Skip to main content

Information security / TISAX

The Hanomag Lohnhärterei Gruppe is aware of the increasing demands for protecting sensitive information and data. To meet the growing security requirements of our customers, particularly in the automotive industry, we have established an Information Security Management System (ISMS) in accordance with TISAX (Trusted Information Security Assessment Exchange).

TISAX is a standard for information security specifically developed for the automotive industry and is monitored by the ENX Association. By successfully achieving TISAX certification, we emphasize our commitment to confidentiality, integrity, and availability of information, ensuring the highest security standards for our customers and partners.

For Hanomag Lohnhärterei Gruppe, the confidentiality, availability, and integrity of information are of utmost importance. We have implemented extensive measures to protect sensitive and confidential information. Therefore, we follow the Information Security Assessment (ISA) questionnaire of the German Association of the Automotive Industry (VDA).

The ENX Association, on behalf of the VDA, supports the mutual acceptance of information security assessments in the automotive industry through TISAX. TISAX assessments are conducted by TISAX-certified audit providers, who regularly demonstrate their qualifications. TISAX and its assessment results are not intended for the general public.

The audit was conducted by a certified provider, in this case, DNV Business Assurance Zertifizierung GmbH. The result is exclusively available via the ENX portal: https://portal.enx.com/en-US/TISAX/

Our Information Security Objectives

  1. Confidentiality: Protecting sensitive customer data and business information from unauthorized access.
  2. Integrity: Ensuring that information is not manipulated or altered without authorization.
  3. Availability: Guaranteeing that information and systems are accessible whenever needed.

For our customers, this means that we are a reliable partner who meets state-of-the-art security standards while complying with legal and industry-specific requirements. Information security is not a project with an end date—it is a continuous process that we regularly review and improve.

Here you can access the participation certificate.