Third Party Index

Snapshot 72409

Document
Security page
URL
https://www.aeb.com/en/trust-center/security.php
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
264001 bytes
SHA-256 (raw)
85878b9110a78ac3a9cf695ea62913e23e456260ad7146049f96e96ea2e8e326
SHA-256 (normalized text)
53556d412ed1e506b3bc4e5be8e9ebf21d896bee906099736d2f3b9596b60c2a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Home
Trust Center
Security
Security at AEB
Availability, confidentiality, integrity - these are AEB's top security objectives. This goes beyond the technical nuts and bolts of our IT solutions. It also covers the availability of our contact persons, the confidentiality with which we handle business partner data, and the integrity we ensure through clear data processing workflows.
Certified security
Login & authentication
Secure products
Security in HQ
Emergency preparedness
All documents
Contact
Certified security
The security and protection of your data are part of our AEB DNA and have always been an integral part of our solutions.
That's why AEB has had ISO 27001 certification for data center (cloud) operations and product development for over ten years and is also certified as an „Authorized Economic Operator - Security“ (AEO-S).
AEB is focused not only on operational and risk management aspects, of course. We also prioritize the modern security mechanisms necessary to protect data. This includes next-generation firewalls, intrusion detection and prevention systems, automatic alerting, and much more - all running with multiple levels of redundancy.
AEB performs penetration tests several times a year and also regularly scans all logins and applications in the AEB Cloud, so we're able to proactively identify potential vulnerabilities and attack scenarios.
Certified as an „Authorized Economic Operator - Security“ (AEO-S)
ISO 27001 certification
Authorized Economic Operator - Security“ (AEO-S) certification. View all certificates
Role-based login & authentication
AEB deploys a central user repository and role-based security model to control the physical and electronic access of customers and employees to resources and solutions. This ensures that users can access only the applications and environments for which they are actually authorized. Users are consolidated in role groups, with access granted strictly to role objects, not individual user objects.
Users with special administrative rights or privileges are also consolidated in appropriate role groups, where they are subject to the groups' processes and approvals. Particularly sensitive privileges (such as access to firewalls or admin portals) require the user to have a special personalized administrator account. „Normal“ user accounts are not granted these rights and cannot be assigned to the corresponding roles.
Excerpt from the AEB Security Concept: Details on access and access control
Last update: 31.10.2024
This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications.
This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications.
Secure products
Quality assurance at AEB means that before any new code goes live, our test managers perform manual testing for strict compliance with data protection and security requirements and our own in-house specifications. We also run continuous automated testing during the development phase to protect our software against unintended side effects.
Access restrictions and role concepts ensure the security of our software products during operation.
Excerpt from the AEB Security Concept: Details on the handling of data in general
Last update: 08.12.2023
The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)).
The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)).
Security in AEB headquarters
Access to AEB offices and infrastructure is generally restricted to AEB employees. All comings and goings are logged. Guests must be announced in advance by the AEB employee who invites them and then register upon arrival at the reception desk. They must remain on the ground floor and visibly display a guest pass so that everyone can recognize them as guests.
Only trained AEB employees have physical access to the data centers, with two-factor authentication and video monitoring providing extra layers of security.
All employees are encouraged to approach or report unknown or suspicious visitors. After hours, this task is handled by security personnel, who check all rooms and specified points. This ensures that there are no unauthorized people in the building or on the premises.
Emergency preparedness: AEB Business Continuity Management
Significance
When logistics and customs processes come to a standstill, this can have massive consequences for many companies. That's why it's essential that AEB Cloud software, services, and support remain available without any hiccups. AEB has implemented a comprehensive business continuity management system to ensure that this is the case - even when the unexpected occurs.
„For us, business continuity management is an essential part of risk management,“ explains Martin Setzler, member of the Board of Directors and responsible for IT at AEB. „That's why we also see it as closely interlinked with our ISO 27001-certified information security management system, in which business continuity is defined as a separate area of regulation.“
Objectives
Emergency prevention
The structure of AEB's business continuity management (BCM) is described in the AEB Business Continuity Guideline, based on the BCM Standard 100-4 issued by Germany's Federal Office for Information Security (BSI) and the ISO 22301 and ISO 22313 standards. BCM is divided into two core areas of action: emergency prevention and emergency management.
The preventive measures are defined in an emergency preparedness concept aimed at reducing both the probability of occurrence and any possible damage. The key question: Which precautions and actions must be taken to immediately restore system availability in the highly improbable event of a partial or complete system failure?
