Assessed from the outside, documented on the inside
Information Security Assessment (ISA/CVA) · Assessment Level 1, document review
Clients hand us unreleased products, brand assets and personal data of event participants, and their procurement teams ask how we protect it. This page sets out what we have done about that and what we can show you. Last updated: October 2026.
The external assessment
In 2026 RAVE.SPACE GmbH went through an Information Security Assessment conducted by DCSO Deutsche Cyber-Sicherheitsorganisation GmbH in Berlin, as a first assessment at Assessment Level 1. We completed a catalogue of 145 control questions, and an external assessor reviewed our evidence documents against the DCSO ISA criteria. The subject of the assessment was the adequacy of our internal control system for information security. It spans 15 domains: the management system itself, personnel security, asset management, physical and environmental security, access control, operations and responsibilities, cryptography, provided web applications, security in development processes, operational security, network security management, supplier relationships, handling of information security incidents, business continuity management, and compliance and data protection. Results are expressed on a maturity scale from 0 to 5, where 3 means a process is fully documented and implemented. The assessment was completed in September 2026.
Documents on request
The assessment produced a detailed report, a management summary and a one-page scorecard. DCSO classifies these documents as confidential, so we do not publish them. We send them to clients and to companies evaluating us, under a mutual non-disclosure agreement. Write to info@ravespace.io with Security in the subject line and name the entity that should receive them. DCSO assessments are repeated at intervals. Once we have been re-assessed, the new date will appear here.
The management system behind it
The evidence is a maintained set of documents, each with an owner, a version and a review date: information security policy, IT risk register, record of processing activities under the GDPR, onboarding and offboarding, incident response plan, business continuity plan, suppliers and subcontractors, home office and clear desk policy, security awareness training plan, access and identity management, cryptography concept, logging and monitoring, secure development lifecycle, patch and vulnerability management, network and system architecture, backup and restore, and data classification.
How this website runs
The application runs on Google Cloud in a region inside the European Union. Administrative access to the content system is switched off in production: content changes go through a reviewed repository and an automated deployment. The site is served over HTTPS only, with HSTS, a content security policy and a short list of permitted embed origins. Runtime credentials are held in a secret manager, and the deployment account carries only the permissions it needs.