Security & Compliance
Jaapi AB is ISO 27001:2022 certified. We protect customer data with minimal data collection, certified hosting in the EU by default, and independently audited controls.
View Trust CenterOur ISO 27001:2022 certification
Jaapi AB was certified against ISO/IEC 27001:2022 in February 2026 after an independent audit by Guardian Assessment Pvt. Ltd. The certification covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise.
How we protect customer data
Encryption
Every connection is encrypted with TLS 1.2 or newer, HTTPS only. Backups and secrets are encrypted at rest, and each database is reachable only from its own server. Card numbers never touch our systems: Stripe holds them and we keep a payment token.
Data location
Each store has one home region: Nuremberg, Germany by default, or Ashburn, Virginia for companies whose employees are mostly in the US. Backups for every store are stored encrypted in the EU. Customers who require EU-only hosting get it as a contractual commitment.
Data minimization
We store only what the service needs: user accounts, orders, and shipping addresses. We never store credit card numbers, government IDs, health data, or financial account information.
Access control
Passwordless sign-in by email link, Google Workspace or Microsoft Entra ID, or SAML 2.0 for enterprise identity providers. Role-based access, tenant isolation on every query, sessions that expire, and regular access reviews.
Backups & recovery
Daily encrypted database backups kept 30 days, monthly archives kept 24 months, and a restore drill every week on real backups. An external monitor checks each region from several places and feeds every store's status page.
Logging & audit trails
Every request is logged and kept 30 days. Sign-ins, privilege and configuration changes, and every movement of credit are written to an audit trail. Application errors and failed background jobs alert both founders.
Sub-processors
These vendors process personal data on our behalf as part of delivering our services. The complete vendor register, including vendors without access to personal data, is published in our Trust Center.
| Vendor | Purpose | Location | Data processed |
|---|---|---|---|
| Cloudflare | CDN caching for jaapi.co domain | US | Cached images, and each visitor's IP address in the edge request logs |
| Google Workspace | Identity provider, email, document collaboration, calendar, SSO authentication | EU | Employee PII, email communications, business documents (may contain customer PII), authentication credentials |
| Hetzner | Store platform hosting (application servers and PostgreSQL databases per region), database backups, CDN origin server | EU (Germany), US | All store data - user accounts, orders, shipping addresses, credit balances, support tickets, product images, database backups |
| MailerSend | Transactional email delivery | EU (Belgium) | Email addresses, email content |
| Slack | Team communication, alerts | US | Internal communications (may contain customer PII from support discussions) |
| Stripe | Payment processing | EU (Ireland) | Payment card data (tokenized), billing addresses, transaction history |
| Vercel | DNS and domain registrar, marketing website hosting (jaapi.com), edge proxy for stores served on customer-owned domains that still point at it | US | DNS records, marketing website code; store traffic in transit (sign-ins, orders, addresses) for customer-owned store domains not yet repointed to Jaapi's edge, not stored |
Security FAQs
Is Jaapi ISO 27001 certified? +
Yes. Jaapi AB holds ISO/IEC 27001:2022 certification, independently audited by Guardian Assessment Pvt. Ltd. (Certificate 55960GAI20260202SWEIS1P1, valid February 2, 2026 to February 1, 2029). The scope covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise. The certificate can be verified on IAF CertSearch.
Where is customer data stored? +
Each store has one home region. Stores are hosted in the EU (Nuremberg, Germany) unless the customer chooses US hosting (Ashburn, Virginia). Backups for every store are stored encrypted in the EU, and store data is hosted in its home region; only a supplier's shipment notices and support reads may briefly be processed in the other. A customer that requires EU-only hosting gets it as a contractual commitment. Jaapi AB is a Swedish company under the GDPR.
How does Jaapi handle payment information? +
Jaapi never stores credit card numbers or payment details. All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. Card details never touch our systems; we store only tokenized payment references.
What security certifications does Jaapi have? +
Jaapi holds ISO/IEC 27001:2022 certification, the international standard for information security management, rather than a separate SOC 2 report; most security reviews accept it in place of one. Jaapi AB is a Swedish company under the GDPR. Our hosting provider Hetzner is ISO 27001 certified, and Stripe, our payment processor, is SOC 2 Type II audited and PCI DSS Level 1 certified.
Which sub-processors does Jaapi use? +
Jaapi uses 7 sub-processors that handle personal data on our behalf: Cloudflare, Google Workspace, Hetzner, MailerSend, Slack, Stripe, Vercel. The full list with purpose, location, and data stored is published on this page, and the complete vendor register is available at trust.jaapi.com/vendors. Our Data Processing Agreement (DPA) is published at trust.jaapi.com/dpa and forms part of our Terms of Service.
Can I review Jaapi's security controls? +
Yes. This page summarizes our key controls and sub-processors, and our Trust Center at trust.jaapi.com provides detailed information about our ISO 27001 controls, policies, and compliance documentation. For security questionnaires, vendor assessments, or audit requests, contact lynn@jaapi.store.
Does Jaapi support SSO? +
Yes. Sign-in is passwordless: an expiring email link, Google Workspace, Microsoft Entra ID, or SAML 2.0 for your organization's own identity provider. SSO is available on all plans and is configured by your IT administrator, and SCIM 2.0 provisioning keeps the user list in step with your directory.
Ready to send your global team swag they actually want?
Book a demo and we'll show you a store your team will actually be excited about. Quality branded items, made on demand, delivered locally. No warehouse, no customs drama.
Get a demo