Hosted 100% in Germany · No US subprocessors

Security Compliance,
die Vertrauen schafft.

Kontinuierliche AWS- & Azure-Audits für NIS2, DSGVO, BSI C5 und ANSSI. Nur-Lese-Zugriff, EU-Datenresidenz.

Pläne vergleichen

Keine Kreditkarte5 Scans/Monat kostenlosEU-Datenresidenz

Overall Compliance
87/100
↑ +4% vs last scan
NIS2
91%
DSGVO
84%
BSI C5
78%
ANSSI
82%
Critical findings
S3 bucket encryption disabled
28d open
MFA not enforced on root
12d open
CloudTrail logging disabled
5d open

One platform for automated audit-readiness

Warum ConformScan?

270+

Automated Compliance Checks

Continuous audit across AWS, Azure and GCP for NIS2, DSGVO, BSI C5, ANSSI, CIS Benchmarks, and ISO 27001. Results in minutes, not weeks.

resource "aws_s3_bucket" {
# ConformScan fix
server_side_encryption {
apply_by_default = true
}
}

Remediation Code

Copy-paste Terraform or CLI fixes for every finding.

Findings Tracker & Drift Detection

Every finding is timestamped, versioned, and tracked across scans. See regressions the moment they happen — not after your auditor does.

+47pts

Slack · Teams · Jira

Critical findings land in your channel or ticket queue automatically — with SLA countdown so nothing stays open past deadline.

🔴 S3 bucket unencrypted · NIS2 · 3d SLA
🟡 MFA not enforced · 12d open

Audit-Ready PDF Reports

One click — a complete audit report lands in your inbox. Available in EN, DE, and FR for cross-border compliance teams.

Executive Summary

One page your board actually reads: overall score, top 3 risks, week-over-week trend, and a PDF export ready for your next governance meeting.

87
Score
↑4%
vs last scan
3
Critical

Teams & Role-Based Access

Owner, Admin, Member, Viewer — each role sees exactly what they need. Full audit log of who did what, when.

OwnerAdminMemberViewer

CI/CD Integration

Block non-compliant infra before it ships. 10 ready-to-use templates for GitHub Actions, GitLab, Jenkins, Terraform, and more.

- name: ConformScan check
run: conformscan scan --fail-on critical

Supported Compliance Frameworks

From NIS2 to ISO 27001, continuous audits for the regulatory standards that matter most in the EU.

Mandatory since Oct 2024

NIS2 Directive

EU-wide cybersecurity risk management and incident reporting requirements for essential and important entities.

Up to €20M fines

DSGVO / RGPD (GDPR)

Requirements to protect personal data and ensure privacy.

German Standard

BSI C5 Catalogue

Security catalogue for cloud services, required for German public sector.

French Certification

ANSSI SecNumCloud

French cybersecurity standard essential for public sector contracts.

Global Standard

ISO 27001 & CIS Benchmarks

Security management and cloud infrastructure configuration guidance.

Your data never leaves the EU.

Our servers run in Germany (Netcup, Karlsruhe). Credentials are encrypted at rest with Fernet and never exit the EU. Read-only IAM access only.

EU Residency Check — PASS

> scanning infrastructure...

EC2_012 | Checking instance region...

PASS | Region is 'eu-central-1' (Frankfurt)

AZURE_STORAGE_001 | Checking location...

PASS | Location is 'Germany West Central'

RDS_007 | Checking DB region...

PASS | Region is 'eu-central-1'

Compliance Risks

Why it matters.

NIS2 — Art. 21 & 23
€10M
or 2% of global turnover

Failure to implement adequate security measures or report an incident within 24 hours.

ConformScan flags this in 3 days
DSGVO / GDPR — Art. 83
€20M
or 4% of global turnover

Processing personal data without adequate technical safeguards. Unencrypted databases or public S3 buckets.

ConformScan flags this in 7 days
BSI C5 — Public sector
Lost contracts
disqualification from tenders

German federal procurement increasingly requires BSI C5 attestation. Without it, you cannot bid on public sector contracts.

Maps every check to BSI C5

“ConformScan told us we had an unencrypted RDS instance that had been open for 34 days. We didn't know. Our auditor did.”

— Head of IT Security, German logistics company (180 employees)

Einfache, transparente Preise

Scale as your compliance needs grow.

Starter
Kostenlos
1 Scans/Monat
  • 1 framework
  • Basic compliance checks
  • Email support
Professional
€99/Monat
Unlimited scans · 5 accounts
Popular
  • All 6 EU frameworks
  • PDF audit-ready reports (EN/DE/FR)
  • SLA escalation + Slack/Teams/Jira
  • Scheduled scans + CI/CD scan triggers
Enterprise
€299/Monat
Unlimited accounts
  • Everything in Pro
  • Full REST API + CI/CD templates + IaC scanning
  • SSO (SAML/OIDC)
  • Self-hosted · Priority support