Security and privacy
We build on established cloud services, keep access tight and process as little personal data as possible. Here is what is actually in place.
GDPR
Privacy
TLS
Encrypted transfer
Vipps
Verified identity
Stripe
PCI DSS Level 1
Certified operating foundation
Database and application infrastructure runs with external providers certified to ISO/IEC 27001:2022 and audited under SOC 2 Type 2. Storage is encrypted, and row-level access control ensures that a partner only sees its own data. The database and the application servers both run in an EU region (Stockholm). Which processors we use, and the basis for transfers outside the EEA, is set out in the privacy policy.
These certifications belong to our operating providers. Provido holds none of its own yet.
Monitoring
Errors and anomalies are picked up by automatic monitoring, so we can fix them quickly.
Continuous anomaly monitoring
Checks before production
Changes go through code review and automated tests before they are put into production.
Access control
Role-based access for partners. Users identify with Vipps, and card data is handled by Stripe - never by us.

Principles
What we do not do.
No unnecessary data
We process only what is needed, and delete it when it is no longer relevant.
No card data with us
Payments go through Stripe. We never store card numbers.
No claims we cannot stand behind
Provido holds no certifications of its own yet - the ones we point to belong to our operating providers. We say it as it is, and will consider our own certification when the scale calls for it.
Questions about security or privacy?
Get in touch and we will answer concretely on how data is handled in Gjenreise.
