Security Summary

Jaapi AB operates an ISO 27001:2022 certified information security management system. Our security approach combines minimal data collection, certified cloud infrastructure, and independently audited controls.

Certification: ISO 27001:2022 (valid February 2026 – February 2029)
Data Location: EU by default, per-store region
Security Contact: lynn@jaapi.store
Last Updated: September 6, 2026

Product Security

Jaapi is a multi-tenant platform serving a branded store per customer. Access control and tenant isolation are enforced at the data layer, and every store runs the same independently audited codebase.

Authentication

  • Passwordless sign-in via expiring email links
  • SSO with Google Workspace and Microsoft Entra ID
  • SAML 2.0 for enterprise identity providers
  • No passwords stored — nothing to leak or crack
  • Sessions expire automatically

Access Control

  • Role-based access (user, admin, auditor)
  • Tenant isolation enforced on every query
  • Administrative actions recorded in an audit trail
  • Least-privilege access with regular access reviews

User Provisioning

  • SCIM 2.0 provisioning and deprovisioning
  • Self-service API tokens, revocable at any time
  • Automatic offboarding when users are deprovisioned

Data Minimization

We store only what the service needs — accounts, orders, and shipping addresses. We never store:

  • Credit card numbers or payment details
  • Government IDs or social security numbers
  • Health, biometric, or financial account data

Infrastructure & Encryption

All production systems run on certified cloud infrastructure. Each store has one home region: the European Union by default, or the United States for companies whose employees are mostly there. Customers who require EU-only hosting get it as a contractual commitment. We operate no physical servers of our own for customer data.

Hosting

  • Application & database, EU stores: Nuremberg, Germany (Hetzner)
  • Application & database, US stores: Ashburn, Virginia (Hetzner)
  • CDN assets: Hetzner (Falkenstein, Germany)
  • Backups: stored in the EU for all regions
  • Hetzner data centres are ISO 27001 certified

Encryption

  • TLS 1.2 or newer in transit, HTTPS-only
  • Backups and secrets encrypted at rest; each database reachable only from its own server
  • Content Security Policy headers
  • Secrets encrypted, never in plain text in code or on a laptop

Operational Security

Monitoring & Logging

  • Every request the application serves is logged, retained 30 days
  • Alerting on application errors and failed background jobs, to both founders
  • Failed authentication tracking
  • Audit trail of privilege and configuration changes

Backup & Recovery

  • Daily automated encrypted database backups, 30-day retention; monthly archives of durable records kept 24 months
  • Backups stored encrypted at a separate EU facility
  • Restore procedures tested weekly on real backups

Change Management

  • Every change is version-controlled
  • Type checks, lint and tests run before a commit; an automated review runs when the change warrants it
  • Nothing deploys on commit: a founder deploys explicitly, the build is checked before it is switched in, and every release is kept so a change can be reversed

Incident Response

  • Documented incident response procedures
  • Breach notification to affected customers within 48 hours, so they can meet their GDPR deadline
  • Incidents tracked, documented, and reviewed

Payments

Card data never touches Jaapi systems. All payment processing is handled by Stripe (PCI DSS Level 1, the highest level of payment industry certification); we store only tokenized payment references.

Reporting a Vulnerability

If you believe you have found a security vulnerability in a Jaapi service, please report it to lynn@jaapi.store. We investigate all reports promptly and will keep you informed of our progress. We ask that you give us reasonable time to remediate before any public disclosure.

Security Reviews & Documentation

Our ISO 27001 certificate is available on the trust center overview. Security policies and audit evidence are available to customers and their auditors on request. For vendor security questionnaires, risk assessments, or additional documentation:

lynn@jaapi.store