Trustworthy email communication at acib

For acib GmbH, email is a business-critical means of communication in the daily, global exchange of bioprocessing innovations from science and industry. In order to preventively counter the system-related risks of conventional email technologies, we rely on a multi-level protection concept that combines technical barriers with clear guidelines for data handling. This enables us to guarantee the highest standards of confidentiality and integrity in order to effectively protect our own research results and those of our partners.

Legal framework and mandatory information (signature)

In order to ensure maximum transparency and compliance with legal requirements, our email communication is subject to strict formal and legal rules:
  • Exclusive use of the official domain: All official and legally valid email communication from acib GmbH is sent exclusively from addresses ending in @acib.at. Messages from other domains (e.g. freemail providers) on behalf of acib GmbH should be considered potentially fraudulent.
  • Project-specific domains: In the context of specific collaborations, research consortia or funding projects, separate, project-specific domains may also be used. An overview of domains managed or used by acib can be found under section 1
  • Legal validity: Conventional emails do not constitute legally binding obligations for acib GmbH unless they have been digitally signed (QES) or transmitted via dedicated, secure channels.
  • Legal requirements (UGB & GDPR): In accordance with Section 14 of the Austrian Commercial Code (UGB) and the information requirements of the EU General Data Protection Regulation (GDPR), every business email sent by acib GmbH must contain a standardised signature disclaimer. This reads as follows: This email is sent on behalf of acib GmbH, Krenngasse 37, 8010 Graz, AUSTRIA. acib GmbH is incorporated under Austrian law and registered at LG für ZRS Graz, company register no. 224687y, VAT no. ATU 54545504. acib uses personal data (contact data, data about professional qualifications) for current and future business collaborations, and will retain such data for the duration of our business relationship and beyond as far as necessary for documentation purposes. Legal basis: Article 6 (1) b) and f) EU GDPR. Further information about acib and its legal status can be found at www.acib.at/imprint/. General information about privacy protection at acib can be found at www.acib.at/data_protection/. 
Since emails are considered full-fledged business and evidence documents in a business context, all incoming and outgoing messages from acib Ltd. – regardless of the domain used – are automatically archived in an audit-proof manner in order to comply with legal retention requirements.

Protection of sender identity (authentication).

To ensure that emails sent under the name of acib GmbH actually originate from us, we use state-of-the-art authentication procedures within our Microsoft environment:
  • SPF (Sender Policy Framework): We specify which servers are authorised to send emails on our behalf.
  • DKIM (DomainKeys Identified Mail): Every outgoing email receives a digital signature that ensures its integrity during transport.
  • DMARC (Domain-based Message Authentication): We use a strict DMARC policy to prevent unauthorised use of our domain (spoofing) and to give recipient systems clear instructions on how to handle suspicious emails.

Threat defence (anti-malware & fraud)

Within our Microsoft 365 infrastructure, advanced filtering technologies are used to defend against threats and prevent data leakage:
  • Spam & phishing protection: Incoming messages are automatically scanned for malicious links, attachments and phishing attempts.
  • Fraud prevention (anti-fraud): We use mechanisms to detect identity theft (e.g. CEO fraud) to protect our employees and partners from targeted social engineering attacks.
  • Safe Links & Safe Attachments: Incoming file attachments are checked for malicious code in a secure, isolated cloud environment (sandbox) before they are delivered. Similarly, URLs contained in emails are dynamically checked for malicious targets at the time of clicking (time-of-click protection).
  • Zero-day threat protection: By using AI-powered threat analysis within the Microsoft infrastructure, we also identify and block new, as yet unknown attack patterns in real time before they reach our systems.
  • Automated quarantine and incident response: Suspicious messages that indicate advanced threats are automatically isolated. Our IT security team receives immediate alerts to proactively analyse potential security incidents and initiate company-wide countermeasures.
Despite these comprehensive, automated protection mechanisms, vigilance remains essential. Technical barriers can significantly minimise the residual risk of sophisticated, targeted attacks, but they cannot completely eliminate it. For this reason, every employee of acib GmbH is obliged to critically examine suspicious messages – even if they appear to come from known internal or external senders – and, in case of doubt, to forward them immediately to the IT department for analysis using the reporting function of our email system.

Note on document transmission: To prevent the introduction of malware through malicious macros (e.g. ransomware), our email gateway blocks the receipt of outdated Office file formats (especially .doc and .xls) on the server side. We urge our communication partners to use only current, secure file formats (such as .docx, .xlsx or .pdf) for document exchangecontrols or complex patent disputes.

Regardless of this, we would like to point out that confidential documents should never be sent as email attachments. On request, we are happy to provide upload options to our system. An upload box can be requested at short.acib.at/secureupload.

Classification and information labelling

We use an internal classification system to highlight the sensitivity of information:
  • Email labels (Traffic Light Protocol): Outgoing messages are assigned specific confidentiality labels (TLP:CLEAR, GREEN, AMBER, AMBER+, RED) by our employees depending on the criticality of the content. This labelling is not to be understood as a mere recommendation, but defines the strict limits of information disclosure. A detailed overview and binding definition of the labels used and the associated rules of use can be found at “Encryption and data security“.
  • Automated disclaimers and protection of trade secrets: Based on the selected label, our system automatically adds legal notices and confidentiality clauses (disclaimers) to messages. We expressly point out that these disclaimers are legally binding. They serve to actively protect our trade secrets and the intellectual property of our research partners.
Legal binding and consequences of non-compliance: The confidentiality requirements specified in the labels and disclaimers must be strictly observed. Any unauthorised disclosure, reproduction or misuse of information marked as confidential (e.g. TLP:AMBER or RED) constitutes a breach of any confidentiality agreements (CDAs) or the protection of trade secrets under the UWG (German Unfair Competition Act). acib GmbH expressly reserves the right to take legal action and assert claims for damages in the event of violations of these information protection guidelines.

Encryption and data security

As a research institution at the interface between science and industry, acib GmbH handles strictly confidential research data, intellectual property (IP) and sensitive trade secrets on a daily basis. To prevent this information from being intercepted, manipulated or viewed by unauthorised third parties during transmission, we use a multi-level, hybrid encryption concept. This is strictly based on our internal information classification system (Traffic Light Protocol). We protect the content of our messages using the following technical encryption mechanisms:
  • Transport encryption (TLS): By default, every email is transmitted via an encrypted connection (TLS 1.2 or higher).
  • Increased protection (TLP:AMBER+STRICT): For highly sensitive data, we enforce the AMBER+STRICT encryption level. In these cases, delivery is only carried out if a highly secure, verified connection to the recipient is guaranteed. Furthermore, only authenticated recipients can receive the message. To open classified documents of this confidentiality level, authentication with acib is required. If a document cannot be opened, please request authentication from acib in the acib tenant.
  • Highest protection (TLP:RED): For the TOP SECRET confidentiality level, emails are encrypted and can only be opened by the recipient. Forwarding, even within the recipient’s organisation, is not possible.
  • Individual encryption (Microsoft Purview Message Encryption): We provide our employees with Microsoft encryption for the flexible and secure exchange of sensitive information at an individual level. By selecting the ‘Encrypt’ option in the email client, messages can be protected in such a way that the recipient must authenticate themselves before reading (e.g. via a one-time passcode or Microsoft account).
  • End-to-end encryption (S/MIME): S/MIME offers certificate-based end-to-end encryption, in which emails are digitally signed and encrypted. This technology is only supported by acib GmbH in specific, highly regulated projects, as it requires the prior exchange of personal certificates between the communication partners.
The choice of the appropriate encryption method is the responsibility of the respective employees, but must comply with the information classification guidelines (see TLP guideline). We would like to point out to external communication partners that the receipt of highly encrypted messages (in particular TLP:AMBER+STRICT and TLP:RED) requires specific technical prerequisites (such as authentication in our Microsoft tenant) or suitable email clients. Our IT administration is available to provide support in the event of technical difficulties when opening encrypted messages. To ensure data security, the unencrypted transmission of data of these classification levels is strictly prohibited.

Secure data transfer instead of email attachments

Conventional email attachments pose considerable system-related risks: they lead to uncontrolled data duplication and version conflicts and make it difficult to protect sensitive information, as control over the document is lost when it is sent. acib GmbH therefore reduces the sending of traditional file attachments to an absolute minimum and relies on modern, cloud-based collaboration solutions within our Microsoft tenant for data exchange:
  • Secure file sharing (SharePoint / OneDrive links): Instead of physical file attachments, we send secure, temporary access links from our SharePoint environment as standard. In order to verify external recipients beyond doubt, these links are usually protected by guest authentication (e.g. by means of a one-time passcode sent to the email address) and automatic expiry dates. This ensures that documents remain centrally located in one place (‘single source of truth’) and that we can control access rights (e.g. read or edit rights) at any time and revoke them immediately if necessary.
  • Temporary upload boxes for partners: We provide dedicated upload boxes in our SharePoint environment for the secure receipt of large amounts of data or sensitive documents from external communication partners. This eliminates the risky detour via email inboxes.
  • Requesting data transfers: If you, as an external partner, would like to send us confidential data, simply ask your acib contact person for a personalised upload link or request a secure file box yourself at short.acib.at/secureupload.
We expressly request all our cooperation partners to adhere to this modern standard of document transmission in order to jointly meet the highest data security and compliance requirements.

Mass mailings and newsletters

acib GmbH does not use its regular internal email infrastructure (Microsoft 365) for sending mass emails, newsletters or unsolicited advertising mailings. In order not to jeopardise smooth business transactions, mass mailings via our regular mail servers are technically prevented.
The following guidelines apply to professional marketing and information communication:
  • Central newsletter dispatch (Mailchimp): We exclusively use the certified external service provider Mailchimp for our information services, event invitations and newsletters. This ensures that high technical delivery standards are maintained and that the server load of our own systems is not affected.
  • Protection of domain reputation: By strictly separating regular project correspondence (via M365) and mass mailings (via Mailchimp), we preventively prevent our primary company domain (@acib.at) from ending up on global blacklists or our regular business emails from being incorrectly classified as spam by recipient systems.
  • GDPR compliance (registration and objection): Marketing emails are only sent to recipients who have given their express prior consent (double opt-in) or with whom we have an existing business relationship. Every message sent via Mailchimp must contain a clearly visible link for immediate, automated unsubscription (opt-out).
  • Privacy policy: All information on the processing of personal data in the context of our newsletter distribution, the legal basis and the right of withdrawal is transparently regulated in our dedicated privacy policy under reference to DSE Newsletter.
The planning, creation and sending of mass emails via Mailchimp is the sole responsibility of the departments authorised for this purpose (e.g. Marketing/Communications) Individual employees, research groups or project managers are not authorised to carry out mass mailings (either via Outlook or external tools) on their own initiative in order to guarantee compliance with our data protection requirements and the integrity of our domain reputation at all times.

Handling external information and forwarding requests

We often receive requests from external partners or networks asking us to forward certain information to the entire staff of acib GmbH. In order to maintain the relevance of internal communication, clear filter criteria apply:
  • No forwarding of advertising and job offers: External advertising mailings, product placements, service offers and non-industry-specific or general job advertisements (job offers) from third-party companies are generally not distributed via our internal channels. We ask external senders to refrain from sending such mailings, as they will be filtered and discarded without exception.
  • Targeted information sharing: However, we are happy to review incoming information on relevant research funding, subject-specific calls for proposals, scientific conferences or industry-related events. If these are of recognisable value to our research and project work, they will be curated by the relevant department and made available to interested employees via our internal dashboards (not via mass email).
Consequences of unsolicited mass mailings: acib GmbH does not tolerate the misuse of our communication channels. External senders or service providers who use our email addresses for unsolicited mass advertising mailings, aggressive acquisition or the untargeted sending of job advertisements (spam) are in violation of our communication guidelines. In order to protect the efficiency of our employees and the security of our systems, our IT administration reserves the right to block the affected sender addresses or entire domains on the server side without prior warning (blacklisting). In such cases, restoration of the communication channels is generally not possible.

Central contact points and availability

The following central contact addresses are available for efficient and secure communication:
General enquiries and informationoffice@acib.at
Legal Questionslegal@acib.at
Questions about invoices and accountingaccounting@acib.at
Billing and Controllingcontrolling@acib.at
Questions about deliveries and ordersprocurement@acib.at
Questions about projects and collaborations (scientific collaboration)scico@acib.at
Questions about (new) project collaborations and solutions (business development)bd@acib.at
Questions about publications and open accesspublications@acib.at
Questions about the COMET programcomet@acib.at
Questions about esib - European Summit for Industrial Biotechnologyesib@acib.at
Questions about LifeIsScience - European Long Night of Researchlis@acib.at
Questions about events, webinars, and functionsevents@acib.at
Personnel matterspersonal@acib.at
Inquiries from applicantsjobs@acib.at
Occupational safetysafety@acib.at
Information and system securitysecurity@acib.at
Data protection questionsprivacy@acib.at
Inquiries under the Freedom of Information Actifg@acib.at
Press inquiriespr@acib.at
Questions about newsletters and mailingseditorial@acib.at
Technical IT questionsit@acib.at
Technical questions emailpostmaster@acib.at
Email abuse (spam, phishing)abuse@acib.at
Technical questions about domain issues and DNS registrationhostmaster@acib.at
Homepage inquirieswebmaster@acib.at
Compliance questions, Compliance Boardcompliance@acib.at
Ombudsman for Scientific Integetriyresearch-integrity@acib.at
Equal Treatment Officerequality@acib.at
CEO Bureaugef@acib.at
Works Councilbetriebsrat@acib.at
Contact for committee membersgremien@acib.at
Sender address for system information (no reply possible)no-reply@acib.at

