Security Summary
Jaapi AB operates an ISO 27001:2022 certified information security management system. Our security approach combines minimal data collection, certified cloud infrastructure, and independently audited controls.
Product Security
Jaapi is a multi-tenant platform serving a branded store per customer. Access control and tenant isolation are enforced at the data layer, and every store runs the same independently audited codebase.
Authentication
- Passwordless sign-in via expiring email links
- SSO with Google Workspace and Microsoft Entra ID
- SAML 2.0 for enterprise identity providers
- No passwords stored — nothing to leak or crack
- Sessions expire automatically
Access Control
- Role-based access (user, admin, auditor)
- Tenant isolation enforced on every query
- Administrative actions recorded in an audit trail
- Least-privilege access with regular access reviews
User Provisioning
- SCIM 2.0 provisioning and deprovisioning
- Self-service API tokens, revocable at any time
- Automatic offboarding when users are deprovisioned
Data Minimization
We store only what the service needs — accounts, orders, and shipping addresses. We never store:
- Credit card numbers or payment details
- Government IDs or social security numbers
- Health, biometric, or financial account data
Infrastructure & Encryption
All production systems run on certified cloud infrastructure. Each store has one home region: the European Union by default, or the United States for companies whose employees are mostly there. Customers who require EU-only hosting get it as a contractual commitment. We operate no physical servers of our own for customer data.
Hosting
- Application & database, EU stores: Frankfurt & Nuremberg, Germany (Vercel, AWS, Hetzner)
- Application & database, US stores: Ashburn, Virginia (Hetzner)
- CDN assets: Hetzner (Falkenstein, Germany)
- Backups: stored in the EU for all regions
- Providers hold SOC 2 Type II and ISO 27001 certifications
Encryption
- TLS 1.3 encryption in transit, HTTPS-only
- Database and backups encrypted at rest
- Content Security Policy headers
- Secrets managed via the hosting platform, never in code
Operational Security
Monitoring & Logging
- Every request logged, retained for 30 days
- Real-time alerting on failures and anomalies
- Failed authentication tracking
- Audit trail of privilege and configuration changes
Backup & Recovery
- Daily automated database backups, 30-day retention
- Cross-region replication to a second EU region
- Restore procedures tested periodically on real backups
Change Management
- All changes version-controlled and reviewed
- Automated type checks, linting, and tests before deploy
- Staged rollout: changes run on internal stores before reaching customer stores
Incident Response
- Documented incident response procedures
- 72-hour breach notification in line with GDPR
- Incidents tracked, documented, and reviewed
Payments
Card data never touches Jaapi systems. All payment processing is handled by Stripe (PCI DSS Level 1, the highest level of payment industry certification); we store only tokenized payment references.
Reporting a Vulnerability
If you believe you have found a security vulnerability in a Jaapi service, please report it to lynn@jaapi.store. We investigate all reports promptly and will keep you informed of our progress. We ask that you give us reasonable time to remediate before any public disclosure.
Security Reviews & Documentation
Our ISO 27001 certificate is available on the trust center overview. Security policies and audit evidence are available to customers and their auditors on request. For vendor security questionnaires, risk assessments, or additional documentation: