
Frankfurt Hosted PAM for Data Sovereignty & Residency in Germany
Audit logs, elevation requests, and inventory data stay in EU-based datacentres in Frankfurt, subject to EU regulations and DSGVO.
Manage local admin rights and control endpoint access to reduce the risk of breaches and failed audits without slowing down your team.
Download and use for free or book a demo and let us show you.
Get 25 Endpoint Privilege Management, Secure Remote Access & Web Access Management seats, free.
Fill out the form with your work email and we’ll send your credentials to your inbox.
Why Data Residency Matters for PAM
Privileged access management touches the systems with your most sensitive permissions. The audit logs of those sessions are themselves regulated data under GDPR.
Where they’re stored, which jurisdiction governs them, and which laws apply to access request are all separate questions that procurement teams need to answer before signing.
Admin By Request stores customers data in EU-based datacentres in Germany, which gives you data residency in the EU and brings the data under EU regulation and DSGVO.
Watch to see how an Admin Session works.

How the Hosting Setup Works

EU-based datacentres in Germany
Audit logs, elevation requests, inventory data, and portal settings are stored in Frankfurt, on infrastructure located within the EU.

EU regulation applies
Customer data stored in EU datacentres is subjects to GDPR, DSGVO, and the broader EU data protection framework.

European company, European jurisdiction
Admin By Request is a European company operating under EU law and GDPR Article 28 obligations. Our DPA covers every customer.
Compliance for EU and German Organisations
As DSGVO compliant software hosted on EU infrastructure, Admin By Request supports compliance with the frameworks that matter most for organisations operating in the EU

GDPR (DSGVO)
Article 28-compliant Data Processing Agreement, full EU data residency, and audit logs of every privileged session for accountability requirements under Article 5(2)

ISO 27001
Information security management certified, providing a supporting framework for organisations building layered compliance programs.

SOC 2
Audited security controls, giving customers independently verified evidence of our own control environment.

NIS2
Privileged access controls aligned with the Directive’s risk management measures, supporting essential and important entities in scope of Germany’s NIS2 transposition.

DORA
Operational resilience and access control requirements for financial sector customers, including ICT third-party risk provisions

NIST SP 800-53
Aligned with the US federal security control catalog, for organisations with cross-border reporting requirements

CyFun (CCB CyberFundementals)
Aligned with the NIST CSF 2.0-based control set, relevant for organisaitons operating across Belgian and wider EU markets
Full documentation, certifications, and reports are available in our Trust Center (on English Website)

Inside the Product
Just-in-time privilege elevation across Windows, macOS, and Linux endpoints.
Full audit trails with elevation logs, approval workflows, and session recording.
Role-based access control with MFA support and SSO integration (Entra ID, SAML, Office 356).
Tenant-wide licensing covering all supported operating systems from a single portal.
25 endpoints free forever on the Free Plan with full feature access.

