It all started with a watch

Health data forms the foundation for sound decision-making, connected care, and responsible innovation. To realize its full value, it must remain trustworthy, interoperable, and sustainable throughout its entire lifecycle. This is precisely what XQT stands for—the DMI GROUP’s brand for data sovereignty.

As part of the DMI GROUP, timeproof contributes its expertise to the XQT brand’s solution portfolio.

As the DMI GROUP’s trust technology specialist, timeproof provides the technological foundation for digital integrity, traceability, and long-term preservation of evidential value, forming a key component of XQT’s TRUST layer.

Together with DMI, Health-Comm, gefyra, and the XQT Innovation Members, XQT combines proven expertise into a robust, comprehensive offering—for secure processes, well-informed decisions, and a sustainable healthcare system.

Digital transformation requires 
constant evolution

timeproof has evolved from a provider of highly specialized timestamping technology into a leading full-service provider of evidence-preserving archiving solutions.

Using in-house developments such as eRecApp, we process even massive amounts of data efficiently and in compliance with legal requirements.

By consistently adhering to the strictest standards, such as BSI TR-ESOR, we offer maximum future-proofing for your critical informatio

Building Trust for Decades

Today, timeproof is part of the DMI GROUP and helps companies in industry, healthcare, and the public sector keep their digital information trustworthy, traceable, and legally compliant. The core concept has remained the same for more than 25 years: building trust in digital data—not for days or months, but for decades.

Milestone Timeline of timeproof GmbH

1999–2000

  • The TSS—and with it, timeproof—emerged from a thesis on a tamper-resistant clock displaying legally valid time and the idea of linking this derived time to qualified electronic certificates.

2000

  • The first small production run of the TSS series is ready for use and is presented at CeBIT.
  • The TSS400 is submitted for certification.
  • D-Trust GmbH and Bundesdruckerei integrate the TSS into the newly established trust center.
  • A-Trust GmbH integrates the TSS into its infrastructure.

2001

  • Airbus launches the pilot program.
  • Certification of the TSS400 is completed.

2003

  • Production deployment at Airbus—launch of one of Europe’s largest archives with timestamp protection.
  • Germanischer Lloyd (later DNV) becomes a customer.

2004

  • UBS, a major bank, becomes a customer with one of the world’s largest single installations of the TSS400 for securing global communication protocols.

2005

  • Lotto Hamburg and other public agencies, such as the Procurement Office of the Federal Ministry of the Interior (BMI), become clients.
  • Sigma-Aldrich, from the chemical and pharmaceutical sector, becomes a client.
  • Integration of the TSS400 into a trust center operated by Deutsche Telekom AG.

2009

  • ARAG SE, from the insurance industry, becomes a client.

2011

  • Olaf Feller takes over as CEO.
  • Starting point: only one product (TSS400), two software stacks, one of which was still unstable.

2012

  • Migration of timeproof’s proprietary Java API to the Java API developed by Graz University of Technology

2013

  • Airbus reports a massive need for hash rehashing (data volumes in the double-digit petabytes).
  • Start of the definition of the eRecApp POC.

2013–2014

  • Development of the eRecApp POC for evidence record generation (RFC 4998).

2015

  • Production rollout of eRecApp at Airbus.

2018

  • DMI becomes a customer using eRecApp.

2021–2022

  • Joint TR-ESOR certification project with DMI.
  • BSI submission in summer 2022, review in fall 2022.
  • Start of development to replace the TSS400 with the TSS500
  • nearly complete software-based approach (instead of a hardware appliance)

Ø  Elimination of smart cards as certificate carriers; software certificates are used instead, thereby eliminating the need for Trustbox hardware.

February 2023

  • The BSI issues the TR-ESOR certification certificate.

2024–2026

  • QTSP certification (Qualified Trust Service Provider) activated in collaboration with DMI (audit by TÜViT, MSG).
  • Completion of the upgrade from the TSS400 to the TSS500:
    • Fully software-based approach (instead of a hardware appliance)
    • Modernization: C++ → Go
    • DCF receiver cards from Meinberg for maximum precision.
  • Acquisition of timeproof GmbH by the DMI GROUP

 “Data integrity is a cornerstone of digital resilience”

How timeproof supports companies in complying with NIS2 and DORA through qualified timestamps and cryptographic evidence preservation.

