fiskaly. Trust Center
Get to know fiskaly's information security, compliance, and data privacy.
Information security
fiskaly has an ISO 27001-certified information security management system (ISMS). The scope covers the entire group of companies, including fiskaly Germany, Deutsche Fiskal, fiskaly Italy, and fiskaly Iberia. This ensures that uniformly high security standards and controls are applied in all our markets and subsidiaries.

Coordinated vulnerability disclosure
fiskaly follows a Coordinated Vulnerability Disclosure (CVD) process in conjunction with its ISO 27001 process. Anyone can submit a vulnerability report to infosec@fiskaly.com

ISO 27001
certified
ISO 9001
certified
GDPR
compliant
EU-based location
fiskaly's services as well as its third parties are located within the EU, ensuring high compliance as well as security and data privacy.

Better in the cloud
A cloud-based approach ensures great availability and strong security. This allows fiskaly to respond faster to incidents through constant monitoring, cooperation with experts and advanced security features.

Information security FAQs
Information Security is a priority for fiskaly. Strict data protection, integrity, confidentiality, and availability requirements are met by our services. These requirements and controls are frequently audited internally and by independent organizations.
As a consequence of the commitment to information security, fiskaly and its subsidiaries have been audited and certified by several standards. More information on our certifications can be found on our Certificates and Associations page.
One of the most relevant certifications in the field of information security is the ISO/IEC 27001 standard. fiskaly and its subsidiaries have been successfully audited and certified against this standard. The current certificate can be found here.
The latest certification audit was successfully conducted in March 2024 with a positive result, which extends the validity of our certificate and covers fiskaly and all its subsidiaries. fiskaly’s certificate can be verified on the official CIS website (Certificate Nr. I-00548/0).
Our Information Security Management System (ISMS) and ISO 27001 certification cover all operational units of the fiskaly Group. This explicitly includes the following companies:
- fiskaly Germany
- Deutsche Fiskal
- fiskaly Italy
- fiskaly Iberia
This comprehensive scope ensures that customer data and processes are subject to the same high level of protection regardless of location or specific country unit.
We take the security of our systems and services seriously. External parties may report potential security vulnerabilities via infosec@fiskaly.com
Please include:
- the name of the system or service and the version(s) affected
- a simple description of the vulnerability
- how the vulnerability can be reproduced, including any additional tools required
- a risk assessment, preferably using a CVSS score
Handling of reports
Reported vulnerabilities are reviewed and assessed by the responsible security team in accordance with our internal security and risk management processes. Valid reports will be acknowledged within a reasonable timeframe.
Disclosure
We follow a coordinated approach to vulnerability handling. Each vulnerability report will be kept confidential to the extent permitted by law.
If the vulnerability report includes personal data, these will be handled in accordance with our privacy policy. Please do not publicly disclose vulnerabilities affecting our systems without prior coordination.
Legal notice
Reports must be submitted in good faith and must not involve unauthorized access, data modification, or actions that could impact service availability. All activities must comply with applicable laws.
The organized controls included in fiskaly’s statement of applicability from the ISO 27001:2022 can be viewed in detail here (section 6).
Because of confidentiality reasons, sharing of internal documents related to our ISMS (Information Security Management System) and the processes documented therein with third parties is not possible.
Nevertheless, interested third parties can request an audit on fiskaly by a competent authority.
The total cost of the audit and resources used for it are to be covered by the requesting third party.
More information and further requests can be made through the following email address: infosec@fiskaly.com.
To support the growth of fiskaly and our customers, we focus on compliance and a secure, transparent supply chain. To learn more, you can read our Code of Conduct and Anti-Corruption Guideline.
DF Deutsche Fiskal is committed to integrity, transparency, and responsible business practices. Our Code of Conduct defines the ethical principles and standards that guide our decisions and actions.
With this Code of Conduct, we formalize our values and ethical principles that guide our decisions and actions toward our business partners, investors, society, and the environment.
All executives, employees of DF Deutsche Fiskal GmbH (hereinafter referred to as “DF”), as well as individuals acting in the name of and on behalf of DF, are bound by the minimum standards established in this Code of Conduct and the associated policies.
The following provisions are intended to create the best possible framework for a business and working environment characterized by integrity, respect, and fair conduct, while complying with ethical and legal standards. We are committed to international agreements on the protection of human rights, anti-corruption, free competition, and sustainability.
German – download PDF English – download PDF
The legally binding version of this Code of Conduct is the German version. Any translations into other languages are provided for informational purposes only and serve to communicate the rules and principles originally formulated in German.
Our security team
fiskaly has a dedicated information security team solely focused on safeguarding information security and data privacy. This team works continuously to identify, reduce, and mitigate risks while enhancing our processes and strengthening security controls.

Open questions?
Our team is happy to answer any additional questions you might have.
For security questions: infosec@fiskaly.com
For privacy questions: privacy@fiskaly.com


