No architecture can credibly guarantee that an attacker will never reach a technical contact point, that credentials can never be stolen or that zero-day vulnerabilities cannot exist. immo.quick therefore does not claim to replace general network, endpoint or organizational cybersecurity.
The verifiable architectural claim is narrower and stronger: invalid requests should not reach governed logic; and access alone should not authorize a real effect. Where required state is missing, stale, revoked, out of scope or arrives through an unauthorized path, execution fails closed.
Review-status note: only the architecture of the immo.quick Serverless Edition was demonstrably submitted to the BSI for technical consideration on 28 July 2026. The architecture of immo.quick Core was not submitted to the BSI. The submission does not constitute a BSI audit, certification, endorsement or confirmation. Public statements by immo.quick must not be understood as government validation.