Technical safeguards are only as strong as the processes that govern them and the people who implement them. Therefore, these organizational measures outline the "who," "when," and "under what rules" of our security framework.
The organizational measures described on this page relating to software quality, secure development practices, and the release process apply to both VTS online and VTS offline, as they form part of SCHUHFRIED's standard development and maintenance processes. In the case of VTS offline, however, the software is installed and operated on the customer's own premises and infrastructure. SCHUHFRIED has no access to these systems and no visibility into the data stored within them. Accordingly, responsibility for the organizational and operational security of VTS offline installations, including access management, backup procedures, and compliance with applicable data protection regulations, rests with the customer.
Development process
Secure coding standards
At SCHUHFRIED, software security is integrated directly into the development lifecycle of the VTS by leveraging the robust, "secure-by-default" features of the .NET and Angular frameworks. By utilizing these industry-standard technologies, the system automatically benefits from built-in protections against common web vulnerabilities, such as Cross-Site Scripting (XSS) and SQL Injection. This foundation is reinforced by professional development tools, which act as continuous quality gates by performing real-time analysis to identify and correct potential security flaws before the code is even compiled.
To complement these framework capabilities, our development teams strictly adhere to established secure coding standards and industry best practices, such as the OWASP (Open Web Application Security Project) guidelines. Security is treated as a continuous process rather than an afterthought.
Automated testing
Our commitment to secure coding is robustly validated through a comprehensive automated testing strategy, utilizing both unit tests and end-to-end (E2E) test automation. Unit tests ensure that individual components, data validation routines, and access control logic function exactly as intended at the code level, preventing regressions that could introduce security loopholes. Complementing this, our E2E automation simulates real-world user interactions and complex workflows across the entire VTS ecosystem. By embedding these automated tests directly into our development pipeline, we can instantly detect and mitigate potential security risks or software faults long before software updates reach production.
Mandatory reviews
To ensure the quality and security of every code change, we enforce mandatory code reviews for all changes before they are integrated. This process is supported by AI-assisted code review tools, which automatically scan incoming changes for potential security flaws, logical errors, and styling inconsistencies. By combining this automated AI analysis with human oversight from our development team, we can efficiently vet every modification and ensure that all updates to the VTS ecosystem consistently meet our security standards.
Regression testing
Prior to every release, our dedicated team of qualified Quality Assurance (QA) specialists conducts exhaustive regression testing to ensure that the wide variety of operational scenarios within the VTS ecosystem function flawlessly. Using a professional test management tool, our QA team systematically tracks, executes, and documents these comprehensive test cases. This disciplined approach guarantees that new updates or security patches do not disrupt existing functionalities, maintaining the high reliability and stability our users expect.
Software release process
Every VTS release follows a structured process governed by SCHUHFRIED's Quality Management (QM) system before being made available to customers. For planned releases, a formal code freeze precedes a dedicated regression testing sprint, during which the full test suite is executed against the release candidate. A release can only be approved once all significant defects have been resolved and Quality Management has reviewed and signed off the complete test documentation. For critical issues that require an out-of-cycle fix, a separate hotfix process is triggered, which includes root-cause verification and targeted regression testing. Customers using VTS online are notified in advance of any planned maintenance window, and a rollback procedure is in place in the event that an update cannot be completed successfully.
Operation
EU data residency
To ensure full compliance with European data sovereignty and GDPR requirements, SCHUHFRIED utilizes a geographically restricted hosting strategy. The VTS online production environments as well as related services and infrastructure are hosted exclusively within the Microsoft Azure “West Europe” region, located in the Netherlands.
By pinning our infrastructure to this specific region, we guarantee that all data processing, including primary storage, backups, and failover operations, remains strictly within the legal jurisdiction of the European Union. This approach eliminates the risks associated with data transfers to third countries and ensures that your data is protected by EU privacy standards and Microsoft's robust physical and digital security protocols at the regional level.
Multi-tier environments
SCHUHFRIED ensures the highest level of data integrity by maintaining a strict multi-tier environment strategy, where development, testing, and production systems are logically and physically isolated. In compliance with the principle of data minimization, all sensitive and personal data are processed exclusively within the production environment. For development and testing purposes, we utilize synthetic or fully anonymized data, thereby eliminating the risk of exposing real-world information or impacting the production environment.
