Skip to main content
Jaapi
ISO 27001:2022 Certified

Security & Compliance

Jaapi AB is ISO 27001:2022 certified. We protect customer data with minimal data collection, certified hosting in the EU by default, and independently audited controls.

View Trust Center

Our ISO 27001:2022 certification

Jaapi AB was certified against ISO/IEC 27001:2022 in February 2026 after an independent audit by Guardian Assessment Pvt. Ltd. The certification covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise.

Jaapi ISO 27001:2022 certificate issued by Guardian Assessment
Certificate number
55960GAI20260202SWEIS1P1
Validity
February 2, 2026 – February 1, 2029
Certification body
Guardian Assessment Pvt. Ltd.

How we protect customer data

Encryption

Every connection is encrypted with TLS 1.2 or newer, HTTPS only. Backups and secrets are encrypted at rest, and each database is reachable only from its own server. Card numbers never touch our systems: Stripe holds them and we keep a payment token.

Data location

Each store has one home region: Nuremberg, Germany by default, or Ashburn, Virginia for companies whose employees are mostly in the US. Backups for every store are stored encrypted in the EU. Customers who require EU-only hosting get it as a contractual commitment.

Data minimization

We store only what the service needs: user accounts, orders, and shipping addresses. We never store credit card numbers, government IDs, health data, or financial account information.

Access control

Passwordless sign-in by email link, Google Workspace or Microsoft Entra ID, or SAML 2.0 for enterprise identity providers. Role-based access, tenant isolation on every query, sessions that expire, and regular access reviews.

Backups & recovery

Daily encrypted database backups kept 30 days, monthly archives kept 24 months, and a restore drill every week on real backups. An external monitor checks each region from several places and feeds every store's status page.

Logging & audit trails

Every request is logged and kept 30 days. Sign-ins, privilege and configuration changes, and every movement of credit are written to an audit trail. Application errors and failed background jobs alert both founders.

Sub-processors

These vendors process personal data on our behalf as part of delivering our services. The complete vendor register, including vendors without access to personal data, is published in our Trust Center.

Vendor Purpose Location Data processed
Cloudflare CDN caching for jaapi.co domain US Cached images, and each visitor's IP address in the edge request logs
Google Workspace Identity provider, email, document collaboration, calendar, SSO authentication EU Employee PII, email communications, business documents (may contain customer PII), authentication credentials
Hetzner Store platform hosting (application servers and PostgreSQL databases per region), database backups, CDN origin server EU (Germany), US All store data - user accounts, orders, shipping addresses, credit balances, support tickets, product images, database backups
MailerSend Transactional email delivery EU (Belgium) Email addresses, email content
Slack Team communication, alerts US Internal communications (may contain customer PII from support discussions)
Stripe Payment processing EU (Ireland) Payment card data (tokenized), billing addresses, transaction history
Vercel DNS and domain registrar, marketing website hosting (jaapi.com), edge proxy for stores served on customer-owned domains that still point at it US DNS records, marketing website code; store traffic in transit (sign-ins, orders, addresses) for customer-owned store domains not yet repointed to Jaapi's edge, not stored

Security FAQs

Is Jaapi ISO 27001 certified? +

Yes. Jaapi AB holds ISO/IEC 27001:2022 certification, independently audited by Guardian Assessment Pvt. Ltd. (Certificate 55960GAI20260202SWEIS1P1, valid February 2, 2026 to February 1, 2029). The scope covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise. The certificate can be verified on IAF CertSearch.

Where is customer data stored? +

Each store has one home region. Stores are hosted in the EU (Nuremberg, Germany) unless the customer chooses US hosting (Ashburn, Virginia). Backups for every store are stored encrypted in the EU, and store data is hosted in its home region; only a supplier's shipment notices and support reads may briefly be processed in the other. A customer that requires EU-only hosting gets it as a contractual commitment. Jaapi AB is a Swedish company under the GDPR.

How does Jaapi handle payment information? +

Jaapi never stores credit card numbers or payment details. All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. Card details never touch our systems; we store only tokenized payment references.

What security certifications does Jaapi have? +

Jaapi holds ISO/IEC 27001:2022 certification, the international standard for information security management, rather than a separate SOC 2 report; most security reviews accept it in place of one. Jaapi AB is a Swedish company under the GDPR. Our hosting provider Hetzner is ISO 27001 certified, and Stripe, our payment processor, is SOC 2 Type II audited and PCI DSS Level 1 certified.

Which sub-processors does Jaapi use? +

Jaapi uses 7 sub-processors that handle personal data on our behalf: Cloudflare, Google Workspace, Hetzner, MailerSend, Slack, Stripe, Vercel. The full list with purpose, location, and data stored is published on this page, and the complete vendor register is available at trust.jaapi.com/vendors. Our Data Processing Agreement (DPA) is published at trust.jaapi.com/dpa and forms part of our Terms of Service.

Can I review Jaapi's security controls? +

Yes. This page summarizes our key controls and sub-processors, and our Trust Center at trust.jaapi.com provides detailed information about our ISO 27001 controls, policies, and compliance documentation. For security questionnaires, vendor assessments, or audit requests, contact lynn@jaapi.store.

Does Jaapi support SSO? +

Yes. Sign-in is passwordless: an expiring email link, Google Workspace, Microsoft Entra ID, or SAML 2.0 for your organization's own identity provider. SSO is available on all plans and is configured by your IT administrator, and SCIM 2.0 provisioning keeps the user list in step with your directory.

Custom branded tumblers

Ready to send your global team swag they actually want?

Book a demo and we'll show you a store your team will actually be excited about. Quality branded items, made on demand, delivered locally. No warehouse, no customs drama.

Get a demo