> ## Documentation Index
> Fetch the complete documentation index at: https://docs.passy.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

## Our Security Commitment

At Passy, security and compliance are not afterthoughts—they're fundamental to everything we build. We understand that you're trusting us with sensitive data and critical infrastructure, and we take that responsibility seriously.

## Infrastructure Security

### EU-Hosted Infrastructure

All Passy infrastructure is hosted exclusively in the European Union:

* **Primary Location**: Netherlands 🇳🇱
* **Hosting Provider**: [bit.nl](https://bit.nl) - ISO27001 & NEN7510 certified
* **Data Residency**: All data remains within EU borders
* **No US Cloud Providers**: We don't use AWS, GCP, or Azure for primary infrastructure

### Certifications

Our infrastructure is certified with industry-leading security standards:

<CardGroup cols={2}>
  <Card title="ISO 27001" icon="certificate">
    **Information Security Management**

    Certified information security management system ensuring comprehensive protection of data assets.

    [View Certificate](https://www.bit.nl/app/uploads/2025/07/2025-06-24-DigiTrust-UK-Certificate-ISO-27001-BIT-B.V.pdf)
  </Card>

  <Card title="NEN 7510" icon="hospital">
    **Healthcare Information Security**

    Dutch healthcare information security standard, ensuring highest level of data protection.

    [View Certificate](https://www.bit.nl/app/uploads/2025/01/Certificaten-NEN7510-NL.pdf)
  </Card>

  <Card title="GDPR Compliant" icon="shield-halved">
    **EU Data Protection**

    Full compliance with EU General Data Protection Regulation, ensuring data privacy rights.
  </Card>

  <Card title="SOC 2 Type II" icon="file-shield">
    **Service Organization Control**

    Currently in progress - Expected Q2 2025
  </Card>
</CardGroup>

## Data Security

### Encryption

**Data in Transit**

* TLS 1.3 for all API communications
* Perfect Forward Secrecy (PFS)
* Strong cipher suites only
* HSTS enabled on all endpoints

**Data at Rest**

* AES-256 encryption for stored data
* Encrypted database backups
* Encrypted file systems
* Hardware security modules (HSM) for key management

### Data Privacy

<Warning>
  **We Do NOT**:

  * Store your API prompts or responses (beyond 24-hour caching)
  * Train AI models on your data
  * Share your data with third parties for training
  * Sell your personal information
  * Transfer data outside the EU
</Warning>

**What We Store**:

* Account information (email, name, billing details)
* API usage metadata (timestamps, model used, token counts)
* Error logs for debugging (30-day retention)
* Billing records (7-year retention for tax compliance)

### Access Controls

**Internal Access**

* Role-based access control (RBAC)
* Principle of least privilege
* Multi-factor authentication (MFA) required
* Regular access reviews
* Audit logging of all administrative actions

**Customer Access**

* API key-based authentication
* Optional IP whitelisting
* Per-key rate limiting
* Granular permission controls
* Team member access management

## Network Security

### Infrastructure Protection

* **DDoS Protection**: Multi-layer DDoS mitigation
* **Web Application Firewall (WAF)**: Protection against common attacks
* **Intrusion Detection**: 24/7 monitoring for suspicious activity
* **Network Segmentation**: Isolated environments for different services
* **Zero Trust Architecture**: Verify every request, trust nothing

### API Security

* **Rate Limiting**: Per-key and per-IP rate limits
* **Request Validation**: Strict input validation and sanitization
* **Authentication**: Bearer token authentication
* **Authorization**: Fine-grained access controls
* **Audit Logging**: Complete audit trail of API usage

## Compliance

### GDPR Compliance

We are fully compliant with the EU General Data Protection Regulation:

**Data Subject Rights**

* ✅ Right to access your data
* ✅ Right to rectification
* ✅ Right to erasure ("right to be forgotten")
* ✅ Right to data portability
* ✅ Right to restrict processing
* ✅ Right to object

**Data Processing**

* Lawful basis for all processing
* Data minimization principles
* Purpose limitation
* Storage limitation
* Integrity and confidentiality

**Data Protection Officer**\
Email: [privacy@passy.ai](mailto:privacy@passy.ai)\
Response time: Within 48 hours

### Industry-Specific Compliance

<Tabs>
  <Tab title="Healthcare (HIPAA)">
    **HIPAA Compliance Available**

    For healthcare applications, we offer:

    * Business Associate Agreement (BAA)
    * PHI encryption and access controls
    * Audit logging and monitoring
    * Breach notification procedures
    * Regular compliance audits

    **Contact**: [healthcare@passy.ai](mailto:healthcare@passy.ai) for BAA setup
  </Tab>

  <Tab title="Finance (PCI-DSS)">
    **Financial Services Compliance**

    For financial applications:

    * PCI-DSS Level 1 compliant infrastructure
    * Secure payment processing
    * Transaction logging and monitoring
    * Regular security assessments
    * Compliance documentation

    **Contact**: [finance@passy.ai](mailto:finance@passy.ai) for compliance details
  </Tab>

  <Tab title="Government">
    **Government & Public Sector**

    For government use cases:

    * EU data sovereignty
    * Enhanced security controls
    * Compliance documentation
    * On-premise deployment options
    * Dedicated support