Access to the production systems is limited to a small circle of authorized personnel who have undergone verifiable legal instruction and security training. This restricted access is governed by robust authentication protocols and monitored to ensure an appropriate level of protection.
Backup & disaster recovery
SCHUHFRIED maintains regular backups of all vital systems and data.
For VTS online, automated backups are managed by Microsoft Azure, with all backup data remaining within the West Europe region in line with our data residency commitments. In the event of a critical disruption, SCHUHFRIED responds and works to restore service within the timeframes defined in our Service Level Agreement. Planned maintenance that may affect availability is announced well in advance and is scheduled during low-traffic periods to minimize impact on testing operations. In addition to data backups, SCHUHFRIED maintains a disaster recovery plan that defines procedures for restoring service availability in the event of a significant incident.
For more information, see Service level agreement (SLA) – VTS online.
Quality management
At SCHUHFRIED, quality is driven by an active, deeply institutionalized Quality Management System that dynamically governs our daily operations. Rather than treating quality control as a final inspection step, we integrate standardized workflows, continuous risk assessments, and systematic process optimization into every stage of our value chain: from advanced psychological research and software design to hardware manufacturing and global sales. This organizational culture ensures that new scientific findings and technological upgrades are seamlessly integrated into the Vienna Test System (VTS), while at the same time guaranteeing reliable data collection, strict data security principles, and uncompromising data protection for sensitive psychological testing.
ISO 9001:2015
Our official ISO 9001:2015 certification serves as formal, third-party validation of this established internal ecosystem. By verifying our comprehensive scope across research, design, production, and sales, this international standard confirms to our clients and regulatory partners that our quality processes are not merely documented, but actively lived and continuously optimized and audited. It provides objective proof that the VTS is developed and maintained within a highly secure, reliable, and compliant framework that strictly adheres to the highest global standards of data protection and operational excellence.
Personnel security
SCHUHFRIED enforces structured security and privacy obligations throughout the entire employee lifecycle. Every new employee completes mandatory QM and GDPR training as part of their onboarding, and all staff are required to sign a confidentiality agreement. Compliance with these requirements is verified through periodic internal controls. When an employee leaves the company, a formal offboarding process ensures that all access to company systems, both hardware and software, is revoked no later than their final working day, preventing any residual unauthorized access to company or customer data.
Physical security
Access to SCHUHFRIED's premises is controlled and restricted to authorized personnel. Outside of regular business hours, all external doors are secured, and an alarm system activates automatically and is directly monitored by a security service. Within the building, sensitive areas, including the server room and archives, are subject to dedicated access restrictions, permitting entry only to specifically authorized individuals. Physical access credentials, including keys and access chips, form part of the formal offboarding checklist and are reclaimed on an employee's last working day.
For VTS online, the physical infrastructure is operated by Microsoft Azure in the West Europe region (Netherlands). Azure data centers are certified to ISO 27001 and SOC 2 standards and implement multiple layers of physical security, including perimeter controls, 24/7 on-site security personnel, biometric and badge-based access controls, and continuous video surveillance. Physical access to the data floor is restricted to a very limited number of authorized Microsoft personnel and is subject to ongoing audit. SCHUHFRIED has no physical access to this infrastructure, which is an intentional design principle of the shared responsibility model underlying the cloud service.
Tool and software validation
SCHUHFRIED applies a formal, risk-based validation process not only to the VTS product itself, but to all software tools used throughout its lifecycle, including development environments, testing frameworks, and traceability systems. Each tool is assessed against defined risk criteria covering product quality and data integrity, with the required validation depth scaled accordingly. The validity of all tool qualifications is reviewed at least annually as part of the management review, ensuring that the entire toolchain supporting VTS development and delivery remains current and controlled.
Internal controls
To ensure that defined processes are followed and that implemented security measures remain effective, SCHUHFRIED operates a structured program of internal controls. At the start of each fiscal year, the QM department plans which controls will be conducted and in which periods; this plan is approved by the CEO. Controls are conducted using random sampling and must be documented with a traceable audit trail. Results are summarized in a report delivered to the CEO and the relevant team leads, enabling management to identify deviations and initiate corrective action. The control scope covers security-relevant areas including system access rights in Azure and internal file systems, backup execution, training completion, and adherence to development process requirements such as code review and the four-eyes principle for bug fixes.
