EQS Group Logo

EQS Trust Center

Start your security review
View & download sensitive information
ControlK

EQS Group is a leading international cloud provider in the fields of corporate compliance, investor relations, and sustainability reporting.

EQS Group’s products are pooled in the cloud-based software EQS COCKPIT. This platform ensures the professional handling of compliance workflows in the fields of whistleblower protection and case management, policy management, business approvals, third-party management, insider list management, disclosure obligations, sustainability reporting including automated ESG data collection, management, and filing in compliance with regulations.

In addition, listed companies benefit from a global newswire, investor targeting and contact management, Investor Relation websites, digital reports, and webcasts for efficient and secure investor communications.

EQS Group was founded in 2000 in Munich, Germany. Today, the group employs around 600 professionals and has offices in the world’s key financial markets.

Find out more at https://www.eqs.com/about-eqs/#about

LEGAL NOTICE

  • Airbus
  • AMAG MediaTeam
  • ARTE Radio
  • Austro Holding
  • Badoo
  • Banco Bilbao Vizcaya Argentaria
  • Boehringer Ingelheim
  • Botify
  • B&B HOTELS GROUP
  • Capgemini
  • China Telcom
  • DELFINGEN
  • Deutsche Bank
  • DZ BANK
  • E.On
  • ERGO
  • Erste Group
  • ERT Technologies SAS
  • Eutelsat
  • Ferrero
  • FRANCE 24
  • GOLDBECK
  • Groupe IDEA
  • Groupe ETAM
  • Halfords
  • HelloFresh
  • HTL Biotechnology
  • Hugo Boss
  • ITA Airways
  • KIABI FRANCE
  • La Banque Postale
  • Leifheit
  • Mangopay.com
  • Meyer Turku
  • Mercedes-Benz
  • Meta
  • Munich Re
  • N26
  • OpenAI
  • PUMA
  • Rosenbauer Group
  • SAP
  • SIGNAL IDUNA Gruppe
  • Sisal
  • SIXT Group
  • Toshiba
  • UBS
  • Zalando

Documents

DOCUMENTSGeneral Bridge Letters
Knowledge Base (FAQ)
  • Are all employees subject to confidentiality?
  • SLAs
  • PII and other sensitive data are encrypted at rest
  • Data processing Exhibit for EQS Cloud Services
  • Is there a security incident process?
View more

EQS Trust Center Updates

EQS Group renews EU Cloud Code of Conduct compliance through the Cloud Security Alliance Framework

Compliance

We are pleased to announce that EQS Group has successfully renewed its declaration of adherence to the EU Cloud Code of Conduct (EU Cloud CoC) through the dedicated framework established in collaboration with the Cloud Security Alliance (CSA). This renewal reaffirms EQS Group's ongoing commitment to robust data protection practices and to transparently demonstrating GDPR compliance year after year.

The EU Cloud CoC is a comprehensive compliance tool that enables cloud providers to legally demonstrate their GDPR adherence efforts while promoting standardization, transparency, and accountability. Greenlit by the European Data Protection Board (EDPB), the Code has become a trusted benchmark across the cloud industry, supporting risk assessments, harmonizing compliance practices, and fostering trust in digital services. In parallel, CSA is a global leader in IT and cybersecurity certifications, all featured in the (STAR Registry), which provides cloud users with clear, trustworthy standards for assessing cloud services.

The successful renewal of this adherence underscores our continued efforts to uphold GDPR compliance and contribute to advancing industry best practices. EQS Group's ongoing adherence not only strengthens the EU Cloud CoC ecosystem but also demonstrates the lasting relevance of practical, sustained compliance solutions for the global cloud market.

For further information and the declaration of adherence, kindly head to EQS Compliance Cockpit – EU Cloud CoC
Do not hesitate to reach out to infosec@eqs.com for any inquiries related to the EU Cloud Code of Conduct Declaration of Adherence.

The EQS team

EQS Security Update: Recent Cryptographic Research

Vulnerabilities

EQS has reviewed Anthropic’s recently published research concerning weaknesses in the HAWK post-quantum signature candidate and a reduced-round version of AES.

We have identified no impact to EQS Cloud Services or Customer Data:

  • HAWK is an experimental candidate undergoing NIST evaluation. It is not deployed by EQS.
  • The AES research applies only to a seven-round research variant of AES-128. It does not compromise standardized, full-round AES or the AES-256 encryption used within applicable EQS security controls.

The research demonstrates the value of rigorous cryptographic review before new algorithms are adopted. EQS continues to monitor NIST standardization, cryptographic guidance, and emerging research through its established cryptographic review and risk-management processes.

No action is required from EQS customers.