    **Contact**: [government@passy.ai](mailto:government@passy.ai) for requirements
  </Tab>
</Tabs>

## Security Practices

### Development Security

**Secure Development Lifecycle**

* Security requirements in design phase
* Code review for all changes
* Static application security testing (SAST)
* Dynamic application security testing (DAST)
* Dependency scanning and updates
* Security-focused CI/CD pipeline

**Third-Party Dependencies**

* Regular vulnerability scanning
* Automated dependency updates
* License compliance checks
* Supply chain security

### Operational Security

**Monitoring & Alerting**

* 24/7 security monitoring
* Real-time threat detection
* Automated incident response
* Security information and event management (SIEM)
* Log aggregation and analysis

**Incident Response**

* Documented incident response plan
* Regular incident response drills
* 24/7 on-call security team
* Breach notification procedures
* Post-incident reviews

**Backup & Recovery**

* Automated daily backups
* Encrypted backup storage
* Regular recovery testing
* Geo-redundant backup locations (within EU)
* 99.9% data durability guarantee

## Penetration Testing

**Regular Security Assessments**

* Annual third-party penetration testing
* Quarterly internal security assessments
* Continuous vulnerability scanning
* Bug bounty program for responsible disclosure

**Bug Bounty Program**

* Rewards for security researchers
* Responsible disclosure policy
* Hall of fame for contributors
* Details at: [https://passy.ai/security](https://passy.ai/security)

## Vendor Security

### Third-Party Providers

We carefully vet all third-party providers:

**AI Model Providers**

* OpenAI (Azure) - SOC 2, ISO 27001
* Anthropic (AWS Bedrock) - SOC 2, ISO 27001
* Google (Vertex AI) - SOC 2, ISO 27001
* All providers GDPR compliant

**Infrastructure Providers**

* bit.nl - ISO 27001, NEN 7510
* Stripe (payments) - PCI-DSS Level 1
* All EU-based or GDPR compliant

### Data Processing Agreements

* Data Processing Agreements (DPA) with all vendors
* Regular vendor security assessments
* Contractual security requirements
* Right to audit vendors

## Security Transparency

### Security Updates

We believe in transparent security:

* **Status Page**: [https://status.passy.ai](https://status.passy.ai)
* **Security Advisories**: Published for all security incidents
* **Changelog**: All security updates documented
* **Incident Reports**: Post-mortem reports published

### Security Contact

**Report Security Issues**\
Email: [security@passy.ai](mailto:security@passy.ai)\
PGP Key: Available at [https://passy.ai/pgp](https://passy.ai/pgp)

**Response Time**

* Critical issues: Within 4 hours
* High severity: Within 24 hours
* Medium/Low: Within 72 hours

## Compliance Documentation

### Available Documentation

For enterprise customers, we provide:

* SOC 2 Type II report (when available)
* ISO 27001 certificate
* NEN 7510 certificate
* GDPR compliance documentation
* Data Processing Agreement (DPA)
* Business Associate Agreement (BAA)
* Security questionnaire responses
* Penetration test reports (summary)

**Request Documentation**: [compliance@passy.ai](mailto:compliance@passy.ai)

## Security Roadmap

### Current (Q1 2025)

* ✅ ISO 27001 certified infrastructure
* ✅ NEN 7510 certified infrastructure
* ✅ GDPR compliance
* ✅ TLS 1.3 encryption
* ✅ 24/7 security monitoring

### Upcoming (Q2 2025)

* 🔄 SOC 2 Type II certification
* 🔄 Enhanced DDoS protection
* 🔄 Advanced threat detection
* 🔄 Customer-managed encryption keys (CMEK)

### Future (2025+)

* 📋 FedRAMP compliance (for US government)
* 📋 ISO 27017 (cloud security)
* 📋 ISO 27018 (cloud privacy)
* 📋 On-premise deployment options

## Best Practices for Customers

### API Key Security

<Tip>
  **Protect Your API Keys**:

  * Never commit keys to version control
  * Use environment variables
  * Rotate keys every 90 days
  * Use separate keys for dev/staging/prod
  * Implement IP whitelisting when possible
</Tip>

### Data Protection

* Encrypt sensitive data before sending to API
* Implement proper access controls in your application
* Follow principle of least privilege
* Regular security audits of your integration
* Monitor API usage for anomalies

### Compliance

* Review our Terms of Service and Privacy Policy
* Implement proper consent mechanisms
* Provide privacy notices to your users
* Maintain audit logs
* Regular compliance reviews

## Questions?

For security and compliance questions:

**General Security**: [security@passy.ai](mailto:security@passy.ai)\
**Compliance**: [compliance@passy.ai](mailto:compliance@passy.ai)\
**Privacy**: [privacy@passy.ai](mailto:privacy@passy.ai)\
**DPO**: [dpo@passy.ai](mailto:dpo@passy.ai)

***

<Info>
  **Security is a shared responsibility**. While we provide secure infrastructure, you're responsible for securing your API keys, implementing proper access controls, and following security best practices in your applications.
</Info>

<Warning>
  **Found a security vulnerability?** Please report it responsibly to [security@passy.ai](mailto:security@passy.ai). Do not disclose publicly until we've had a chance to address it. We appreciate responsible disclosure and have a bug bounty program.
</Warning>