A Note on Data Sovereignty
Data residency and data sovereignty aren’t the same thing. Data residency means the data is physically stored in the EU and subject to EU regulation, which is the case for every Admin By Request customer in Germany today. Full data sovereignty also consider who owns and operates the underlying infrastructure, and which jurisdiction can legally compel access.
Today, our EU hosting runs on Microsoft Azure datacentres in Germany. that gives you strong EU data residency and DSGVO compliance, but Microsoft is a US-headquartered company subject to the US CLOUD Act, which applies to most major SaaS providers today. For organisations with strict sovereignty requirements that need infrastructure outside US-headquartered providers, we’re working towards EU-sovereign hosting infrastructure and are happy to discuss timelines.
Award Winning Solutions
We provide award-winning SaaS-based solutions to standing admin rights, overloaded helpdesks, outdated remote access infrastructure, malicious downloads, and internet access management.
Frequently Asked Questions
What is GDPR?
The General Data Protection Regulation is EU law governing data protection and privacy for individuals within the EU. It applies to any organization processing EU citizen data and requires privacy by design, data minimization, breach notification within 72 hours, and comprehensive data subject rights.
How Admin By Request Helps
- Access Management: Granular data access controls limiting access to personal data by business justification
- Risk Management: Privacy by design implementation with automated data minimization controls
- Documentation: Comprehensive audit trails for all data access and modification activities
- Operations: Quick breach detection and detailed impact assessment for 72-hour notification
- All data is processed and stored in Germany, with no cross-border transfers outside the EEA
- Removes the need for Standard Contractual Clauses (Article 46) or adequacy decisions (Article 45) to legitimise data flows
- Supports Article 32 requirements to implement appropriate technical and organisational measures to protect personal data
- Supports Article 30 Records of Processing Activities by providing a clear, verifiable data location
What is NIS2?
The Network and Information Systems Directive 2 (NIS2) is comprehensive European Union legislation that enhances cybersecurity requirements for critical infrastructure and essential service providers across the EU.
How Admin By Request Helps
- Access Management: Enforces strict separation between privileged IT access and sensitive operational systems, reducing the risk of unauthorized access
- Documentation: Detailed logs of all elevated access and system changes, supporting NIS2 obligations for auditability and incident investigation
- Operations: Segregation of duties enforcement to minimize insider risk and ensure accountability in managing critical network and information systems
- Process: Automated access reviews and certifications helping demonstrate continuous alignment with NIS2’s risk management and governance standards
- Supports Article 21 requirements for appropriate and proportionate technical security measures across your organisation
- German organisations subject to BSI oversight (as designated under Article 33) benefit from keeping incident data and audit records within the same jurisdiction
- Reduces the compliance burden for entities newly brought into scope under NIS2’s expanded Article 3 coverage
What is DORA?
The Digital Operational Resilience Act is EU regulation requiring financial entities to strengthen their operational resilience against ICT risks. It covers ICT risk management, incident reporting, operational resilience testing, and third-party risk management.
How Admin By Request Helps
- Risk Management: ICT risk assessment and management through controlled privileged access
- Operations: Operational resilience testing with secure emergency access procedures
- Monitoring: Real-time monitoring of critical ICT systems and privileged activities
- Documentation: Comprehensive incident reporting and third-party access management
- Supports Chapter V third-party ICT risk requirements by keeping financial data within the EU and removing cross-border data transfer risk from your vendor assessment
- Helps meet Article 28 requirements for contractual documentation between financial entities and ICT third-party providers
- Supports Article 11 ICT business continuity requirements by ensuring your operational data remains within a defined and auditable boundary
What is CyFun?
Cybersecurity Fundamentals is Belgium’s national cybersecurity network, from the Centre for Cybersecurity Belgium. It uses the same structure as the NIST Cybersecurity Framework but extends it with guidance from ISO 27001, CIS Controls, and real-world Belgian threat data. Organisations can implement it across four assurance levels — Small, Basic, Important, and Essential — making it more accessible than traditional frameworks while still meeting EU regulatory expectations.
How Admin By Request Helps
- Access Management: Demonstrates least privilege principle with just-in-time elevation and role-based access controls
- Documentation: Comprehensive audit trails and automated compliance reporting for SOC 2 requirements
- Operations: Segregation of duties enforcement and streamlined access certification processes
- Security: Multi-factor authentication and secure remote access with session monitoring
- GDPR compliance is embedded in CyFun’s Govern function (GV.OC). A German data centre satisfies the data protection obligations that underpin it.
- Supports PR.DS (Data Security) controls by keeping data at rest and in transit within a defined, auditable EU boundary.
- Reduces risk exposure under ID.RA (Risk Assessment) controls by removing cross-border data transfer risk from your threat profile.
- At Important and Essential assurance levels, stricter supply chain controls apply. Frankfurt-hosted data provides a clear, verifiable answer to third-party risk requirements.
- CyFun maps directly to NIS2. A Frankfurt-hosted platform supports both frameworks simultaneously, reducing duplicated compliance effort
What is ISO 27001?
ISO 27001 is an international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through risk assessment, security controls implementation, and continuous improvement processes.
How Admin By Request Helps
- Access Management: Comprehensive access control management aligned with ISO 27001 requirements
- Risk Management: Regular risk assessments and treatment of information security risks
- Security: Implementation of security controls for asset and access management
- Documentation: Detailed documentation and evidence collection for certification audits
- Operations: Business continuity management and supplier relationship security
- Annex A.18.1 requires identification of and compliance with applicable legal and regulatory obligations, including GDPR for EU organisations
- German data residency directly satisfies that control without additional technical or contractual workarounds
- Provides a clear, auditable answer to Annex A.8.10 information deletion and Annex A.5.33 protection of records requirements, as data location is fixed and verifiable
What is ISO 27001?
ISO 27001 is an international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through risk assessment, security controls implementation, and continuous improvement processes.
How Admin By Request Helps
- Access Management: Comprehensive access control management aligned with ISO 27001 requirements
- Risk Management: Regular risk assessments and treatment of information security risks
- Security: Implementation of security controls for asset and access management
- Documentation: Detailed documentation and evidence collection for certification audits
- Operations: Business continuity management and supplier relationship security
- Annex A.18.1 requires identification of and compliance with applicable legal and regulatory obligations, including GDPR for EU organisations
- German data residency directly satisfies that control without additional technical or contractual workarounds
- Provides a clear, auditable answer to Annex A.8.10 information deletion and Annex A.5.33 protection of records requirements, as data location is fixed and verifiable
