Tenant separation
Organisation context is checked for protected application and API operations.
Security
Product and supplier data needs defined access, traceable change and honest communication about what the platform protects.
Organisation context is checked for protected application and API operations.
Roles, scoped supplier links, API credentials and managed sessions reduce unnecessary access.
Compliance-relevant operations write to an organisation-specific audit trail.
The production database and application hosting are configured in European regions.
Passwords are handled by the authentication system, API keys are stored as hashes and passkeys are supported.
Export, deletion and pseudonymisation workflows support accountable handling of personal and product data.
Passvanta is not an authority, notified body or certification service. The platform supports evidence and regulatory readiness, while legal assessment and formal approval remain with the responsible organisation and its advisers.
If you believe you have found a vulnerability, send the details without including unnecessary personal or confidential production data.
Email security contactOur privacy notice, processing terms and other legal documents explain responsibilities and data handling in more detail.
View legal documentsFAQ
The production application and database are configured in European regions. Specific contractual and procurement details can be discussed before rollout.
No. API-key secrets are shown when created and stored as hashes for later verification. Revocation remains available to authorised workspace users.
Authorised people in the customer organisation review evidence and approve values. Platform automation does not replace their responsibility or external legal advice.
Tell us about your access, hosting and procurement requirements before rollout.