Navigation

Get in touch
Logo
News

Industries / Government

Digital government. Secure by design.

Deliver digital public services, secure identities and sovereign cloud solutions.

Consulting. Integration. Operations.

people inside the building — illustrative image

Built around your industry.

  • Federal authorities and ministries
  • State administrations and municipalities
  • Municipal IT service providers
  • Social insurance agencies and public corporations

Your priorities

Understand the challenge. Shape the solution.

We develop digital administrative services under the OZG, integrate eIDAS-compliant identities and signatures with hardware-protected keys, and design sovereign cloud environments in German data centers.

01

OZG online services and modernization of case management systems

Online service with BundID login and accessibility test report

More on this
02

Sovereign cloud and operation in German data centers

Platform architecture with tenant model and operating concept

More on this
03

Classified information under VS-NfD with approved products

VS-NfD architecture with product selection and conditions of use

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01OZG online services and modernization of case management systemsFIT-Connect · XÖV · FIM

Our approach

The Online Access Act requires that administrative services can be applied for digitally, and since the OZG amendment act the focus is on end-to-end digitization down into the case management system. We develop online services based on the FIM building blocks, connect login through BundID and transfer applications via FIT-Connect as XÖV messages directly into the case management system. We modernize legacy case management systems step by step, interfaces first and individual modules next, each with automated tests and without interrupting casework. Interfaces meet BITV 2.0, and we map changes in the legal basis through versioned rules.

Full scope
  • Online service with FIM service description, FIM data fields and application flow, login through BundID and decision delivered to the mailbox
  • Transfer of applications via FIT-Connect as XÖV messages with connection to the case management system and status feedback
  • Modernization of case management systems in stages with an interface layer, replacement of individual modules and data migration
  • Accessible interfaces under BITV 2.0 and EN 301 549 with test report and accessibility statement
  • Automated tests, versioning and a release process with the department and data protection before every go-live

A district administration connects its online service for business registrations to the case management system via FIT-Connect; applications arrive as structured data instead of being retyped from PDF files.

What you get

  • Online service with BundID login and accessibility test report
  • Interface between FIT-Connect and the case management system with test suite
  • Modernization roadmap for the case management system with stages and acceptance
Discuss this topic
02eIDAS identities, qualified signatures and sealsEntrust nShield 5c · Thales Luna 7 Network HSM · Utimaco CryptoServer CC eIDAS

Our approach

The eIDAS Regulation gives the qualified electronic signature the same legal effect as a handwritten signature and gives authorities the qualified electronic seal to send administrative decisions with proof that they are unaltered. Both are qualified only with a certificate from a qualified trust service provider and a key in a qualified signature creation device, which for server-side services means an HSM certified under EN 419 221-5 and listed as a QSCD. We advise vendor-neutrally on Entrust nShield 5c, Thales Luna 7 and Utimaco CryptoServer with the CC eIDAS package, plan key ceremonies and connect signatures and seals to the e-file system, case management systems and outgoing mail. We integrate login with the online ID function through an eID server under BSI TR-03130 and prepare procedures for the EUDI Wallet under eIDAS 2.0.

Full scope
  • Signature and seal concept with use cases, assurance level, certificates from a qualified trust service provider and roles
  • HSM selection with certification under EN 419 221-5 and QSCD listing, server signing under EN 419 241-2, key ceremonies with records
  • Seal service for administrative decisions in PAdES format with time stamps under RFC 3161, connected to the e-file system and outgoing mail
  • Validation of incoming signatures and seals with validation report and connection to incoming mail and case management systems
  • eID login with the online ID function through an eID server under BSI TR-03130 and a concept for the EUDI Wallet under eIDAS 2.0

A state authority applies a qualified electronic seal to administrative decisions automatically; the seal key is generated in a recorded ceremony inside the HSM and never leaves it.

