Security

Trust starts with clear controls

Product and supplier data needs defined access, traceable change and honest communication about what the platform protects.

Tenant separation

Organisation context is checked for protected application and API operations.

Controlled access

Roles, scoped supplier links, API credentials and managed sessions reduce unnecessary access.

Traceable change

Compliance-relevant operations write to an organisation-specific audit trail.

EU hosting

The production database and application hosting are configured in European regions.

Credential protection

Passwords are handled by the authentication system, API keys are stored as hashes and passkeys are supported.

Data lifecycle

Export, deletion and pseudonymisation workflows support accountable handling of personal and product data.

What we do not claim

Passvanta is not an authority, notified body or certification service. The platform supports evidence and regulatory readiness, while legal assessment and formal approval remain with the responsible organisation and its advisers.

Report a security concern

If you believe you have found a vulnerability, send the details without including unnecessary personal or confidential production data.

Email security contact

Privacy and legal information

Our privacy notice, processing terms and other legal documents explain responsibilities and data handling in more detail.

View legal documents

FAQ

Security and responsibility

Where is production hosted?

The production application and database are configured in European regions. Specific contractual and procurement details can be discussed before rollout.

Does Passvanta store plain API keys?

No. API-key secrets are shown when created and stored as hashes for later verification. Revocation remains available to authorised workspace users.

Who approves compliance-relevant data?

Authorised people in the customer organisation review evidence and approve values. Platform automation does not replace their responsibility or external legal advice.

Discuss your security requirements

Tell us about your access, hosting and procurement requirements before rollout.