Everything a vendor-onboarding workflow typically asks for, in three forms: a pre-filled human-readable response, a machine-readable JSON for VMS ingest, and an ISMS summary mapped to ISO 27001:2022 Annex A. Bespoke artifacts (signed DPA, TOM, SIG Lite, CAIQ, insurance) on request.
1. Legal entity at a glance
- Legal name: Inger s.r.o.
- Trade name: INGER technologies
- Registered seat: Banská Bystrica, Slovakia (EU)
- IČO: 50178831 · DIČ: 2120217781 · VAT: SK2120217781
- Founded: 2016 · Markets served: SK, CZ, CH, FR, EU
- Sales: info@inger.sk · Security: security@inger.sk
2. Live security posture
This site is the reference implementation for the same checks we recommend to clients. Scanned by ZulienScore — an open audit tool we operate — on every release.
ZulienScore is calibrated for e-commerce. Several checks that lower our score (Apple Pay, Product Schema, Cookie Consent Banner, Age Verification) do not apply to a B2B engineering site that sells no goods and sets no tracking cookies — we publish the raw number anyway rather than curate it.
3. Regulatory scope (NIS2 · DORA · GDPR)
NIS2 self-scoping: direct scope none (size-cap rule, Art. 2 — Inger is a micro entity); indirect scope yes via Art. 21(2)(d) supply-chain security when serving NIS2-scoped clients. Methodology and binding determination paths are documented at /trust §6.
DORA: not in direct scope (we are not a financial entity), but ICT third-party readiness for financial-sector customers is documented in the vendor DD.
GDPR: we operate as a controller for our own marketing data and as a processor for client engagements under DPA. Privacy policy: /privacy.html.
4. Bespoke artifacts (under NDA)
The following are not published; we send them after a mutual NDA or your standard onboarding cover:
- Signed Data Processing Agreement (your template or ours)
- Technical and Organisational Measures statement (TOM, GDPR Art. 32)
- SIG Lite or CAIQ workbook completion
- Professional liability insurance certificate
- Sub-processor list with location and SCC posture
- Business continuity / disaster recovery summary
Email info@inger.sk with subject "Vendor DD — [company]". Typical turnaround is two business days.
5. Procurement FAQ
Do you carry professional liability insurance?
Yes. Certificate is provided with the bespoke vendor pack on request.
Where is data stored?
EU-only. Hosting at o2switch (France, ISO 27001 certified). Source code at GitHub (US, SCCs applicable). No cross-border transfers outside the standard subprocessor set listed in /vendor-dd.
What is your incident-notification SLA?
24 hours early notice · 72 hours detailed report · 30 days post-mortem with corrective actions. NIS2-aligned. Documented at /trust §4–5.
Exit / data return?
Source code, exports, and credentials are returned in their original formats within 30 days of contract termination, with documented destruction certificates after a 90-day grace.
6. Full posture
For the complete posture (site controls, anti-abuse, GDPR, regulatory mapping, accessibility, subprocessors, own-tooling proof) see /trust.html. The Slovak counterpart is at /sk/dovera.html.