What you get

  • Signature and seal concept with HSM selection and certificate profiles
  • Seal service in operation with recorded key ceremonies
  • Integration evidence for eID login and signature validation
Discuss this topic
03Sovereign cloud and operation in German data centersKubernetes · OpenStack · Terraform

Our approach

Authorities want to deliver new procedures quickly without giving up control over data, keys and operations. We design platforms on Kubernetes and OpenStack in German data centers, with tenant separation, infrastructure as code and a security concept under IT-Grundschutz that maps the modules of the compendium down to each individual requirement. Where external cloud services are used, we check the provider's C5 attestation against your protection requirements and keep the keys in your HSM with Bring Your Own Key or Hold Your Own Key. Backup, recovery and exit scenario are documented and tested before a procedure goes live.

Full scope
  • Platform architecture with Kubernetes and OpenStack in German data centers, tenant separation and infrastructure as code with Terraform
  • Security concept under BSI Standard 200-2 with structure analysis, protection requirements assessment, modeling and IT-Grundschutz check
  • Assessment of external cloud services against BSI C5 and the BSI minimum standard for the use of external cloud services
  • Key management with Bring Your Own Key or Hold Your Own Key through HSMs and Thales CipherTrust Manager
  • Backup with Veeam, recovery tests under BSI Standard 200-4 and a documented exit scenario per service

A municipal IT service provider moves the online services of several municipalities to a multi-tenant Kubernetes platform in its own data center; security concept and IT-Grundschutz check are complete before the first go-live.

What you get

  • Platform architecture with tenant model and operating concept
  • Security concept under IT-Grundschutz with IT-Grundschutz check
  • Tested recovery and exit concept
Discuss this topic
04Assistants and document classification for caseworkvLLM · OpenSearch · Apache Tika

Our approach

Incoming mail, file research and drafts take up much of the time in casework, and public AI services are ruled out for files with personal data. We operate open-weight language models on GPU servers in your data center or a German one, assign incoming documents to file plan and case type and build assistants that answer exclusively from approved files and regulations and cite every source. The decision stays with the caseworker, in line with Article 22 GDPR. We prepare the classification under the EU AI Act, the data protection impact assessment and the involvement of the staff council from the start.

Full scope
  • Selection and operation of open-weight language models on GPU servers with vLLM, without data flowing to external services
  • Document classification for incoming mail by file plan, case type and deadlines with text recognition for scanned letters
  • Assistant with retrieval augmented generation over approved files and regulations, source citations and permissions from the e-file system
  • Evaluation of answer quality with test cases from the department, logging and model operations with versioning
  • Classification under the EU AI Act, data protection impact assessment under Article 35 GDPR and documents for the staff council

A regional government authority assigns incoming letters to the file number automatically; the caseworker receives a draft with source citations from the file and decides personally.

What you get

  • Language model platform in your own or a German data center
  • Classification model and assistant with test report and model card
  • Documents on EU AI Act, impact assessment and staff council involvement
Discuss this topic
05Classified information under VS-NfD with approved productsUtimaco LAN Crypt · Utimaco DiskEncrypt · Utimaco CryptoServer

Our approach

Anyone who stores or transmits classified information at the level VS-NUR FÜR DEN DIENSTGEBRAUCH needs encryption products approved by the BSI under the classified information directive, operated according to their conditions of use and operation. We design the architecture with approved products such as Utimaco LAN Crypt for files and folders, Utimaco DiskEncrypt for storage media and Utimaco CryptoServer with the VS-NfD package for keys, and implement their conditions in configuration and operating processes. The approval belongs to the product; OTOKO® integrates and operates it and documents the configuration states for the classified information security officers. OPSWAT MetaDefender Kiosk scans removable media before files enter the network.

Full scope
  • Inventory of classified information by storage location, transmission path and parties involved, checked against the classified information directive
  • Architecture with BSI-approved products and implementation of their conditions of use and operation in configuration and operations manual
  • Rollout of Utimaco LAN Crypt and Utimaco DiskEncrypt with smartcards and role separation between administration and security officers
  • Key management with Utimaco CryptoServer and succession planning for installed devices whose vendor support is ending
  • Media gateway for removable media with OPSWAT MetaDefender Kiosk and logging for reviews by classified information security officers

A higher federal authority encrypts file shares for VS-NfD documents with LAN Crypt; the classified information security officers receive approval documents, policies and configuration states in one audit file.

