence: trust.indicium.ag
01 Confidentiality toward Indicium

The first question isn’t who gets checked — it’s who at our end sees whom you check.

A search query is itself data worth protecting. The mere fact of the query reveals who is checking whom — and why now. For professionals bound by confidentiality, general counsel and family offices, this is the decisive purchasing point. We treat it as such — contractually assured, not just technically claimed:

a
Strict client separation
Your queries, reports and history are logically separated from every other client’s. No one at another client sees that you exist.
b
Access on a need-to-know basis only
Within Indicium, only those who need a query to process it can see it — role-based, logged, not “the team.”
c
No training of our models on your queries
Your searches, names and reports don’t flow back into a model that serves others. A contractual assurance, not best-effort.
d
Deletion of query metadata
The information on who checked whom is deleted automatically after 30 days.
e
Confidentiality-compliant data processing
For those bound by professional secrecy, the DPA is set up not only under data-protection law but under professional-conduct law — details in section 02.
02 Professional secrecy

We solve the DPA under professional-conduct law, not only data-protection law.

A data-protection-compliant DPA isn’t enough for the lawyer — she needs one that carries her professional secrecy. That’s exactly where most standard DPAs start and stop. The concrete statutory reference is in the Trust Package — so you can check it before you enter the first client name.

DE
§ 43a BRAO · § 2 BORA · § 203 StGB · § 43e BRAO
Contributor status explicitly addressed: confidentiality binding on contributors and the contractual obligation on the service provider required under § 43e BRAO.
CH
Art. 13 BGFA · Art. 321 StGB
The equivalent, via attorney professional secrecy, for Swiss mandates.
03 DPA & deletion concept

Deletion duty and retention duty — resolved, not left in conflict.

The reflexive data-protection line is: “We delete everything.” For a regulated client, that’s precisely a problem — the regulator requires the reviewable report file to remain demonstrable for five to ten years. We resolve the conflict in writing. The DPA under Art. 28 GDPR governs:

a
Roles clearly assigned
Where Indicium is a processor and where — e.g. in a credit-reference service — it is not, is set out in writing, not tacitly assumed.
b
Instruction binding, confidentiality, TOM obligation
Under Art. 28(3) — including support for data-subject rights and data-protection impact assessment.
c
A deletion concept that knows the retention duty
Query metadata (“who checked whom”) is deleted early; the reviewable report file stays available for the period the regulator requires. Two data categories, two rules — explicitly separated: query metadata 30 days, contract and billing data 10 years (statutory retention).
04 Regulatory matrix

Every requirement against the clause that meets it — as a mapping, not a seal.

Three compliance logos side by side prove nothing. Your outsourcing governance wants to see which contract clause carries which regulatory requirement — line by line, reviewable.

RegimeCore requirementMet by contract clause
DORA Art. 30Mandatory ICT third-party contract content, audit & access rights, termination rights
MaRisk AT 9Materiality assessment, instruction, information & control rights, sub-outsourcing
NIS2 Art. 21Supply-chain risk-management measures
VAG-Outsourcing (§ 32 VAG)Insurance-specific outsourcing, BaFin supervisory & audit rights

This includes what the second line really asks: audit, information and instruction rights for you and your regulator (BaFin, FINMA). Support for your DORA information register under Art. 28(3) DORA, with a sample register entry. An honest assessment of concentration and substitutability risk. And where your own on-site audit would be disproportionate, we name pooled audits and an ISAE 3402 report as a recognized substitute.

Full matrix with clause numbers: under NDA via trust.indicium.ag
05 Legal bases

We check from open and licensed sources — and tell you on which legal basis.

a
Legitimate interest as the standard case
Usually the legitimate interest in integrity and compliance checking carries it (Art. 6(1)(f) GDPR) — after a case-by-case balancing of interests, not as a blanket rule.
b
Special categories (Art. 9) and Art. 10
Here we derive the permitting basis case by case, drawing on § 22 BDSG or the revDSG equivalent — not papered over with an article citation.
c
Controller or processor?
In a credit-reference service this is anything but trivial. We assign the roles in writing, case by case — before the first report runs.
06 Information security

We hold no attestation we don’t have. We run the controls that matter behind it.

So we say it plainly: we hold no ISO 27001 and no SOC 2 today. We don’t claim it, and we don’t write “in preparation” either, because a status line without substance says nothing.

What we present instead is the substance an attestation would only certify anyway — the technical and organizational measures (TOMs) in effect today under Art. 32 GDPR and the compensating controls:

a
Encryption
TLS 1.2 minimum, TLS 1.3 preferred, in transit; AES-256 at rest, key management via AWS KMS.
b
Access control
Role-based, need-to-know, with multi-factor authentication and logging.
c
Client & environment separation
Strict logical tenant separation by Customer-ID. Separation between production, staging and development environments.
d
Audit trail & logging
Security-relevant access, documented tamper-proof.
e
Backup & recoverability
Daily automated encrypted snapshots, redundant, with point-in-time recovery.
f
DDoS protection
AWS Shield + Web Application Firewall (WAF).
g
Vulnerability management
Automated dependency scanning, container scanning, SAST, 4-eyes code review.

We ourselves buy only from providers that pass a clean security due diligence. Hold us to that same standard.

07 Hosting & sovereignty

“Made in Europe for Europe” — and the honest point where that is still a goal today.

Sovereignty is often sold in this market as an absolute claim. We don’t say that, because today it wouldn’t be the whole truth — and because a claim your own review immediately finds a crack in costs more trust than it earns. Here’s how it really looks with us:

a
EU hosting
Your query and personal data are held and processed in the EU.
b
The residual risk, openly named
We run on AWS infrastructure within the EU (Frankfurt/Ireland regions). We chose AWS deliberately, for its security capabilities, compliance tooling and the depth of its Absicherungspaket. A US-headquartered provider carries a CLOUD Act / FISA 702 exposure that even an EU region does not fully remove. We don’t hide it; we assess it. We don’t trade security for a sovereignty label.
c
The direction we’re actively working toward
AWS was a deliberate choice, not a fallback. The security capabilities, compliance tooling and the depth of its Absicherungspaket are what we need for regulated clients. Sovereignty is not a label we slap on today, it’s a direction we keep building toward.
d
Where we make no compromises
On cyber security. Sovereignty-first as the path, security uncompromising at every step.

Separately, the second half of the truth: some of our sanctions and PEP reference data comes from international providers. That concerns the origin of the matching data — not the residency of your query and personal data. We separate the two openly instead of merging them under a sovereignty label.

08 Contracting entity & transfer

We tell you up front whom you contract with — and what that means for third-country transfer.

From a revDSG view, the CH-≠-EU question is no detail: relative to the EU, Switzerland is a third country with an adequacy decision. Which entity is right for your case, and what follows for third-country transfer (including CH ↔ EU), we set out concretely before signing — not afterward in the fine print.

Indicium Technologies AG
Hünenberg, Canton of Zug (Switzerland) · UID CHE-349.104.783
Indicium Technologies GmbH
Hamburg (Germany) · Hamburg Local Court, HRB 164822
EU adequacy decision 2000/518/EC for Switzerland — in force.
09 Sub-processors

We name our core sub-processors — and disclose the full list to you and your regulator.

a
AWS (Amazon Web Services EMEA SARL, Luxembourg)
Cloud hosting, eu-central-1 Frankfurt.
b
Google Cloud EMEA Ltd. (Ireland)
AI processing, Vertex AI.
c
Indicium Technologies AG (Switzerland)
Parent company, development.

Current sub-processors as of July 2026. Changes notified per AVV §7.

The full sub-processor list — with each one’s location and function — is available under NDA, before signing. To you as contracting party and to your regulator we disclose it fully; DORA and the EBA outsourcing guidelines require exactly this disclosure anyway.

And because outsourcing governance doesn’t end at signing: under Art. 28(2) GDPR we assure advance notification of every sub-processor change, with a right to object.

Request sub-processor list with locations (NDA) — via trust.indicium.ag
10 Human final review

On reports with significance, a human decides — never the machine alone.

Art. 22 GDPR prohibits a solely automated decision with legal effect about a person. The clarification your legal department is looking for: at Indicium there is no such decision. The software prepares; the decision on the merits is yours.

a
Fixed trigger thresholds
Documented triggers for human final review — not “sensitive case by gut feeling.”
b
Proof of analyst qualification
Named by role — without real names on the public page.
c
Four-eyes principle in the audit trail
A qualified person reviews, assesses and stands behind the finding — traceably documented.
11 Error types & liability

We catch the false hit. The structural limit we tell you — instead of claiming “gapless.”

Two error types, honestly separated. The false positive — the wrongly flagged hit — is assessed by human final review before it takes effect. The more liability-critical one is the false negative, the missed real risk. We address it not with the word “gapless” but with documented methodology, named source coverage and clearly marked structural limits.

What research from open and licensed sources structurally cannot see, we tell you in every report: cash, unregistered offshore trusts with no register, hidden non-public holdings. Where your case lies beyond this line, analyst-led depth begins — and we say so before you commission, not after.

Liability and risk allocation, up front. The basic structure of our risk allocation is on the table before the demo; the negotiated wording is governed by the contract. Full contractual documentation, TOMs and sub-processor details are available via trust.indicium.ag before signing. We don’t sell a guarantee of success — we deliver the report you can present.

12 SLA, exit & resilience

As numbers up front — not reassurance during onboarding.

Outsourcing often fails on the unspoken question: what if the provider goes down — or we want out again? We answer it with benchmarks before you sign.

a
Availability
Target: 99% availability.
b
Support & escalation
Named tiers; the incident reporting chain spelled out to DORA deadlines.
c
Breach notification
Within 72 hours per Art. 33 GDPR.
d
Exit with machine-readable return format
A defined transition phase — and the explicitly resolved tension between the deletion claim and the regulatory retention duty (typically 5–10 years).
e
Resilience, dated
Two operating entities (CH and DE), ongoing production operation, incident reporting chain, data access on provider failure (escrow/exit).
13 Data-subject rights

Whoever collects third-party data owes data-subject rights — we settle up front who answers them.

In a person check, data is regularly not collected from the data subject themselves. That triggers duties — and who bears them belongs settled before signing, not deferred to a dispute. Who answers these requests — Indicium or you — is clearly governed in the contract, depending on the assigned role. No gray zone where in the end no one is responsible.

Art. 14
Duty to inform when collecting from third-party sources, including the relevant exceptions — checked case by case.
Art. 15
The data subject’s right of access.
Art. 17
Erasure — weighed against the regulatory retention duty of the reviewable file.

Hold this page against your checklist — then talk to us.

What’s public here is the table of contents and the honest line; what goes deeper we open under NDA, before signing — so your second line can exercise its veto before it gets expensive.

Request the Trust Package under NDA Book a call