Security Summary

Jaapi AB operates an ISO 27001:2022 certified information security management system. Our security approach combines minimal data collection, certified cloud infrastructure, and independently audited controls.

Certification: ISO 27001:2022 (valid February 2026 – February 2029)
Data Location: EU by default, per-store region
Security Contact: lynn@jaapi.store
Last Updated: August 5, 2026

Product Security

Jaapi is a multi-tenant platform serving a branded store per customer. Access control and tenant isolation are enforced at the data layer, and every store runs the same independently audited codebase.

Authentication

  • Passwordless sign-in via expiring email links
  • SSO with Google Workspace and Microsoft Entra ID
  • SAML 2.0 for enterprise identity providers
  • No passwords stored — nothing to leak or crack
  • Sessions expire automatically

Access Control

  • Role-based access (user, admin, auditor)
  • Tenant isolation enforced on every query
  • Administrative actions recorded in an audit trail
  • Least-privilege access with regular access reviews

User Provisioning

  • SCIM 2.0 provisioning and deprovisioning
  • Self-service API tokens, revocable at any time
  • Automatic offboarding when users are deprovisioned

Data Minimization

We store only what the service needs — accounts, orders, and shipping addresses. We never store:

  • Credit card numbers or payment details
  • Government IDs or social security numbers
  • Health, biometric, or financial account data

Infrastructure & Encryption

All production systems run on certified cloud infrastructure. Each store has one home region: the European Union by default, or the United States for companies whose employees are mostly there. Customers who require EU-only hosting get it as a contractual commitment. We operate no physical servers of our own for customer data.

Hosting

  • Application & database, EU stores: Frankfurt & Nuremberg, Germany (Vercel, AWS, Hetzner)
  • Application & database, US stores: Ashburn, Virginia (Hetzner)
  • CDN assets: Hetzner (Falkenstein, Germany)
  • Backups: stored in the EU for all regions
  • Providers hold SOC 2 Type II and ISO 27001 certifications

Encryption

  • TLS 1.3 encryption in transit, HTTPS-only
  • Database and backups encrypted at rest
  • Content Security Policy headers
  • Secrets managed via the hosting platform, never in code

Operational Security

Monitoring & Logging

  • Every request logged, retained for 30 days
  • Real-time alerting on failures and anomalies
  • Failed authentication tracking
  • Audit trail of privilege and configuration changes

Backup & Recovery

  • Daily automated database backups, 30-day retention
  • Cross-region replication to a second EU region
  • Restore procedures tested periodically on real backups

Change Management

  • All changes version-controlled and reviewed
  • Automated type checks, linting, and tests before deploy
  • Staged rollout: changes run on internal stores before reaching customer stores

Incident Response

  • Documented incident response procedures
  • 72-hour breach notification in line with GDPR
  • Incidents tracked, documented, and reviewed

Payments

Card data never touches Jaapi systems. All payment processing is handled by Stripe (PCI DSS Level 1, the highest level of payment industry certification); we store only tokenized payment references.

Reporting a Vulnerability

If you believe you have found a security vulnerability in a Jaapi service, please report it to lynn@jaapi.store. We investigate all reports promptly and will keep you informed of our progress. We ask that you give us reasonable time to remediate before any public disclosure.

Security Reviews & Documentation

Our ISO 27001 certificate is available on the trust center overview. Security policies and audit evidence are available to customers and their auditors on request. For vendor security questionnaires, risk assessments, or additional documentation:

lynn@jaapi.store