Further information: https://www.anthropic.com/research/discovering-cryptographic-weaknesses

EQS Position on AI-Accelerated Vulnerability Discovery and Zero-Day Risk

General

EQS is closely monitoring the evolution of AI-assisted vulnerability discovery and exploit development, including public reporting around Anthropic’s Claude Mythos Preview and related industry initiatives such as Project Glasswing. We do not treat this as a single-vendor or single-model issue. Our position is that “Mythos-class” capabilities are part of a broader shift: vulnerability discovery, exploit validation, patch-diff analysis, and attack automation are becoming faster, more accessible, and more scalable.

This development reinforces EQS’s existing security direction: controls must become faster, more evidence-based, and more integrated into software development, operations, supplier management, and incident response.

Scope of the Threat

EQS uses the term “Mythos-class” as shorthand for a broader class of AI-assisted vulnerability discovery and exploitation workflows. The risk is not dependent on an attacker having direct access to Anthropic’s Claude Mythos Preview or any other specific frontier model.

Material parts of these capabilities are already available today by combining existing AI models with coding agents, security tools, fuzzing, static analysis, exploit frameworks, vulnerability intelligence, patch-diff analysis, and human operator expertise. Well-orchestrated use of existing models can already accelerate vulnerability discovery, exploit validation, and remediation pressure.

For this reason, EQS treats Mythos as a signal of the direction and speed of change, not as the sole source of the threat. Our security response is model-agnostic and focused on reducing exposure, improving detection and remediation speed, strengthening Secure SDLC controls, and limiting blast radius.

CSA Alignment and Industry Collaboration

EQS aligns its approach with relevant industry guidance, including the Cloud Security Alliance publication The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program. This guidance reflects the same core assumption used by EQS: AI is changing the speed, scale, and economics of vulnerability discovery, and security programs must adapt beyond traditional patching and vulnerability-counting models.

EQS has been actively engaged in Cloud Security Alliance activities and has participated early in the discussion and definition of practical responses to AI-accelerated vulnerability risk. EQS is also listed in the CSA STAR Registry and holds the CSA Trusted Cloud Provider trustmark, reflecting our ongoing commitment to cloud security transparency, assurance, and community contribution.

This external collaboration complements EQS’s internal security work. We use CSA guidance as one input into our ongoing improvements across Secure SDLC, exposure management, third-party risk, security operations, incident response, and customer transparency.

Vulnerability and Patch Management

EQS maintains vulnerability management processes covering infrastructure, applications, dependencies, cloud services, containers, and supporting systems. Newly disclosed vulnerabilities are assessed using exploitability, exposure, reachability, affected services, affected data, compensating controls, dependency context, and evidence of active exploitation.

For critical vulnerabilities affecting customer-facing services, EQS applies expedited triage, emergency change handling, and prioritized remediation or containment. Where a fix cannot be safely deployed immediately, compensating controls may be applied to reduce exposure and blast radius while remediation proceeds.

EQS is continuously strengthening automated security checks, dependency visibility, software bill of materials coverage, reachability-based prioritization, and AI-assisted review in development workflows.

Vulnerability Prioritization and Use of CVSS

EQS does not rely on CVSS as the primary driver for vulnerability prioritization. CVSS may be considered as one contextual input where available, but it has never been a decisive factor in EQS vulnerability handling and is even less suitable as a standalone prioritization mechanism in the current threat environment.

Many SaaS-specific vulnerabilities do not have a CVE at all. CVEs are typically available for known components or publicly disclosed issues, but not for all application-specific, configuration-specific, or business-logic weaknesses. In addition, the fact that a component has a vulnerability does not automatically determine the actual risk for a service using it. Exposure, reachability, exploitability, compensating controls, and business impact are decisive.

EQS prioritizes vulnerabilities based on practical risk to EQS services and customers, including active exploitation, exploit availability, internet exposure, affected asset criticality, data sensitivity, dependency context, and operational impact. This prioritization can function independently of whether a CVE or CVSS score is available.

This approach also reflects the increasing strain on public vulnerability infrastructure. The CVE and NVD ecosystem is facing record vulnerability volumes, delayed or incomplete enrichment, and changing prioritization models. NIST has stated that CVE submissions increased by 263% between 2020 and 2025 and that NVD will no longer immediately enrich all CVEs or routinely provide separate NIST severity scores where a CVE Numbering Authority has already provided one. FIRST has similarly advised organizations to focus on vulnerabilities that pose the greatest risk to their specific environment, not only those with the highest CVSS scores.

Accordingly, EQS treats CVSS as a useful reference point, not as a substitute for exposure-based, exploitability-based, and business-impact-based security judgment.

Detection of Emerging Attack Patterns

EQS uses a combination of threat intelligence, vendor advisories, security monitoring, vulnerability feeds, automated tooling, and internal security analysis to identify emerging attack techniques. We explicitly consider AI-enabled attack acceleration in security planning, including higher vulnerability volumes, faster exploit development, and increased pressure on triage and remediation workflows.