Data subject rights
As a data processor, SCHUHFRIED processes personal data within VTS online on behalf of its customers, who act as data controllers. Requests from individuals exercising their rights under GDPR Articles 15–20, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection, are therefore handled in coordination with the relevant controller.
Where a customer forwards a data subject request relating to data processed through VTS online, SCHUHFRIED will support the controller in fulfilling its obligations without undue delay. This includes providing structured data exports, correcting or deleting records, and restricting processing as instructed. Individuals seeking to exercise their rights in relation to data processed through VTS online should contact the organization that administered the assessment, which acts as the data controller and is responsible for handling such requests. SCHUHFRIED will not respond directly to queries from individuals but forward all requests to the controller.
Suppliers and contractors
Subprocessors
Where SCHUHFRIED engages third-party service providers who process personal data in the course of delivering services to customers, those providers act as subprocessors under GDPR Article 28. SCHUHFRIED selects subprocessors exclusively on the basis that they provide sufficient guarantees of appropriate technical and organizational measures, and each subprocessor relationship is governed by a data processing agreement imposing data protection obligations equivalent to those applicable to SCHUHFRIED. All subprocessor relationships are documented in SCHUHFRIED's records of processing activities, maintained as required by GDPR Article 30. A current list of subprocessors engaged in the delivery of VTS online is available on our Subprocessors page.
For more information, see Subprocessors.
External employees
Where SCHUHFRIED engages external specialists, including sole traders and freelancers, to support VTS development, these individuals work under the direct authority and instruction of SCHUHFRIED, fully integrated into its development teams. They have no autonomous decision-making power over the purpose or means of any personal data processing; all processing they carry out is exclusively on SCHUHFRIED's documented instructions and within SCHUHFRIED's systems and processes.
Accordingly, SCHUHFRIED classifies these individuals as acting under its direct authority within the meaning of Article 4(10) and Article 29 GDPR and therefore as employee-equivalent, not as subprocessors within the meaning of Article 28 GDPR. This classification is consistent with EDPB Guidelines 07/2020 on the concepts of controller and processor (paragraphs 78 and 87–88), which explicitly recognize that persons in a role highly comparable to that of employees are not to be regarded as processors.
All such individuals are subject to the same confidentiality obligations as SCHUHFRIED's own staff and are contractually bound by data protection requirements. Access to personal data is granted only to the extent strictly necessary for the task at hand and only with a documented justification.
Security assurance
PEN testing
SCHUHFRIED guarantees the ongoing security of the VTS through regular, independent Penetration Tests. These tests are designed to simulate real-world attacks against both the application layer and the supporting infrastructure. We maintain a formal remediation process where critical and high-severity vulnerabilities are addressed as a priority through timely security updates. For transparency and audit purposes, SCHUHFRIED can provide a management summary of the latest penetration test results upon request. This summary outlines the testing scope, the general risk profile, and evidence that identified vulnerabilities have been successfully mitigated.
To ensure the highest level of objectivity and technical rigor, SCHUHFRIED exclusively commissions qualified, independent third-party security firms to conduct our annual penetration tests. These partners are selected based on their proven expertise in web application security and their adherence to international testing methodologies.
Vulnerability management
SCHUHFRIED ensures the security of the developed software and its dependencies through a structured vulnerability management lifecycle. We utilize automated scanning tools to identify known security weaknesses (CVEs) in all third-party libraries. We evaluate the criticality of every identified vulnerability using the Common Vulnerability Scoring System (CVSS). Our reaction and patching strategy prioritize vulnerabilities with a high base score that are confirmed to be reachable and exploitable within the specific architecture of our application.
High-priority security updates and patches are provided within the target timeframes defined in our service level agreement, ensuring that the VTS environment remains resilient against known threats while maintaining the high stability required for psychological testing systems.
For more information, see Service level agreement (SLA) – VTS online.
Data incident management
SCHUHFRIED maintains a formal data breach response process that applies across all activities in which the company acts as either a data controller or a data processor. Every potential breach is documented and assessed for its impact on the rights and freedoms of affected individuals, determining whether notification obligations arise under GDPR Article 33. In the context of VTS online, where SCHUHFRIED acts as a data processor on behalf of its customers, any identified breach is reported to the affected customer without undue delay, enabling customers to meet their own regulatory notification deadlines. All incidents are tracked in a central register, and each case is followed by a post-incident review to evaluate whether additional protective measures are warranted.