Trust Center
How we protect your product and supplier data
Tappr is ISO/IEC 27001 certified. Product and supplier records are hosted in the EU, encrypted in transit and at rest, and separated by brand.
Review our certification, access controls and data protection documentation below.
Hosting and encryption
Primary hosting
Google Cloud, Netherlands
europe-west4
Disaster recovery
Google Cloud, Belgium
europe-west1
In transit
TLS 1.2 or higher
At rest
AES-256
Documents for your security review
ISO/IEC 27001 certificate Certification scope, issuing body and validity dates. Open the certificate → Statement of Applicability Applicable security controls, implementation status and documented exclusions. Open the statement → Sub-processor list The providers involved in delivering Tappr, their roles and processing locations. Open the list → Data Processing Agreement The contractual terms governing personal data processing. Request the DPA → Service status Current availability and published incident history. Open the status page →
Questions about security and privacy
What does Tappr’s ISO/IEC 27001 certification cover?
The certificate states the certified scope, the issuing body and the validity dates. Open it above, and read the Statement of Applicability alongside it for the controls that apply and any documented exclusions.
Where is data stored and processed?
Product and supplier records are hosted on Google Cloud in the Netherlands (europe-west4), with the disaster recovery environment in Belgium (europe-west1). The sub-processor list names every provider involved in delivering Tappr and where each one processes data.
How is access controlled for brands, suppliers and Tappr staff?
Each brand has a separate data schema, and permissions control what a user can reach inside the platform. Suppliers answer from a link without an account, scoped to the products and components in their request. Staff access follows the controls listed in the Statement of Applicability.
What personal data is collected when someone uses a passport?
Viewing public passport information needs no account. Registration, warranty and similar services may require personal information; what is collected and how it is handled is set out in the privacy policy and the Data Processing Agreement.
How are vulnerabilities assessed and addressed?
The relevant controls and their implementation status are documented in the Statement of Applicability. For the detail your review needs, send us your questionnaire and we will point you to the right document.
What are the backup, recovery and incident-response arrangements?
A separate disaster recovery environment runs in Belgium (europe-west1), and published availability and incident history are on the status page. The arrangements themselves sit in the Statement of Applicability; ask us for the version your review requires.
Support for your security review
Share your security questionnaire or specific requirements with our team. We’ll help you find the relevant documentation and clarify how it applies to your setup.