Jaapi AB operates an ISO 27001:2022 certified information security
management system. Our security approach combines minimal data
collection, certified cloud infrastructure, and independently audited
controls.
Certification: ISO 27001:2022 (valid February 2026 –
February 2029)
Jaapi is a multi-tenant platform serving a branded store per customer.
Access control and tenant isolation are enforced at the data layer, and
every store runs the same independently audited codebase.
Authentication
Passwordless sign-in via expiring email links
SSO with Google Workspace and Microsoft Entra ID
SAML 2.0 for enterprise identity providers
No passwords stored — nothing to leak or crack
Sessions expire automatically
Access Control
Role-based access (user, admin, auditor)
Tenant isolation enforced on every query
Administrative actions recorded in an audit trail
Least-privilege access with regular access reviews
User Provisioning
SCIM 2.0 provisioning and deprovisioning
Self-service API tokens, revocable at any time
Automatic offboarding when users are deprovisioned
Data Minimization
We store only what the service needs — accounts, orders, and shipping
addresses. We never store:
Credit card numbers or payment details
Government IDs or social security numbers
Health, biometric, or financial account data
Infrastructure & Encryption
All production systems run on certified cloud infrastructure. Each store
has one home region: the European Union by default, or the United States
for companies whose employees are mostly there. Customers who require
EU-only hosting get it as a contractual commitment. We operate no
physical servers of our own for customer data.
Hosting
Application & database, EU stores: Nuremberg, Germany
(Hetzner)
Application & database, US stores: Ashburn, Virginia (Hetzner)
CDN assets: Hetzner (Falkenstein, Germany)
Backups: stored in the EU for all regions
Hetzner data centres are ISO 27001 certified
Encryption
TLS 1.2 or newer in transit, HTTPS-only
Backups and secrets encrypted at rest; each database reachable only from its own server
Content Security Policy headers
Secrets encrypted, never in plain text in code or on a laptop
Operational Security
Monitoring & Logging
Every request the application serves is logged, retained 30 days
Alerting on application errors and failed background jobs, to both founders
Failed authentication tracking
Audit trail of privilege and configuration changes
Backup & Recovery
Daily automated encrypted database backups, 30-day retention;
monthly archives of durable records kept 24 months
Backups stored encrypted at a separate EU facility
Restore procedures tested weekly on real backups
Change Management
Every change is version-controlled
Type checks, lint and tests run before a commit; an automated
review runs when the change warrants it
Nothing deploys on commit: a founder deploys explicitly, the build
is checked before it is switched in, and every release is kept so
a change can be reversed
Incident Response
Documented incident response procedures
Breach notification to affected customers within 48 hours, so they can meet their GDPR deadline
Incidents tracked, documented, and reviewed
Payments
Card data never touches Jaapi systems. All payment processing is
handled by Stripe (PCI DSS Level 1, the highest level of payment
industry certification); we store only tokenized payment references.
Reporting a Vulnerability
If you believe you have found a security vulnerability in a Jaapi
service, please report it to lynn@jaapi.store. We investigate
all reports promptly and will keep you informed of our progress. We ask
that you give us reasonable time to remediate before any public
disclosure.
Security Reviews & Documentation
Our ISO 27001 certificate is available on the trust center overview. Security policies and audit
evidence are available to customers and their auditors on request. For
vendor security questionnaires, risk assessments, or additional
documentation: