Skip to main content
Jaapi
ISO 27001:2022 Certified

Security & Compliance

Jaapi AB is ISO 27001:2022 certified. We protect customer data with enterprise-grade security controls, EU data residency, and continuous compliance monitoring.

View Trust Center

Our ISO 27001:2022 certification

Jaapi AB was certified against ISO/IEC 27001:2022 in February 2026 after an independent audit by Guardian Assessment Pvt. Ltd. The certification covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise.

Jaapi ISO 27001:2022 certificate issued by Guardian Assessment
Certificate number
55960GAI20260202SWEIS1P1
Validity
February 2, 2026 – February 1, 2029
Certification body
Guardian Assessment Pvt. Ltd.

How we protect customer data

Encryption

All traffic is encrypted in transit with TLS 1.3 and all databases are encrypted at rest. Payment tokens are the only payment data we hold — card numbers never touch our systems.

EU data residency

All customer data is stored in the European Union (Frankfurt, Germany) with cross-region backup replication inside the EU. Jaapi AB is a Swedish company subject to GDPR.

Data minimization

We store only what the service needs: user accounts, orders, and shipping addresses. We never store credit card numbers, government IDs, health data, or financial account information.

Access control

Role-based access with least-privilege defaults, enterprise SSO (SAML 2.0, OpenID Connect), automatic session expiration, and regular access reviews.

Backups & resilience

Daily automated database backups with 30-day retention and cross-region replication, on serverless infrastructure with automatic failover and a 99.99% uptime SLA.

Monitoring & audit trails

Every request is logged, security-relevant actions are written to a dedicated audit trail, and real-time alerts flag failed authentication and configuration changes.

Sub-processors

These vendors process personal data on our behalf as part of delivering our services. The complete vendor register, including vendors without access to personal data, is published in our Trust Center.

Vendor Purpose Location Data processed
AWS Database hosting (RDS PostgreSQL) EU (Frankfurt) Customer data, order data, user accounts, audit logs
Google Workspace Identity provider, email, document collaboration, calendar, SSO authentication EU Employee PII, email communications, business documents (may contain customer PII), authentication credentials
Juni Business banking, corporate card, expense management EU (Sweden) Sales transactions from Stripe, purchase receipts with customer shipping addresses
MailerSend Transactional email delivery EU (Belgium) Email addresses, email content
Slack Team communication, alerts US Internal communications (may contain customer PII from support discussions)
Stripe Payment processing EU (Ireland) Payment card data (tokenized), billing addresses, transaction history
Vercel Application hosting, DNS, cron jobs EU (Frankfurt) Environment variables, serverless function logs, application code, transient request data

Security FAQs

Is Jaapi ISO 27001 certified? +

Yes. Jaapi AB holds ISO/IEC 27001:2022 certification, independently audited by Guardian Assessment Pvt. Ltd. (Certificate 55960GAI20260202SWEIS1P1, valid February 2, 2026 to February 1, 2029). The scope covers the development and operation of our B2B SaaS platform for on-demand corporate branded merchandise. The certificate can be verified on IAF CertSearch.

Where is customer data stored? +

All customer data is stored in the European Union, primarily in Frankfurt, Germany, with encrypted backups replicated to a second EU region. We are an EU-based company (Jaapi AB, Sweden) and maintain EU data residency as part of our GDPR compliance commitment.

How does Jaapi handle payment information? +

Jaapi never stores credit card numbers or payment details. All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. Card details never touch our systems—we only store encrypted payment tokens.

What security certifications does Jaapi have? +

Jaapi holds ISO/IEC 27001:2022 certification, the international standard for information security management. We are also GDPR compliant as an EU-based company with EU data hosting. Our infrastructure providers (hosting, database, payments) maintain SOC 2 Type II and PCI DSS certifications.

Which sub-processors does Jaapi use? +

Jaapi uses 7 sub-processors that handle personal data on our behalf: AWS, Google Workspace, Juni, MailerSend, Slack, Stripe, Vercel. The full list with purpose, location, and data stored is published on this page, and the complete vendor register is available at trust.jaapi.com/vendors. A Data Processing Agreement (DPA) is available on request.

Can I review Jaapi's security controls? +

Yes. This page summarizes our key controls and sub-processors, and our Trust Center at trust.jaapi.com provides detailed information about our ISO 27001 controls, policies, and compliance documentation. For security questionnaires, vendor assessments, or audit requests, contact lynn@jaapi.store.

Does Jaapi support SSO? +

Yes. Jaapi supports enterprise Single Sign-On via SAML 2.0, OpenID Connect, and social authentication (Google, Microsoft). SSO is available on all plans and can be configured by your organization's IT administrator.

Custom branded tumblers

Ready to send your global team swag they actually want?

Book a demo and we'll show you a store your team will actually be excited about. Quality branded items, made on demand, delivered locally. No warehouse, no customs drama.

Get a demo