What we will not do, and why it matters here
In security, a publication that blurs the line between explaining and assessing does actual harm. So the line is drawn plainly.
We do not touch systems
ELO Digital Office GmbH does not scan, test, audit or monitor websites, does not sell or operate security software, and takes on no client work. Nobody here has access to any reader's system and nobody is asking for it.
We cannot help with an incident
This is the most important sentence on the site. If a system has been compromised, contact whoever hosts or maintains it immediately. If personal data may have been exposed, there are notification duties with short deadlines and you need qualified advice today, not a general text.
Please do not send us details of an incident. We cannot act on them, we are not equipped to hold them, and the time spent writing to us is time not spent on the call that matters.
What we do not do
- No scanning, testing or auditing of any system.
- No incident response, forensics or remediation.
- No software: we build nothing, sell nothing and operate nothing.
- No certification or attestation of any kind.
- No vendor recommendations, and no payment from any vendor.
Why no numbers
Scan intervals, severity thresholds and retention periods depend on what a system does, how often it changes and what it holds. A figure printed here would be applied to systems it does not fit, and in security that produces either wasted effort or false confidence.
How this is funded
The site is published and paid for by ELO Digital Office GmbH. There is no advertising, no sponsorship and no affiliate links. No security vendor has contributed to or paid for this material.
