About the author

Maori profile picture
Maori Kunigo
hsp Software

Maori Kunigo is responsible for communications and brand management at hsp Handels-Software-Partner GmbH in Hamburg. A qualified media designer, he brings 18 years’ experience from both small and large advertising agencies, where he worked primarily as a copywriter and, most recently, as a creative director. Outside his creative work, he takes a keen interest in future technologies, New Work and People Management.

Identifying secure cloud software: What businesses and law firms really need to look out for

What you can expect from this article

Cloud software is convenient, flexible and ready to use straight away. That is why, when it comes to sensitive data, many prospective users immediately ask the crucial question: how secure is the whole thing really? This is all the more true when it is not just ordinary project data that is being processed, but highly confidential information such as login details, powers of attorney, contracts, living wills or estate plans.

The example of hsp Software’s digital end-of-life file illustrates what is essential for a cloud solution that complies with data protection regulations. Key considerations include the choice of data centre, backup and disaster recovery measures, multi-layer encryption, and the careful use of third-party providers such as DeepL or OpenAI. In conversation with Hendrik Sievers, an IT law solicitor and hsp’s data protection officer from the law firm beck rechtsanwälte, we discussed the security of cloud services and possible measures.

An image showing a microphone and the caption: "Podcast episode for this article: click here to listen!"

Why cloud security is so important, particularly when it comes to sensitive data

The new pension scheme is a cloud-only solution. This means that both the application and the data are hosted entirely in the cloud. This offers significant advantages for users. They do not need to carry out any local installation, undertake any time-consuming system maintenance, or have any special infrastructure other than a browser and internet access.

At the same time, however, the requirements regarding data protection and data security are increasing. This is because a pension file contains not only organisational information, but in many cases also data that is particularly sensitive. This includes, for example:

  • important login details and passwords,
  • current contracts and powers of attorney,
  • business-relevant proprietary knowledge
  • and private documents such as living wills or estate plans.

If such data falls into the wrong hands, there is a risk of serious damage. That is why it is not enough for a cloud solution to be „modern“ or „easy to use“. It must be properly structured, both technically and organisationally.

The myth of local servers: Is data automatically more secure when hosted in-house?

Many companies and law firms still assume that data stored on their own servers is, by its very nature, more secure than data in the cloud. This assumption often does not stand up to objective scrutiny. This is because a professionally operated data centre is generally much better secured than a traditional in-house server room.

What matters is not whether data is stored in the cloud, but where and under what conditions. That is why hsp has chosen a German provider with server locations in Germany for its solution. Equally important: the servers do not belong to a global hyperscaler such as Amazon or Microsoft, but to a German operator. The operator’s terms and conditions were thoroughly reviewed in advance by the data protection officer.

In addition, there are recognised security standards and certifications, such as those relating to ISO 27001. Such requirements are particularly relevant for professionals bound by professional secrecy, such as tax advisers, auditors, solicitors and notaries. For businesses, this means that anyone wishing to assess the security of a cloud solution should ask specific questions about the provider, the hosting location, certifications and technical security measures.

Backup and disaster recovery: What happens in an emergency?

One aspect of secure cloud software that is often underestimated is the backup strategy. After all, security is not just about protection against unauthorised access, but also about ensuring availability in an emergency. Good cloud solutions must therefore provide answers to two questions:

  • How often are backups carried out?
  • How quickly can operations be restored following a failure?

Ideally, backups are created continuously, archived and retained over extended periods. This enables companies to revert to previous states if necessary. Furthermore, the data is not only backed up at the primary data centre, but is also stored in a second fire compartment or in a separate backup area. This is precisely how the provider selected by hsp for its cloud operates.

The benefit for customers is that even if the primary data centre were to fail at short notice, the cloud platform would be up and running again in no time. For professional users, this is a key quality feature.

Double encryption: Why a single layer of protection is not enough

When it comes to highly sensitive data, simple encryption is often not enough. That is why the provider uses a dual-encryption system for the hsp. This also applies to the digital end-of-life plan. Even in the event of a data breach, the thieves would be unable to make any use of the data, as it contains nothing but gibberish.

Put simply:

  • There is a user’s personal key, i.e. the password.
  • This key is stored in encrypted form using a further key.

It is only the interaction of both components that enables access. Furthermore, certain particularly sensitive fields, such as stored passwords, are not stored in plain text. They are already protected at field level, whilst the entire database is also encrypted.

This is where the security architecture demonstrates just how resilient it is. It must be highly secure, whilst remaining practical for everyday use. Too many hurdles render an application unusable. Too little protection makes it risky. A good solution strikes the right balance.

The downside of high security: what happens if you lose your master password?

Greater security often means greater personal responsibility. In the case of the pension file, this means, in practical terms, that if you lose your master password or personal key, not even the provider will be able to access the stored content.

This is not a shortcoming, but a direct consequence of the security concept. After all, if the provider were able to reconstruct the key, they could, in theory, access your data themselves at any time. And you certainly wouldn’t want that. BThis is a familiar trade-off when it comes to popular digital password vaults or contingency planning systems. The benefits in terms of data protection and data security are considerable, but the responsibility that comes with centralised access must not be underestimated.

DeepL and OpenAI: Use third-party providers only in a considered and controlled manner

Another important point is the use of external tools, such as translation services or AI applications. Transparency is crucial here. In the platform described, such services are not permanently and automatically integrated. Instead, users must set up their own account with DeepL or OpenAI and enter the relevant API key into the software.

This has several advantages:

  • The user makes a conscious and active decision to use it.
  • There is complete control over which service is used at all.
  • Changes relating to providers or data protection assessments can be accommodated flexibly.