Business Continuity Policy
Last update: 16.07.2025
The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level.
The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level.
Emergency management
The emergency preparedness concept comprises tools that allow AEB to correctly classify and evaluate its processes by relevance so that emergency measures can be executed smoothly. This includes regular drills.
Should an emergency ever actually occur and AEB or its solutions ever suffer a disruption, an Emergency Guide provides a clear definition of processes and responsibilities. The Emergency Guide contains predefined contingency plans for various scenarios to ensure quick, efficient decision-making processes, even during a crisis.
These measures help reassure customers that AEB will respond to even a worst-case scenario in an ordered and professional manner to get AEB services up and running again quickly.
All documents
Basic information
Security Concept
Last update: 27.01.2026
The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)).
The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)).
Integrated Management System Guideline
Last update: 16.07.2025
This guideline describes guiding principles as well as organizational principles of the management systems for quality and information security established in the company.
This guideline describes guiding principles as well as organizational principles of the management systems for quality and information security established in the company.
Business Continuity Policy
Last update: 16.07.2025
The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level.
The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level.
Details of the security concept
Excerpt from the AEB Security Concept: Details on access and access control
Last update: 31.10.2024
This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications.
This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications.
Excerpt from the AEB Security Concept: Details on AEB Cloud Services API
Last update: 01.04.2021
This document provides an overview of the interfaces (APIs) of the AEB Cloud Services and their security concept.
This document provides an overview of the interfaces (APIs) of the AEB Cloud Services and their security concept.
Excerpt from the AEB Security Concept: Details on cryptography
Last update: 23.05.2025
This document provides an overview of the cryptographic methods used in AEB.
This document provides an overview of the cryptographic methods used in AEB.
Excerpt from the AEB Security Concept: Details on the backup strategy
Last update: 01.07.2025
This document describes data backup measures AEB takes to enable data recovery.
This document describes data backup measures AEB takes to enable data recovery.
Excerpt from the AEB Security Concept: Details on the handling of data in general
Last update: 08.12.2023
The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)).
The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)).
Excerpt from the AEB Security Concept: Security event and incident management
Last update: 01.11.2024
This document provides an overview of security event management and security incident management.
This document provides an overview of security event management and security incident management.
Excerpt from the AEB Security Concept: Security vulnerability management
Last update: 01.11.2024
This document provides an overview of the security concept vulnerability management.
This document provides an overview of the security concept vulnerability management.
Certificates: Security
Certificate: ISO/IEC 27001:2022
Last update: 13.10.2024
The certificate attests that AEB has implemented and maintains an information security management system in accordance with ISO/IEC 27001:2022.
The certificate attests that AEB has implemented and maintains an information security management system in accordance with ISO/IEC 27001:2022.
Report IDW PS 951
Last update: 24.04.2025
Since 2019: The standard according to IDW PS 951 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft.
Since 2019: The standard according to IDW PS 951 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft.
Report ISAE 3402
Last update: 24.04.2025
Since 2019: The standard according to ISAE 3402 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft.
Since 2019: The standard according to ISAE 3402 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft.
Zertifikat: AEO-S
Last update: 05.03.2010
Die AEB erhält das AEO-Zertifikat "Sicherheit" (AEO S) auf Grundlage der Sicherheitsänderungen des Zollkodex der Gemeinschaft (Verordnung (EG) 648/2005). Das Zertifikat wurde 2018 erneut überprüft.
Die AEB erhält das AEO-Zertifikat "Sicherheit" (AEO S) auf Grundlage der Sicherheitsänderungen des Zollkodex der Gemeinschaft (Verordnung (EG) 648/2005). Das Zertifikat wurde 2018 erneut überprüft.
Our IT Security Manager
Maik Bolbeth, IT Security Manager
Maik Bolbeth
As an IT Security Manager, I ensure that people can rely on the security of their data and systems.
With more than 12 years of experience in security-related fields within government agencies and in the automotive industry – including roles as a CISO and auditor for ISO 27001 and TISAX – I am familiar with security requirements from both the implementing and auditing perspective.
What keeps me motivated every single day:
Security should not be a hindrance, but rather provide guidance and serve as a foundation for reliable and trustworthy collaboration. I am convinced that strong security develops when it is understandable, taken into account early on, and empowers people instead of blocking them.
That's why I see my role as that of a mediator and facilitator. With clear guardrails, appropriate tools, and open communication.
Questions about IT security at AEB?
Contact the IT Security Manager: srvcbcm