Security & Compliance
Jaapi AB is ISO 27001:2022 certified. We protect customer data with enterprise-grade security controls, EU data residency, and continuous compliance monitoring.
View Trust CenterOur ISO 27001:2022 certification
Jaapi AB was certified against ISO/IEC 27001:2022 in February 2026 after an independent audit by Guardian Assessment Pvt. Ltd. The certification covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise.
How we protect customer data
Encryption
All traffic is encrypted in transit with TLS 1.3 and all databases are encrypted at rest. Payment tokens are the only payment data we hold — card numbers never touch our systems.
EU data residency
All customer data is stored in the European Union (Frankfurt, Germany) with cross-region backup replication inside the EU. Jaapi AB is a Swedish company subject to GDPR.
Data minimization
We store only what the service needs: user accounts, orders, and shipping addresses. We never store credit card numbers, government IDs, health data, or financial account information.
Access control
Role-based access with least-privilege defaults, enterprise SSO (SAML 2.0, OpenID Connect), automatic session expiration, and regular access reviews.
Backups & resilience
Daily automated database backups with 30-day retention and cross-region replication, on serverless infrastructure with automatic failover and a 99.99% uptime SLA.
Monitoring & audit trails
Every request is logged, security-relevant actions are written to a dedicated audit trail, and real-time alerts flag failed authentication and configuration changes.
Sub-processors
These vendors process personal data on our behalf as part of delivering our services. The complete vendor register, including vendors without access to personal data, is published in our Trust Center.
| Vendor | Purpose | Location | Data processed |
|---|---|---|---|
| AWS | Database hosting (RDS PostgreSQL) | EU (Frankfurt) | Customer data, order data, user accounts, audit logs |
| Google Workspace | Identity provider, email, document collaboration, calendar, SSO authentication | EU | Employee PII, email communications, business documents (may contain customer PII), authentication credentials |
| Juni | Business banking, corporate card, expense management | EU (Sweden) | Sales transactions from Stripe, purchase receipts with customer shipping addresses |
| MailerSend | Transactional email delivery | EU (Belgium) | Email addresses, email content |
| Slack | Team communication, alerts | US | Internal communications (may contain customer PII from support discussions) |
| Stripe | Payment processing | EU (Ireland) | Payment card data (tokenized), billing addresses, transaction history |
| Vercel | Application hosting, DNS, cron jobs | EU (Frankfurt) | Environment variables, serverless function logs, application code, transient request data |
Security FAQs
Is Jaapi ISO 27001 certified? +
Yes. Jaapi AB holds ISO/IEC 27001:2022 certification, independently audited by Guardian Assessment Pvt. Ltd. (Certificate 55960GAI20260202SWEIS1P1, valid February 2, 2026 to February 1, 2029). The scope covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise. The certificate can be verified on IAF CertSearch.
Where is customer data stored? +
All customer data is stored in the European Union, primarily in Frankfurt, Germany, with encrypted backups replicated to a second EU region. We are an EU-based company (Jaapi AB, Sweden) and maintain EU data residency as part of our GDPR compliance commitment.
How does Jaapi handle payment information? +
Jaapi never stores credit card numbers or payment details. All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. Card details never touch our systems—we only store encrypted payment tokens.
What security certifications does Jaapi have? +
Jaapi holds ISO/IEC 27001:2022 certification, the international standard for information security management. We are also GDPR compliant as an EU-based company with EU data hosting. Our infrastructure providers (hosting, database, payments) maintain SOC 2 Type II and PCI DSS certifications.
Which sub-processors does Jaapi use? +
Jaapi uses 7 sub-processors that handle personal data on our behalf: AWS, Google Workspace, Juni, MailerSend, Slack, Stripe, Vercel. The full list with purpose, location, and data stored is published on this page, and the complete vendor register is available at trust.jaapi.com/vendors. A Data Processing Agreement (DPA) is available on request.
Can I review Jaapi's security controls? +
Yes. This page summarizes our key controls and sub-processors, and our Trust Center at trust.jaapi.com provides detailed information about our ISO 27001 controls, policies, and compliance documentation. For security questionnaires, vendor assessments, or audit requests, contact lynn@jaapi.store.
Does Jaapi support SSO? +
Yes. Jaapi supports enterprise Single Sign-On via SAML 2.0, OpenID Connect, and social authentication (Google, Microsoft). SSO is available on all plans and can be configured by your organization's IT administrator.
Ready to send your global team swag they actually want?
Book a demo and we'll show you a store your team will actually be excited about. Quality branded items, made on demand, delivered locally. No warehouse, no customs drama.
Get a demo