Legally secure delivery and signature

Since conventional emails are often insufficient for verifiable delivery (e.g. to meet deadlines) or the legally valid conclusion of contracts, acib GmbH uses specialised, certified channels for these purposes. The choice of system depends on the respective recipient and the legal purpose of the communication:
  • Communication with authorities (e-delivery / MeinPostkorb): We use the electronic delivery system for legally effective and timely exchanges with Austrian offices and authorities. This replaces traditional RSa and RSb letters. acib GmbH retrieves and sends these centrally via the Enterprise Service Portal (USP) using ID Austria.
  • Verifiable business mail (eBrief): Digital letter delivery (e.g. eBrief from Austrian Post) is used for the certified dispatch of important documents to partners or companies that are not connected to the official e-delivery system. This ensures a high level of security and traceability during transport.
  • Contract signing (DocuSign & PDF signatures): A secure transport route does not replace a legally binding signature. For contracts and legally binding documents, acib GmbH uses dedicated electronic signature workflows (such as DocuSign or certified Adobe signatures). Such documents may only be sent for digital signature after mandatory prior review and approval by the legal department (legal@acib.at).

Strict adherence to these specified delivery and signature methods is essential to ensure the legal validity of our contracts and our correspondence with authorities beyond any doubt. This effectively protects acib GmbH from legal disadvantages, missed deadlines or invalid agreements due to formal errors. The use of private or non-IT-approved signature and delivery services (so-called shadow IT) for business purposes is strictly prohibited for compliance and data protection reasons. If you are unsure about the correct transmission method or the formal requirements for a signature, you must consult the legal department (legal@acib.at) in advance.

Security information for recipients (precautionary measures)

Despite all our technical protective measures (such as SPF, DKIM and DMARC), email sender addresses can be spoofed by third parties. To protect yourself and your company from cybercrime, we ask you to take the following precautions when communicating with acib GmbH:
  • Reinsurance in case of suspicion: If in doubt, contact your contact person at acib GmbH via a second channel (e.g. telephone) to verify the authenticity of a request.
    No password requests: We will never ask you to disclose passwords or access data via email. We use secure systems such as 1Password or encrypted messages to communicate or share passwords.
  • Confidentiality in subject lines: We take care not to include sensitive information in the subject line of an email, as for technical reasons this can often be transmitted unencrypted or stored in logs.
  • No last-minute changes to bank details by email: acib GmbH will never ask you exclusively by email (without prior personal consultation) to make transfers to changed or new bank accounts. If you receive such payment requests, please contact our finance department at accounting@acib.at or by telephone, or compare the details with those published on our homepage under Reference to accounting.
  • Be wary of unexpected links and requests: Be suspicious of emails that appear to come from acib GmbH but create unusually high time pressure (e.g. ‘Urgent review required’) or unexpectedly ask you to click on external links or enter login details on a website.
  • Check the sender’s address: Do not rely solely on the name of the sender displayed. For unexpected messages, always check the actual email address (behind the name) to ensure that the message actually originates from an @acib.at domain and not from a similar-looking fake (e.g. @acib.com or @aclb.at).
The security of our shared data is a top priority for acib GmbH. If you receive an email in our name that seems suspicious in terms of the sender, content, attachments or calls to action, please do not reply to it, click on any links or open any attachments. Instead, please forward such suspicious messages immediately to our IT security team at security@acib and then delete the email from your inbox. We thank you for your help and vigilance in the joint fight against cybercrime.

