We check people. Check us — before you sign.
Your second line will not read this page like a brochure. They will check data residency, sub-processors, liability, security controls and exit. This page is built for that review.
This is no promise but a reviewable document package — the Trust Package. We publish the table of contents up front. The detailed documents are available under NDA before signing, so you can hold it point by point against your own MaRisk, DORA or TPRM checklist.
A preliminary note that sets the tone of this page: we deliberately do not claim legal certainty or that a report can be presented as a court-proof instrument. In the same spirit, we claim no attestation we don’t hold and no sovereignty we don’t deliver. What you read below is the honest version, residual risks included.
The first question isn’t who gets checked — it’s who at our end sees whom you check.
A search query is itself data worth protecting. The mere fact of the query reveals who is checking whom — and why now. For professionals bound by confidentiality, general counsel and family offices, this is the decisive purchasing point. We treat it as such — contractually assured, not just technically claimed:
We solve the DPA under professional-conduct law, not only data-protection law.
A data-protection-compliant DPA isn’t enough for the lawyer — she needs one that carries her professional secrecy. That’s exactly where most standard DPAs start and stop. The concrete statutory reference is in the Trust Package — so you can check it before you enter the first client name.
Deletion duty and retention duty — resolved, not left in conflict.
The reflexive data-protection line is: “We delete everything.” For a regulated client, that’s precisely a problem — the regulator requires the reviewable report file to remain demonstrable for five to ten years. We resolve the conflict in writing. The DPA under Art. 28 GDPR governs:
Every requirement against the clause that meets it — as a mapping, not a seal.
Three compliance logos side by side prove nothing. Your outsourcing governance wants to see which contract clause carries which regulatory requirement — line by line, reviewable.
| Regime | Core requirement | Met by contract clause |
|---|---|---|
| DORA Art. 30 | Mandatory ICT third-party contract content, audit & access rights, termination rights | — |
| MaRisk AT 9 | Materiality assessment, instruction, information & control rights, sub-outsourcing | — |
| NIS2 Art. 21 | Supply-chain risk-management measures | — |
| VAG-Outsourcing (§ 32 VAG) | Insurance-specific outsourcing, BaFin supervisory & audit rights | — |
This includes what the second line really asks: audit, information and instruction rights for you and your regulator (BaFin, FINMA). Support for your DORA information register under Art. 28(3) DORA, with a sample register entry. An honest assessment of concentration and substitutability risk. And where your own on-site audit would be disproportionate, we name pooled audits and an ISAE 3402 report as a recognized substitute.
We check from open and licensed sources — and tell you on which legal basis.
We hold no attestation we don’t have. We run the controls that matter behind it.
So we say it plainly: we hold no ISO 27001 and no SOC 2 today. We don’t claim it, and we don’t write “in preparation” either, because a status line without substance says nothing.
What we present instead is the substance an attestation would only certify anyway — the technical and organizational measures (TOMs) in effect today under Art. 32 GDPR and the compensating controls:
We ourselves buy only from providers that pass a clean security due diligence. Hold us to that same standard.
“Made in Europe for Europe” — and the honest point where that is still a goal today.
Sovereignty is often sold in this market as an absolute claim. We don’t say that, because today it wouldn’t be the whole truth — and because a claim your own review immediately finds a crack in costs more trust than it earns. Here’s how it really looks with us:
Separately, the second half of the truth: some of our sanctions and PEP reference data comes from international providers. That concerns the origin of the matching data — not the residency of your query and personal data. We separate the two openly instead of merging them under a sovereignty label.
We tell you up front whom you contract with — and what that means for third-country transfer.
From a revDSG view, the CH-≠-EU question is no detail: relative to the EU, Switzerland is a third country with an adequacy decision. Which entity is right for your case, and what follows for third-country transfer (including CH ↔ EU), we set out concretely before signing — not afterward in the fine print.
We name our core sub-processors — and disclose the full list to you and your regulator.
Current sub-processors as of July 2026. Changes notified per AVV §7.
The full sub-processor list — with each one’s location and function — is available under NDA, before signing. To you as contracting party and to your regulator we disclose it fully; DORA and the EBA outsourcing guidelines require exactly this disclosure anyway.
And because outsourcing governance doesn’t end at signing: under Art. 28(2) GDPR we assure advance notification of every sub-processor change, with a right to object.
Request sub-processor list with locations (NDA) — via trust.indicium.ag ↗On reports with significance, a human decides — never the machine alone.
Art. 22 GDPR prohibits a solely automated decision with legal effect about a person. The clarification your legal department is looking for: at Indicium there is no such decision. The software prepares; the decision on the merits is yours.
We catch the false hit. The structural limit we tell you — instead of claiming “gapless.”
Two error types, honestly separated. The false positive — the wrongly flagged hit — is assessed by human final review before it takes effect. The more liability-critical one is the false negative, the missed real risk. We address it not with the word “gapless” but with documented methodology, named source coverage and clearly marked structural limits.
What research from open and licensed sources structurally cannot see, we tell you in every report: cash, unregistered offshore trusts with no register, hidden non-public holdings. Where your case lies beyond this line, analyst-led depth begins — and we say so before you commission, not after.
Liability and risk allocation, up front. The basic structure of our risk allocation is on the table before the demo; the negotiated wording is governed by the contract. Full contractual documentation, TOMs and sub-processor details are available via trust.indicium.ag before signing. We don’t sell a guarantee of success — we deliver the report you can present.
As numbers up front — not reassurance during onboarding.
Outsourcing often fails on the unspoken question: what if the provider goes down — or we want out again? We answer it with benchmarks before you sign.
Whoever collects third-party data owes data-subject rights — we settle up front who answers them.
In a person check, data is regularly not collected from the data subject themselves. That triggers duties — and who bears them belongs settled before signing, not deferred to a dispute. Who answers these requests — Indicium or you — is clearly governed in the contract, depending on the assigned role. No gray zone where in the end no one is responsible.
The table of contents — open, no NDA.
Hold it against your own checklist. The documents themselves we open under NDA via our document hub trust.indicium.ag ↗ — before signing.
Numbering matches the Trust Package register; the “8.x” references in our FAQ point to this.