OZG online services and modernization of case management systems
Online service with BundID login and accessibility test report
More on thisIndustries / Government
Deliver digital public services, secure identities and sovereign cloud solutions.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We develop digital administrative services under the OZG, integrate eIDAS-compliant identities and signatures with hardware-protected keys, and design sovereign cloud environments in German data centers.
Online service with BundID login and accessibility test report
More on thisPlatform architecture with tenant model and operating concept
More on thisVS-NfD architecture with product selection and conditions of use
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
The Online Access Act requires that administrative services can be applied for digitally, and since the OZG amendment act the focus is on end-to-end digitization down into the case management system. We develop online services based on the FIM building blocks, connect login through BundID and transfer applications via FIT-Connect as XÖV messages directly into the case management system. We modernize legacy case management systems step by step, interfaces first and individual modules next, each with automated tests and without interrupting casework. Interfaces meet BITV 2.0, and we map changes in the legal basis through versioned rules.
A district administration connects its online service for business registrations to the case management system via FIT-Connect; applications arrive as structured data instead of being retyped from PDF files.
Our approach
The eIDAS Regulation gives the qualified electronic signature the same legal effect as a handwritten signature and gives authorities the qualified electronic seal to send administrative decisions with proof that they are unaltered. Both are qualified only with a certificate from a qualified trust service provider and a key in a qualified signature creation device, which for server-side services means an HSM certified under EN 419 221-5 and listed as a QSCD. We advise vendor-neutrally on Entrust nShield 5c, Thales Luna 7 and Utimaco CryptoServer with the CC eIDAS package, plan key ceremonies and connect signatures and seals to the e-file system, case management systems and outgoing mail. We integrate login with the online ID function through an eID server under BSI TR-03130 and prepare procedures for the EUDI Wallet under eIDAS 2.0.
A state authority applies a qualified electronic seal to administrative decisions automatically; the seal key is generated in a recorded ceremony inside the HSM and never leaves it.
Our approach
Authorities want to deliver new procedures quickly without giving up control over data, keys and operations. We design platforms on Kubernetes and OpenStack in German data centers, with tenant separation, infrastructure as code and a security concept under IT-Grundschutz that maps the modules of the compendium down to each individual requirement. Where external cloud services are used, we check the provider's C5 attestation against your protection requirements and keep the keys in your HSM with Bring Your Own Key or Hold Your Own Key. Backup, recovery and exit scenario are documented and tested before a procedure goes live.
A municipal IT service provider moves the online services of several municipalities to a multi-tenant Kubernetes platform in its own data center; security concept and IT-Grundschutz check are complete before the first go-live.
Our approach
Incoming mail, file research and drafts take up much of the time in casework, and public AI services are ruled out for files with personal data. We operate open-weight language models on GPU servers in your data center or a German one, assign incoming documents to file plan and case type and build assistants that answer exclusively from approved files and regulations and cite every source. The decision stays with the caseworker, in line with Article 22 GDPR. We prepare the classification under the EU AI Act, the data protection impact assessment and the involvement of the staff council from the start.
A regional government authority assigns incoming letters to the file number automatically; the caseworker receives a draft with source citations from the file and decides personally.
Our approach
Anyone who stores or transmits classified information at the level VS-NUR FÜR DEN DIENSTGEBRAUCH needs encryption products approved by the BSI under the classified information directive, operated according to their conditions of use and operation. We design the architecture with approved products such as Utimaco LAN Crypt for files and folders, Utimaco DiskEncrypt for storage media and Utimaco CryptoServer with the VS-NfD package for keys, and implement their conditions in configuration and operating processes. The approval belongs to the product; OTOKO® integrates and operates it and documents the configuration states for the classified information security officers. OPSWAT MetaDefender Kiosk scans removable media before files enter the network.
A higher federal authority encrypts file shares for VS-NfD documents with LAN Crypt; the classified information security officers receive approval documents, policies and configuration states in one audit file.
Our approach
Records, registers and certificates of civil status often have to remain confidential and legally valid for decades, and encrypted data intercepted today can be decrypted later with capable quantum computers. We inventory encryption, signatures and certificates in the e-file system, registers, portals and PKI, rate each use by retention period and protection requirement and plan the migration to ML-KEM and ML-DSA in hybrid schemes, as BSI TR-02102 recommends. For signed documents in the long-term archive, preservation of evidential value under BSI TR-03125 with renewed archive time stamps keeps their legal validity across the change of algorithms. We review HSMs and PKI software for firmware with the new algorithms before procurement is due.
A state office with an electronic register inventories the cryptography in portal, PKI and archive; the internal PKI moves to hybrid certificates first, and the archive receives renewed time stamps under TR-ESOR.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Government
Online service live, applications arrive as PDF files in the mailbox and are retyped into the case management system, follow-up questions go out by letter.
Interface via FIT-Connect with XÖV messages, connection to the case management system, status feedback and decision delivered to the BundID mailbox.
Applications as structured data in the case management system, processing status visible to applicants, tested interface with release process.
02 / Government
Decisions are printed and signed by hand, a seal certificate sits as a software file on the server, internal audit objects to the key storage.
Seal concept, HSM with QSCD listing, recorded key ceremony, seal service in PAdES format connected to the e-file system and outgoing mail.
Qualified sealed decisions in outgoing mail, keys exclusively in the HSM, operations manual and ceremony records for internal audit.
03 / Government
Employees use public AI services for drafts, data protection officers and the staff council demand an approved in-house alternative.
Open-weight language model in the authority's own data center, assistant over approved files with source citations, impact assessment and documents for the staff council agreement.
Approved tool without data leaving the house, drafts with sources, classification under the EU AI Act and documents for the staff council.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Administrative services, case management systems, protection requirements and obligations under OZG, eIDAS and IT-Grundschutz
Target architecture, security concept, operating model
Online services, platform, signature services and assistants in stages
Monitoring, certificates, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from OZG online services to a post-quantum roadmap for records that must stay confidential for decades. OTOKO® plans, builds and operates them under IT-Grundschutz and evidences every measure to data protection, classified information security and internal audit. The entire solution runs in German data centers.
IT solutions for government make administrative services digitally accessible, connect them to the case management systems of the departments and protect citizen data, classified information and signature keys under the requirements of the BSI and the GDPR. OTOKO® covers six fields of action: OZG online services and modernization of case management systems, eIDAS identities with qualified signatures and seals, sovereign cloud in German data centers, assistants and document classification with on-premises language models, classified information under VS-NfD, and a post-quantum roadmap for long-lived records and registers.
The difference from a pure consulting project lies in operations and evidence. Every online service, every seal key and every model comes with a security concept, a version state and the records that data protection officers, classified information security officers and internal audit require. The entire solution runs in German data centers. Keys for seals and classified information stay in hardware security modules under your control.
Cryptography and hardware security modules are our core competence. We plan and operate seal keys, eID integration and encryption for classified information with certified devices and approved products.
The entire solution runs in German data centers. Online services, language models and keys stay under German jurisdiction and your control.
We work with operators of critical infrastructure and regulated industries. The requirements of the BSI, data protection authorities and classified information security are part of our everyday project work.
One team accompanies you from consulting to operations. Software developers, cryptography specialists and AI engineers stay on board into daily operations without handover to third parties.
Most authorities do not fail for lack of will to digitize but on legacy case management systems, missing control over keys and unclear rules for new tools.
01
Applications arrive digitally but are printed or retyped because the case management system offers no interface for structured data.
02
Seal and signature keys sit as files on servers, certificates expire unnoticed and nobody checks incoming signatures systematically.
03
New procedures are built on provider platforms, the provider manages the keys itself and nobody has mapped the setup to C5 and IT-Grundschutz.
04
Employees paste extracts from case files into public AI services because no approved tool exists, and data protection and the staff council find out last.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your government data center or that of your IT service provider | Data centers in Germany, operated under ISO 27001 and IT-Grundschutz | Azure, AWS or Google Cloud, region Germany, unclassified data only |
| Operation | Your team or OTOKO® as managed service | OTOKO®, access under the four-eyes principle and logged | Shared, platform services by the provider |
| Tools | Case management systems, HSMs, LAN Crypt, language models on your own GPU servers | Kubernetes platform, hosted HSMs, language models in a German data center | Managed platform services, cloud HSM, keys through Hold Your Own Key |
| Suited for | Classified information, registers, seal keys | Online services and assistants with a need for sovereignty | Information portals, peak loads at application deadlines, development and test |
| Compliance | Full control, evidence from your ISMS under IT-Grundschutz | Processing agreement under GDPR, IT-Grundschutz evidence, location Germany | Processing agreement, provider's C5 attestation, no classified information |
Collaboration
Project
Clearly scoped initiative such as an OZG online service, a seal service in the HSM or a security concept under IT-Grundschutz, with a statement of work, milestones and acceptance.
Team reinforcement
Software developers, cryptography specialists or AI engineers work in your teams and tools, following your approval processes and classified information rules.
Managed service
OTOKO® operates platform, seal service, language models or encryption with agreed service levels, regular reports and operation under IT-Grundschutz in German data centers.
Five regulations against which government IT must be measured, with their requirements and what OTOKO® delivers for them.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| OZG | Digital access to administrative services through the portal network, user account with BundID, end-to-end digitization under the OZG amendment act, accessible services | Online services based on FIM, BundID integration, transfer via FIT-Connect with XÖV messages, connection of case management systems, test report under BITV 2.0 |
| eIDAS | Qualified signatures and seals with qualified certificates and QSCD, recognition of notified eID means, acceptance of the EUDI Wallet under eIDAS 2.0 | HSM selection under EN 419 221-5 with QSCD listing, seal and signature services, signature validation, eID integration under BSI TR-03130, wallet concept |
| BSI IT-Grundschutz | Information security management under BSI Standards 200-1 to 200-3, protection requirements assessment, modeling with the compendium, business continuity management under BSI Standard 200-4 | Structure analysis, protection requirements assessment, modeling and IT-Grundschutz check, security concept per procedure, emergency and recovery concept |
| GDPR | Legal basis, data protection by design, data protection impact assessment, processing agreements, limits on automated individual decisions under Article 22 | Data protection concept per procedure, contribution to the impact assessment, deletion concept based on retention periods, processing agreement with location Germany |
| NIS2 | Risk management measures, staged reporting obligations and management accountability for entities of the federal administration and for IT service providers within the directive's scope | Applicability check, gap analysis of the measures, reporting process with deadlines and exercises, cryptography and access concept |
FAQ
15 answers about your industry, the project and ongoing operations.
OTOKO® develops OZG online services and modernizes case management systems, integrates qualified signatures and seals with HSMs, builds sovereign platforms in German data centers and operates assistants with on-premises language models. It also delivers encryption for classified information under VS-NfD with approved products and a post-quantum roadmap for long-lived records. Each field of action can be commissioned on its own or as a package.
Yes, if protection requirements, storage location and key control fit. For unclassified data with normal protection requirements, cloud services with a C5 attestation are an option, provided processing agreement and location are settled. Classified information and registers with high protection requirements usually stay in your own or a German data center. We document the decision in the security concept under IT-Grundschutz and keep the keys in your HSM.
Through an interface that receives applications from FIT-Connect as XÖV messages and writes them into the case management system, instead of redeveloping the system. The business logic is preserved, individual modules are replaced step by step later, and each stage runs with tests and acceptance by the department. One team accompanies you from consulting to operations, also when legislative changes require new data fields.
The BSI grants VS-NfD approvals for IT security products, not for service providers. We use products approved for this purpose, such as Utimaco LAN Crypt, Utimaco DiskEncrypt and Utimaco CryptoServer with the VS-NfD package, and comply with their conditions of use and operation in configuration and operations. Your classified information security officers receive the documentation in one audit file.
Yes, if model, data and logs stay in your own or a German data center and the decision remains with the caseworker. We operate open-weight models without training them on file contents, take over permissions from the e-file system and log every request. Classification under the EU AI Act, the data protection impact assessment and documents for the staff council are completed before the pilot.
Because records and registers must stay confidential longer than classical encryption is expected to hold, and intercepted data can be decrypted later. Procurement cycles for HSMs, PKI and case management systems also take years. An inventory rated by retention periods shows which connections, certificates and archives migrate first, and new tenders demand crypto agility from the start.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Security architect: IT-Grundschutz, protection requirements, VS-NfD architecture. Cryptography specialist: HSMs, signatures and seals, PQC roadmap. Software developer: Online services, FIT-Connect, case management system modernization. Cloud architect: Platform, tenant separation, recovery. AI engineer: Language models, document classification, model operations. Project lead: Milestones, committees, acceptance, reports.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Administrative services, case management systems, protection requirements and obligations under OZG, eIDAS and IT-Grundschutz Procedure inventory, crypto inventory, gap analysis, initiatives prioritized by benefit and risk
Project: Clearly scoped initiative such as an OZG online service, a seal service in the HSM or a security concept under IT-Grundschutz, with a statement of work, milestones and acceptance. Team reinforcement: Software developers, cryptography specialists or AI engineers work in your teams and tools, following your approval processes and classified information rules. Managed service: OTOKO® operates platform, seal service, language models or encryption with agreed service levels, regular reports and operation under IT-Grundschutz in German data centers.
Monitoring, certificates, audits, knowledge transfer Daily operations under IT-Grundschutz, certificate renewal, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Government
Let us work out together how your authority can digitize administrative services securely while keeping control of its data.
Book a first consultation