Security awareness and training

The most advanced technical IT security measures at acib GmbH can only be fully effective if they are supported by the conscious and trained behaviour of our employees. Compliance with the highest security standards (human firewall) is therefore a mandatory organisational measure:
  • Mandatory employee training: All employees (including guest researchers and administrative staff) participate in mandatory security awareness training upon joining the company and as part of regular refresher courses. These courses impart essential knowledge for the early detection of phishing, spear phishing, ransomware attacks and social engineering tactics (such as CEO fraud).
  • Active phishing simulations: To continuously review and sharpen our security awareness, we conduct internal, unannounced phishing simulations at irregular intervals. These serve purely as training exercises and help us to identify weaknesses in the detection process and provide targeted retraining.
  • Reporting culture (phishing button): We promote a proactive reporting culture (see something, say something). Every email client in our Microsoft tenant is equipped with a special ‘phishing report button’. Employees are encouraged to immediately forward suspicious messages to the IT security team for analysis at the touch of a button, rather than simply deleting or ignoring them.
  • Incident response management: Should a security incident nevertheless occur (e.g. a malicious link clicked or compromised access data), our clearly defined incident response processes come into effect. Affected employees are obliged to report incidents immediately and without fear of sanctions to security@acib.at <security@acib.at> in order to ensure rapid containment, isolation of affected systems and transparent information for any partners.

Joint security responsibility in the research network (NISG)

As an internationally active centre of excellence and operator of critical infrastructure, acib GmbH is subject to the strict requirements of the Network and Information System Security Act (NISG 2026). This also includes far-reaching responsibility for the security of our digital supply and value chains. We therefore regard information security not only as an internal obligation, but as a shared, cross-network responsibility. We expect our scientific and industrial communication partners to have a similarly high level of security awareness and to comply with up-to-date IT security standards. If we discover that messages, phishing attempts or security risks are emanating from our partners’ systems, we reserve the right to immediately block email reception from these sources until the relevant systems have been demonstrably cleaned up in order to protect our own infrastructure. phishing attempts or security risks, we reserve the right to immediately block email reception from these sources in order to protect our own infrastructure until the relevant systems have been demonstrably cleaned up.

Rejection of insufficiently secured messages (DMARC/SPF/DKIM): In order to protect our systems from spoofing and phishing, acib GmbH strictly checks incoming emails for compliance with current email authentication standards (SPF, DKIM and DMARC). We do not guarantee delivery of messages sent from mail servers with no or insufficiently configured authentication entries. Such emails may be automatically rejected (Rejected) or moved to quarantine by our security systems.

We ask our communication partners to secure their email infrastructure in accordance with current best practices in order to ensure smooth communication.

If your emails to acib GmbH are rejected due to missing authentication (Non-Delivery Report / NDR), we ask you to contact your internal IT department or your email provider immediately. Please ask them to store correct SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail) and DMARC entries for your sender domain in the DNS. These measures are in line with global best practices (including BSI, Microsoft) and are essential to restore secure and smooth communication with our systems.

Archiving and data protection

In order to comply with legal documentation requirements and our own compliance requirements, email communication at acib GmbH is subject to strict archiving and data protection regulations:
  • Audit-proof and unalterable archiving: In accordance with the provisions of the Austrian Commercial Code (UGB § 212) and the Federal Tax Code (BAO), all incoming and outgoing business emails (including attachments) are archived automatically, completely and in an audit-proof manner. The archiving solution used ensures that messages cannot be manipulated retrospectively or deleted before the expiry of the statutory retention periods (usually 7 years, often longer for specific research projects).
  • Data protection (GDPR) and data subject rights: In the course of email communication, acib GmbH inevitably processes personal data (e.g. names, contact details, communication content). This processing is carried out on the basis of our legitimate interest and for the purpose of fulfilling contracts (Art. 6 (1) (b) and (f) GDPR). For detailed information on data processing, storage periods and your rights as a data subject (such as information, deletion or restriction), please refer to our comprehensive privacy policy at reference to DSE email.
  • Exclusion of private use: In order to avoid conflicts between the company’s archiving obligations and telecommunications secrecy or the privacy of employees, the use of work acib email addresses for private purposes is prohibited. Incoming messages are always treated as business correspondence and processed and archived in accordance with the above guidelines.
Access to the email archive is strictly regulated and only permitted to authorised personnel (such as management or designated compliance officers) within the scope of legally binding requirements – for example, in the event of legal disputes (e-discovery) or official audits. If external communication partners request the deletion of their personal data from our email communication in accordance with the GDPR, this request will be reviewed individually by our data protection team. We would like to point out that in many cases, the right to deletion may be overridden by overriding legal retention obligations (e.g. from contracts or company law), which is why complete removal from the audit-proof archive before the expiry of these periods is often not technically or legally possible.