Skip to content
INGER
SK Contact
Vendor onboarding · Procurement

Vendor onboarding kit

For procurement teams vetting Inger s.r.o. as an ICT supplier · Last updated: 1 May 2026

Everything a vendor-onboarding workflow typically asks for, in three forms: a pre-filled human-readable response, a machine-readable JSON for VMS ingest, and an ISMS summary mapped to ISO 27001:2022 Annex A. Bespoke artifacts (signed DPA, TOM, SIG Lite, CAIQ, insurance) on request.

Pre-filled DD Vendor due-diligence response 9 sections · human-readable · ready to attach JSON ingest vendor-dd.json machine-readable · safe to import into VMS ISMS summary ISO 27001:2022 mapping 15 control families · Annex A coverage

1. Legal entity at a glance

  • Legal name: Inger s.r.o.
  • Trade name: INGER technologies
  • Registered seat: Banská Bystrica, Slovakia (EU)
  • IČO: 50178831 · DIČ: 2120217781 · VAT: SK2120217781
  • Founded: 2016 · Markets served: SK, CZ, CH, FR, EU
  • Sales: info@inger.sk · Security: security@inger.sk

2. Live security posture

This site is the reference implementation for the same checks we recommend to clients. Scanned by ZulienScore — an open audit tool we operate — on every release.

81/100 Live ZulienScore scan of inger.sk — 23 April 2026
100 Performance
90 Security
80 SEO
75 Mobile
70 Vulnerability
65 AI readiness
59 GDPR

ZulienScore is calibrated for e-commerce. Several checks that lower our score (Apple Pay, Product Schema, Cookie Consent Banner, Age Verification) do not apply to a B2B engineering site that sells no goods and sets no tracking cookies — we publish the raw number anyway rather than curate it.

View full scan report →  ·  Raw JSON API

3. Regulatory scope (NIS2 · DORA · GDPR)

NIS2 self-scoping: direct scope none (size-cap rule, Art. 2 — Inger is a micro entity); indirect scope yes via Art. 21(2)(d) supply-chain security when serving NIS2-scoped clients. Methodology and binding determination paths are documented at /trust §6.

DORA: not in direct scope (we are not a financial entity), but ICT third-party readiness for financial-sector customers is documented in the vendor DD.

GDPR: we operate as a controller for our own marketing data and as a processor for client engagements under DPA. Privacy policy: /privacy.html.

4. Bespoke artifacts (under NDA)

The following are not published; we send them after a mutual NDA or your standard onboarding cover:

  • Signed Data Processing Agreement (your template or ours)
  • Technical and Organisational Measures statement (TOM, GDPR Art. 32)
  • SIG Lite or CAIQ workbook completion
  • Professional liability insurance certificate
  • Sub-processor list with location and SCC posture
  • Business continuity / disaster recovery summary

Email info@inger.sk with subject "Vendor DD — [company]". Typical turnaround is two business days.

5. Procurement FAQ

Do you carry professional liability insurance?

Yes. Certificate is provided with the bespoke vendor pack on request.

Where is data stored?

EU-only. Hosting at o2switch (France, ISO 27001 certified). Source code at GitHub (US, SCCs applicable). No cross-border transfers outside the standard subprocessor set listed in /vendor-dd.

What is your incident-notification SLA?

24 hours early notice · 72 hours detailed report · 30 days post-mortem with corrective actions. NIS2-aligned. Documented at /trust §4–5.

Exit / data return?

Source code, exports, and credentials are returned in their original formats within 30 days of contract termination, with documented destruction certificates after a 90-day grace.

6. Full posture

For the complete posture (site controls, anti-abuse, GDPR, regulatory mapping, accessibility, subprocessors, own-tooling proof) see /trust.html. The Slovak counterpart is at /sk/dovera.html.

INGER INGER technologies
Home Contact Privacy Trust & security For procurement Vendor DD ISMS SK
© 2026 Inger s.r.o.