What you get

  • VS-NfD architecture with product selection and conditions of use
  • Encryption rolled out on file shares, endpoints and storage media
  • Audit file with approval documents, policies and configuration states
Discuss this topic
06Post-quantum roadmap for long-lived records and registersML-KEM (FIPS 203) · ML-DSA (FIPS 204) · SLH-DSA (FIPS 205)

Our approach

Records, registers and certificates of civil status often have to remain confidential and legally valid for decades, and encrypted data intercepted today can be decrypted later with capable quantum computers. We inventory encryption, signatures and certificates in the e-file system, registers, portals and PKI, rate each use by retention period and protection requirement and plan the migration to ML-KEM and ML-DSA in hybrid schemes, as BSI TR-02102 recommends. For signed documents in the long-term archive, preservation of evidential value under BSI TR-03125 with renewed archive time stamps keeps their legal validity across the change of algorithms. We review HSMs and PKI software for firmware with the new algorithms before procurement is due.

Full scope
  • Crypto inventory across e-file system, registers, portals, VPN, PKI and signature services with rating by retention period
  • Prioritization by the risk that intercepted data is decrypted later and by the lifetime of the systems
  • Hybrid schemes with ML-KEM and ML-DSA in line with BSI TR-02102 for TLS, VPN and internal PKI
  • Preservation of evidential value for signed documents under BSI TR-03125 with archive time stamps and planning of algorithm changes
  • Requirements for HSMs, PKI software and case management systems in tenders, so that new procurements bring crypto agility

A state office with an electronic register inventories the cryptography in portal, PKI and archive; the internal PKI moves to hybrid certificates first, and the archive receives renewed time stamps under TR-ESOR.

What you get

  • Crypto inventory with rating by retention period
  • Migration roadmap for PKI, signature services and archive
  • Crypto agility requirements catalog for future tenders
Discuss this topic
white concrete building during daytime — illustrative image
Government

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Government

End-to-end application at a district administration

Online service live, applications arrive as PDF files in the mailbox and are retyped into the case management system, follow-up questions go out by letter.

Solution

Interface via FIT-Connect with XÖV messages, connection to the case management system, status feedback and decision delivered to the BundID mailbox.

Applications as structured data in the case management system, processing status visible to applicants, tested interface with release process.

Discuss this topic

02 / Government

Qualified seal at a state authority

Decisions are printed and signed by hand, a seal certificate sits as a software file on the server, internal audit objects to the key storage.

Solution

Seal concept, HSM with QSCD listing, recorded key ceremony, seal service in PAdES format connected to the e-file system and outgoing mail.

Qualified sealed decisions in outgoing mail, keys exclusively in the HSM, operations manual and ceremony records for internal audit.

Discuss this topic

03 / Government

On-premises assistant at a higher federal authority

Employees use public AI services for drafts, data protection officers and the staff council demand an approved in-house alternative.

Solution

Open-weight language model in the authority's own data center, assistant over approved files with source citations, impact assessment and documents for the staff council agreement.

Approved tool without data leaving the house, drafts with sources, classification under the EU AI Act and documents for the staff council.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Administrative services, case management systems, protection requirements and obligations under OZG, eIDAS and IT-Grundschutz

    Procedure inventory, crypto inventory, gap analysis, initiatives prioritized by benefit and risk
  2. 02

    Concept

    Target architecture, security concept, operating model

    Target architecture, security concept under IT-Grundschutz, HSM and signature concept, operating model, data protection documents
  3. 03

    Implementation

    Online services, platform, signature services and assistants in stages

    Tested services, recorded ceremonies, documentation, acceptance with department and data protection per stage
  4. 04

    Operations

    Monitoring, certificates, audits, knowledge transfer

    Daily operations under IT-Grundschutz, certificate renewal, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for government?

Six fields of action from OZG online services to a post-quantum roadmap for records that must stay confidential for decades. OTOKO® plans, builds and operates them under IT-Grundschutz and evidences every measure to data protection, classified information security and internal audit. The entire solution runs in German data centers.

IT solutions for government make administrative services digitally accessible, connect them to the case management systems of the departments and protect citizen data, classified information and signature keys under the requirements of the BSI and the GDPR. OTOKO® covers six fields of action: OZG online services and modernization of case management systems, eIDAS identities with qualified signatures and seals, sovereign cloud in German data centers, assistants and document classification with on-premises language models, classified information under VS-NfD, and a post-quantum roadmap for long-lived records and registers.

The difference from a pure consulting project lies in operations and evidence. Every online service, every seal key and every model comes with a security concept, a version state and the records that data protection officers, classified information security officers and internal audit require. The entire solution runs in German data centers. Keys for seals and classified information stay in hardware security modules under your control.

Why OTOKO® for government

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. We plan and operate seal keys, eID integration and encryption for classified information with certified devices and approved products.

  • German data centers

    The entire solution runs in German data centers. Online services, language models and keys stay under German jurisdiction and your control.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. The requirements of the BSI, data protection authorities and classified information security are part of our everyday project work.

  • One team through to operations

    One team accompanies you from consulting to operations. Software developers, cryptography specialists and AI engineers stay on board into daily operations without handover to third parties.

Delivery and details

Most authorities do not fail for lack of will to digitize but on legacy case management systems, missing control over keys and unclear rules for new tools.

Online service without connection

Applications arrive digitally but are printed or retyped because the case management system offers no interface for structured data.

Signature keys in software

Seal and signature keys sit as files on servers, certificates expire unnoticed and nobody checks incoming signatures systematically.

Cloud without key control

New procedures are built on provider platforms, the provider manages the keys itself and nobody has mapped the setup to C5 and IT-Grundschutz.

AI use without rules

Employees paste extracts from case files into public AI services because no approved tool exists, and data protection and the staff council find out last.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour government data center or that of your IT service providerData centers in Germany, operated under ISO 27001 and IT-GrundschutzAzure, AWS or Google Cloud, region Germany, unclassified data only
OperationYour team or OTOKO® as managed serviceOTOKO®, access under the four-eyes principle and loggedShared, platform services by the provider
ToolsCase management systems, HSMs, LAN Crypt, language models on your own GPU serversKubernetes platform, hosted HSMs, language models in a German data centerManaged platform services, cloud HSM, keys through Hold Your Own Key
Suited forClassified information, registers, seal keysOnline services and assistants with a need for sovereigntyInformation portals, peak loads at application deadlines, development and test
ComplianceFull control, evidence from your ISMS under IT-GrundschutzProcessing agreement under GDPR, IT-Grundschutz evidence, location GermanyProcessing agreement, provider's C5 attestation, no classified information

Collaboration

Project

Clearly scoped initiative such as an OZG online service, a seal service in the HSM or a security concept under IT-Grundschutz, with a statement of work, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Contract under EVB-IT, fixed price or effort by milestone
  • Suited for online services, signature services and IT-Grundschutz projects

Team reinforcement

Software developers, cryptography specialists or AI engineers work in your teams and tools, following your approval processes and classified information rules.

  • Onboarding into case management systems, committees and approval paths
  • Scalable as the project progresses
  • Suited for authorities and IT service providers with capacity gaps

Managed service

OTOKO® operates platform, seal service, language models or encryption with agreed service levels, regular reports and operation under IT-Grundschutz in German data centers.

  • Monitoring, certificate renewal, updates and support
  • Processing agreement under GDPR and exit scenario in the contract
  • Suited for authorities without their own operations team for HSMs or platforms

Five regulations against which government IT must be measured, with their requirements and what OTOKO® delivers for them.

Standards and evidence
RequirementDemandsOTOKO® delivers
OZGDigital access to administrative services through the portal network, user account with BundID, end-to-end digitization under the OZG amendment act, accessible servicesOnline services based on FIM, BundID integration, transfer via FIT-Connect with XÖV messages, connection of case management systems, test report under BITV 2.0
eIDASQualified signatures and seals with qualified certificates and QSCD, recognition of notified eID means, acceptance of the EUDI Wallet under eIDAS 2.0HSM selection under EN 419 221-5 with QSCD listing, seal and signature services, signature validation, eID integration under BSI TR-03130, wallet concept
BSI IT-GrundschutzInformation security management under BSI Standards 200-1 to 200-3, protection requirements assessment, modeling with the compendium, business continuity management under BSI Standard 200-4Structure analysis, protection requirements assessment, modeling and IT-Grundschutz check, security concept per procedure, emergency and recovery concept
GDPRLegal basis, data protection by design, data protection impact assessment, processing agreements, limits on automated individual decisions under Article 22Data protection concept per procedure, contribution to the impact assessment, deletion concept based on retention periods, processing agreement with location Germany
NIS2Risk management measures, staged reporting obligations and management accountability for entities of the federal administration and for IT service providers within the directive's scopeApplicability check, gap analysis of the measures, reporting process with deadlines and exercises, cryptography and access concept

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for government does OTOKO® offer?

OTOKO® develops OZG online services and modernizes case management systems, integrates qualified signatures and seals with HSMs, builds sovereign platforms in German data centers and operates assistants with on-premises language models. It also delivers encryption for classified information under VS-NfD with approved products and a post-quantum roadmap for long-lived records. Each field of action can be commissioned on its own or as a package.

May government data be processed in the cloud?

Yes, if protection requirements, storage location and key control fit. For unclassified data with normal protection requirements, cloud services with a C5 attestation are an option, provided processing agreement and location are settled. Classified information and registers with high protection requirements usually stay in your own or a German data center. We document the decision in the security concept under IT-Grundschutz and keep the keys in your HSM.

How are existing case management systems connected to OZG online services?

Through an interface that receives applications from FIT-Connect as XÖV messages and writes them into the case management system, instead of redeveloping the system. The business logic is preserved, individual modules are replaced step by step later, and each stage runs with tests and acceptance by the department. One team accompanies you from consulting to operations, also when legislative changes require new data fields.

Does OTOKO® need its own approval for classified information under VS-NfD?

The BSI grants VS-NfD approvals for IT security products, not for service providers. We use products approved for this purpose, such as Utimaco LAN Crypt, Utimaco DiskEncrypt and Utimaco CryptoServer with the VS-NfD package, and comply with their conditions of use and operation in configuration and operations. Your classified information security officers receive the documentation in one audit file.

Can language models be used in casework in compliance with data protection law?

Yes, if model, data and logs stay in your own or a German data center and the decision remains with the caseworker. We operate open-weight models without training them on file contents, take over permissions from the e-file system and log every request. Classification under the EU AI Act, the data protection impact assessment and documents for the staff council are completed before the pilot.

Why should authorities think about post-quantum cryptography today?

Because records and registers must stay confidential longer than classical encryption is expected to hold, and intercepted data can be decrypted later. Procurement cycles for HSMs, PKI and case management systems also take years. An inventory rated by retention periods shows which connections, certificates and archives migrate first, and new tenders demand crypto agility from the start.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: IT-Grundschutz, protection requirements, VS-NfD architecture. Cryptography specialist: HSMs, signatures and seals, PQC roadmap. Software developer: Online services, FIT-Connect, case management system modernization. Cloud architect: Platform, tenant separation, recovery. AI engineer: Language models, document classification, model operations. Project lead: Milestones, committees, acceptance, reports.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Administrative services, case management systems, protection requirements and obligations under OZG, eIDAS and IT-Grundschutz Procedure inventory, crypto inventory, gap analysis, initiatives prioritized by benefit and risk

Operations & development4 questions

How can we work together?

Project: Clearly scoped initiative such as an OZG online service, a seal service in the HSM or a security concept under IT-Grundschutz, with a statement of work, milestones and acceptance. Team reinforcement: Software developers, cryptography specialists or AI engineers work in your teams and tools, following your approval processes and classified information rules. Managed service: OTOKO® operates platform, seal service, language models or encryption with agreed service levels, regular reports and operation under IT-Grundschutz in German data centers.

What happens at handover to operations?

Monitoring, certificates, audits, knowledge transfer Daily operations under IT-Grundschutz, certificate renewal, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Government

Let's discuss your next step.

Let us work out together how your authority can digitize administrative services securely while keeping control of its data.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.