NIS2 and DORA place greater emphasis on the availability, authenticity, and integrity of digital information. For regulated organizations, this also raises the critical question of how the authenticity of business-critical information can be verified in a traceable manner over the long term.  In this interview, Managing Director Olaf Feller and Christoph Schmelter, Managing Partner of the DMI Group—to which timeproof belongs—explain why integrity assurance plays a key role in this context and what the change in ownership means for the future of timeproof GmbH.

Mr. Feller, why does integrity assurance play such an important role in the context of NIS2 and DORA?

Olaf Feller: “NIS2 and DORA significantly raise the bar for traceability, IT resilience, and governance. It’s not just about keeping data available. Organizations must also be able to protect the integrity and authenticity of their data and ensure it is traceable. Especially after a cyberattack, a crucial question arises: Which data can we still trust? This is exactly where timeproof comes in. We provide technical evidence that relevant information has remained unchanged—or that any changes can be reliably identified.”

What specific benefits does timeproof offer to companies that need to comply with NIS2 or DORA requirements?

Olaf Feller: “We ensure the integrity of digital information over long periods of time. To do this, we combine qualified timestamps, cryptographic evidence records, and BSI-certified procedures for preserving the evidential value of data. This provides companies with technically robust proof of the integrity of their data—whether for regulatory inspections, internal audits, or the investigation of a cyber incident. In doing so, we address a key component of a NIS2- and DORA-compliant security and resilience strategy.”

What sets timeproof apart from other providers on the market?

Olaf Feller: “Our particular strength lies in our modular approach. Qualified timestamps, RFC-4998-based evidence records, and our BSI-certified TR-ESOR solution, RECORDPROOF, can be used individually. However, their true strength lies in how they work together: We can ensure the integrity of information from its creation through its processing to the long-term preservation of its evidential value. This results in a seamless integrity pipeline. Companies therefore do not have to piece together disparate standalone solutions to form a chain of evidence, but can build it from a single source.”

Mr. Schmelter, you have taken over timeproof. What was the deciding factor in taking this step?

Christoph Schmelter:  “Timeproof addresses a key issue in the digital transformation. With NIS2 and DORA, digital integrity has evolved from a niche IT topic to a matter for the executive board. At the same time, virtually every other aspect of digitalization—including AI—relies on the origin and integrity of data remaining reliably traceable. This is precisely why timeproof is a strategic excellent fit for the DMI Group. Our mission is to provide infrastructure for trustworthy data that can be used with confidence. timeproof brings to the table an outstanding technological foundation, BSI-certified processes, and deep cryptographic expertise. We want to further develop this potential together and scale it beyond the healthcare sector.”

In short: What do customers and partners need to keep in mind?

Kurz gesagt: Was müssen sich Kunden und Partner merken? 

Christoph Schmelter: “Digital resilience requires trustworthy data. timeproof provides a crucial building block for this: the verifiable integrity of digital information. With qualified timestamps, cryptographic evidence preservation, and BSI-certified TR-ESOR technology, a seamless integrity pipeline is created—modular, scalable, and from a single source. “In this way, timeproof consistently complements our mission at the DMI Group: not only to make data available, but also to ensure its trustworthiness and sovereign usability in the long term.”

Why Hospitals Choose Timeproof
  • Meets key NIS2 requirements—such as traceability, risk management, and cyber resilience—with a solution that covers the entire lifecycle of digital information
  • Protects patient and company data from tampering and ensures that changes are traceable and verifiable at all times.
  • Simplifies audits, certifications, and compliance documentation through audit-proof timestamps, preservation of evidence, and long-term archiving.
  • Ensures the ability to act in the event of a crisis, because digital records, minutes, and documents remain reliably available and verifiable even in the long term.
  • Builds trust with regulatory authorities, partners, and management, as the solutions are based on recognized standards such as eIDAS, TR-ESOR, RFC 3161, and RFC 4998.

XQT: The Strategic Foundation for Confident, Resilient, and Cost-Effective Hospital Digitalization

Health data forms the foundation for sound decision-making, connected care, and responsible innovation. To realize its full value, it must remain trustworthy, interoperable, and sustainable throughout its entire lifecycle. This is precisely what XQT stands for—the DMI GROUP’s brand for data sovereignty. As part of the DMI GROUP, timeproof contributes its expertise to the XQT brand’s solution portfolio. Together with DMI, Health-Comm, gefyra, and the XQT Innovation Members, it combines proven expertise into a strong, comprehensive offering—for secure processes, well-informed decisions, and a future-proof healthcare system.

Would you like to learn more about timeproof?

We look forward to hearing from you.