Our security strategy is moving from traditional vulnerability counting toward exposure management: prioritizing what is exploitable, reachable, business-critical, or actively targeted.

Protection Against Zero-Day Exploits

No organization can guarantee prevention of all zero-day exploitation. EQS therefore applies layered controls designed to limit the likelihood and impact of unknown vulnerabilities. These include secure configuration baselines, least-privilege access, privileged-access protections, network and service segmentation, logging and monitoring, hardened deployment pipelines, application security testing, dependency controls, and containment procedures.

The goal is to reduce reachable attack surface, limit lateral movement, detect suspicious behavior early, and preserve the ability to contain or recover quickly.

Incident Response and Escalation

EQS maintains incident response processes with defined escalation paths, internal ownership, customer communication procedures, and management involvement for significant security events. For rapidly evolving vulnerability or exploitation scenarios, EQS can activate expedited assessment, containment, remediation, and communication workflows.

Customers are informed through the appropriate contractual and operational channels when a confirmed security issue materially affects the confidentiality, integrity, availability, or risk profile of services provided to them.

Ongoing Security Enhancements

EQS is continuously enhancing its security practices in light of AI-enabled threats. Current focus areas include:

  • AI-aware Secure SDLC controls
  • stronger vulnerability and dependency visibility
  • faster triage and remediation workflows
  • AI-assisted code and security review
  • tabletop exercises for rapid-exploitation and multi-vulnerability scenarios
  • improved security telemetry and evidence capture
  • governance for AI systems, agents, connectors, and automation
  • developer and security-team training for AI-era risks

This work is intended to improve defensive speed and governance quality without disclosing sensitive internal architecture, tooling configuration, or operational playbooks.

Third Parties and Subprocessors

EQS manages third-party and subprocessor risk through due diligence, contractual security expectations, supplier monitoring, compliance reviews, and review of relevant advisories or incidents.

EQS uses multiple sources and tools to monitor third-party risk. Where an increased risk signal is identified for a relevant supplier, EQS receives alerts and assesses the potential impact on services, data, and customers. These signals may include security advisories, vulnerability information, external risk indicators, compliance changes, potential “dark web” reports and data leakages, incident notifications, or other material changes in the supplier’s risk profile.

In addition to ongoing monitoring, EQS performs periodic compliance reviews of relevant suppliers, including an annual review cycle for applicable third parties and subprocessors. Where third-party technology forms part of EQS services, vulnerabilities are assessed according to exposure, exploitability, service impact, and available compensating controls.

EQS expects relevant suppliers to support timely vulnerability handling, security communication, and incident cooperation.

Transparency and Communication

EQS provides security transparency through the Trust Center, contractual documentation, and direct customer communication where appropriate. Public Trust Center materials describe our control approach at a level suitable for customers and auditors. For security reasons, EQS does not publicly disclose detailed detection logic, internal tooling configuration, supplier-specific exposure maps, vulnerability backlogs, or incident playbooks.

EQS will continue to monitor AI-enabled vulnerability discovery and update its security practices as the threat landscape evolves.

Relevant Public References


For security-related questions, customers may open a request against the InfoSec queue on our Support Center or contact EQS Information Security at infosec@eqs.com.

Dr. Marco Ermini
Chief Information Security Officer, EQS Group

TISAX AL3 Labels for EQS location in Denver

Compliance

We’re excited to share that EQS Groups Denver location has successfully achieved TISAX® Assessment Level 3 (AL3) for the following objectives:

• Data protection (including special categories of personal data)
• Very high availability
• Strict confidentiality

This is the highest assessment level within the TISAX framework and confirms that our site meets very stringent information security requirements expected by partners in the automotive industry. The scope covers all relevant processes and resources related to the collection, storage, and processing of information.

The assessment is valid until September 23, 2028, reinforcing our long-term commitment to maintaining strong security standards and building trust with our customers and partners.
The TISAX decorative assessment document can be accessed here in our Trust Center at https://trust.eqs.com/product/eqsgroup/tisax

Planned Maintenance Notification – Private Cloud Hosting (T-Systems)

Compliance

We would like to inform you about an upcoming migration to a new hosting platform affecting customers using Compliance Cockpit and BKMS System with private cloud hosting at T-Systems.

Schedule & Scope

Saturday, April 18, 10:00 – 12:00 (CEST)

Migration of Data Center and Integrity Line

Impact: During the maintenance window, users may experience short interruptions affecting login, web intake, and the Compliance Cockpit.

Sunday, April 19, 10:00 – 12:00 (CEST)

Migration of BKMS System

Impact: During the maintenance window, users may experience short interruptions affecting login, web intake, and the BKMS System.

Additional Information

We are working to minimise any disruption and ensure a smooth transition to the new hosting environment. Services will be fully restored once the maintenance windows are completed.

If you have any questions, please contact our support team.

Thank you for your understanding.

If you need help using this EQS Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo