Secure Supply Chains: Save 36h with on-site customs. Find out more.

FACTUREE Strengthens Resilient Procurement for the Security and Defense Industries

Author Photo

Those who source parts digitally often share more than just dimensions, materials, and tolerances. Technical drawings and CAD data can contain references to prototypes, development stages, and design know-how. The procurement service provider FACTUREE has now reinforced its standards for protecting sensitive data and design know-how with ISO/IEC 27001:2022 certification. With the successful audit of its own information security management system, FACTUREE confirms that data protection is the top priority in digital procurement.

„Design data isn’t just an attachment to a purchase order. For many companies, it’s an essential part of their intellectual property,“ says Christopher Walzel, CPO and co-founder of FACTUREE. „We are now ISO 27001 certified. This means that the protection of this information is embedded in our independently audited management system. An important USP here is that we are certified as a company, not just our data centers.“

FACTUREE’s compliance with the standard was confirmed by a certification audit conducted in accordance with ISO 27006. The certificate was issued by the Digital Institute for the Certification of International Standards (DICIS). It is valid until June 12, 2028, and is monitored annually.

The scope of the audit covers the development, operation, and provision of the online platform for the procurement of custom-manufactured parts, as well as the processing of customer, supplier, and order data, including technical drawings, CAD data, and product-specific specifications.

Information Security Throughout the Procurement Process

FACTUREE sources parts based on customer drawings through a network of more than 2,000 vetted manufacturing partners and acts as the sole contractual partner and point of contact for its customers. The process ranges from the technical inquiry and the selection of suitable manufacturing partners to production, quality assurance, and delivery. This creates a central interface through which companies can consolidate their procurement and reduce operational overhead.

Customers upload technical information, which is then stored. It is subsequently reviewed, processed internally, and shared with selected manufacturing partners on a project-by-project basis. In the case of FACTUREE, information security therefore concerns not only hosting but also access rights, internal processes, supplier management, and the controlled disclosure of order-related manufacturing information.

Manufacturing partners receive only the information necessary to carry out the respective project. For buyers, ISO 27001 certification confirms FACTUREE’s already established information security management system, which has long governed the handling of customer, supplier, and order data in accordance with risk-based processes. For customers, the certification now provides official proof that they can use as documentation in their supplier evaluations, quality management processes, or when dealing with auditors.

Evidence for regulated industries and early stages of development

Prototypes, pre-production runs, and customer-specific components present particularly high demands in terms of information security. In these projects, drawings and CAD data often provide insight into new products, processes, or design solutions. The uncontrolled disclosure of such information can jeopardize development projects and undermine competitive advantages.

For companies in the security and defense, automotive, medical technology, and aerospace industries, the handling of technical information is therefore a key criterion in supplier evaluation. In addition to quality certifications, traceability, and documentation, procurement teams require reliable evidence that sensitive development and manufacturing data is processed in a controlled manner.

„Digitalization makes technical procurement faster and more efficient, but at the same time increases the demands placed on the protection of sensitive information,“ says Christopher Walzel. „In the future, companies will increasingly select their procurement partners based on how professionally and transparently they handle intellectual property and confidential development data.“

You may also be interested in these articles

Press releases

all press releases