This flexibility is particularly valuable when it comes to data protection. Provider structures change. Server locations may change. Legal assessments may also change as a result of new developments or court rulings. As long as you work with interchangeable interfaces, you can respond flexibly to changes at any time.

What you need to bear in mind regarding data protection when using DeepL

With DeepL, the situation is relatively straightforward. The company is based in Germany, its servers are located in the EU, and you can configure its use to suit your needs. Users can decide for themselves whether and how DeepL is used within the software, and which languages are employed.

Another important question is whether data is used to train the service on offer. According to the classification described, this is generally not the case with DeepL. The glossary function is an exception. Here, the user specifically defines their own terms and desired translations. The output is customised solely on this basis. Users who do not use this function do not train DeepL with their own data. From a data protection perspective, this is a transparent and easily controllable approach.

What makes OpenAI different

With AI services such as OpenAI, the situation is more complex. By default, data processing may also take place outside the EU. Anyone working with OpenAI must therefore pay particularly close attention to the project structure, contractual arrangements and hosting options.

Under the model described, users create their own project within their OpenAI account and generate the API keys there. Under certain conditions and subject to a separate agreement, hosting within the EU may be arranged. Without such a supplementary agreement, this regionality is not automatically guaranteed.

At the same time, technical measures have been put in place to ensure that the data transmitted to the AI is handled appropriately. With regard to the API endpoints used, the content transmitted is not used for training purposes. However, in some cases, it may remain on the servers for a limited period for monitoring purposes.

This is precisely why hsp has implemented a deletion mechanism in its software: as soon as an AI chat is closed within the software, a deletion command is sent to OpenAI at the same time. This ensures that the content is removed. In addition, there is to be a feature that allows users to deliberately choose to retain certain data for recurring projects within their own OpenAI project – such as templates or guidelines that are needed on multiple occasions.

The key point, therefore, is not a blanket statement such as „AI complies with data protection regulations“ or „AI breaches data protection regulations“, but rather precise control:

  • What data is transmitted?
  • Who decides on this?
  • Is the content used for training?
  • How long are they stored for?
  • Can a deletion be triggered manually?

Digital sovereignty rather than the blind use of tools

A common thread running through the whole topic is digital sovereignty. Companies and law firms need to know which tools they are using, what happens to their data and what risks are involved. With US providers in particular, there is often a residual risk that cannot be dismissed.

It therefore makes sense to design systems in such a way that you can respond quickly to legal or technical changes. If a provider changes its infrastructure or new legal requirements come into force, companies should not find themselves at a dead end. Flexible interfaces and ongoing legal support are a major advantage in this regard.

How to recognise secure cloud software

If you are interested in a cloud solution, you should look beyond the catchy advertising claims. Before signing a contract, you should consider the following questions:

  • Where are the servers located, and who runs the data centre?
  • What certifications and safety standards are in place?
  • What are the procedures for backups, archiving and disaster recovery?
  • Are the database and sensitive individual data items encrypted?
  • Can the provider access customer data, or not at the moment?
  • How are third-party providers, such as translation or AI services, integrated?
  • Is data used for training or not?
  • What options do users themselves have for deletion and control?

Privacy Policy

In conversation: Hendrik Sievers
How secure are cloud services?

On our programme „hsp live at 11“, hsp’s Managing Director Paul Liese and our Data Protection Officer Hendrik Sievers, a lawyer specialising in IT law, discussed cloud security and possible measures.

For privacy reasons YouTube needs your permission to be loaded. For more details, please see our Datenschutz.

Conclusion: Good cloud security is not a promise, but a concept

The key takeaway is this: secure cloud software is not recognised by bold marketing claims, but by specific technical and organisational measures. A German data centre operating in accordance with the GDPR and EU law, robust backups, clear contingency plans, dual encryption and a controlled approach to third-party providers are key components of this.

It is equally important to be honest about the limits of what is feasible. There is no such thing as absolute security. However, there are solutions that significantly reduce risks whilst remaining practical to use. This is precisely what matters in a professional context.

For law firms and businesses that process particularly sensitive information, the following therefore applies: it is not the cloud itself that is the problem. What matters is how it has been built. Those who ask the right questions here and insist on transparent answers lay the foundations for data protection, data security and digital trust.

More on this topic Pension scheme

Related posts
  • Blog post cover image: Why every family needs an estate planning file
    Why every family needs an estate planning file

    In everyday life, a lot of things just work. Bills get paid, insurance policies run in the background, and important documents are tucked away somewhere in folders, drawers or digital storage. You have a rough idea of where things are. And if not, you’ll find them one way or another. However, it is precisely this „one way or another“ that is the problem. Because as long as nothing goes wrong, it’s hard to notice just how unstructured much of our information actually is.

  • Blog post featured image: Why entrepreneurs need a contingency plan
    Why the pension plan is essential for business owners

    At first glance, estate planning is a subject that many clients are keen to put off. It is often associated with emergencies – such as illness, accident or death – in other words, precisely the issues that hardly anyone wants to deal with in their day-to-day lives. Yet it is precisely this emotional distance that makes the estate planning file such a valuable tool for tax practice firms.

  • Blog post cover image: Cloud security with Hendrik Sievers
    Identifying secure cloud software: What businesses and law firms really need to look out for

    Cloud software is convenient, flexible and quick to set up. This is precisely why, when it comes to sensitive data, the crucial question immediately arises: just how secure is the whole system really? This is all the more true when it is not just ordinary project data that is being processed, but highly confidential information such as login details, powers of attorney, contracts, living wills or probate arrangements.