Last updated: July 29, 2026
Enterprise-Grade Security : npass.io implements industry-leading security practices to protect your network authentication infrastructure and sensitive data.
npass.io is hosted on Amazon Web Services (AWS) in the Frankfurt region (eu-central-1), ensuring data residency within the European Union. Our infrastructure is designed for high availability, scalability, and security.
Data residency and operational access : All customer data is stored exclusively in the EU (AWS Frankfurt, eu-central-1). Our operations and support teams in the EU and in Seoul, Republic of Korea, may access customer data remotely for service operation, maintenance, and support. Remote access from Korea is covered by the European Commission's adequacy decision for the Republic of Korea (Art. 45 GDPR) and is role-based, logged, and limited to what is necessary. Details: DPA, Section 5.
All data stored in npass.io is encrypted at rest using industry-standard encryption :
All data transmitted to and from npass.io is encrypted in transit :
Each customer's data is logically isolated using a per-tenant architecture :
In the event of a personal data breach, we notify affected customers without undue delay after becoming aware, so that customers (as controllers) can meet their own obligation to notify their supervisory authority within 72 hours (Art. 33 GDPR) and, where required, inform affected data subjects without undue delay (Art. 34 GDPR). Our notification includes :
npass.io is currently in an early-access phase. We are transparent about what is legally in place today and what independent certifications are on our roadmap. We will never imply a certification we do not hold.
| Framework | Status | Basis |
|---|---|---|
| GDPR (EU 2016/679) | Compliant | Privacy-by-design, Art. 13/14 notices, Art. 28 DPA available, Art. 30 processing records, TOMs documented. EU data residency. |
| NIS2 Directive (EU 2022/2555) | Aligned | Technical and organizational measures aligned with Art. 21 risk management requirements. Incident response procedures documented. |
| TDDDG / DDG §5 (Germany) | Compliant | Impressum, cookie consent, and telemedia/digital services requirements met in full. |
EU representation : Netcube, Inc. is established in the Republic of Korea. Our EU representative under Art. 27 GDPR is: OBSECOM GmbH, Königstr. 40, 70173 Stuttgart, Germany — Email: netcube@obsecom.eu.
| Certification / Attestation | Status | Target |
|---|---|---|
| ISO/IEC 27001 | In progress — ISMS implementation under way; scope covers our operations in Seoul (HQ and R&D) and our EU service infrastructure under a single ISMS. | Stage 2 audit: Q2 2027 |
| BSI C5 Type 2 (ISAE 3000) | Planned — prioritized based on public-sector and regulated customer demand. | 2027 - 2028 |
| SOC 2 Type II (AICPA) | Planned — targeted for customers with North American or global procurement requirements. | 2027 - 2028 |
Early-access commitment. Customers onboarded during the early-access phase receive our current TOMs documentation, DPA, and a binding written commitment to the above certification timeline. We will notify customers promptly of any change to the roadmap.
npass.io uses the following third-party providers to deliver and operate the service:
| Provider | Purpose | Location | Role / Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting, compute, storage, databases, networking | Frankfurt, Germany (eu-central-1) | Sub-processor — Data Processing Addendum |
| Google Cloud (optional) | Identity provider federation relay (only if configured by customer) | European Union | Sub-processor — SCC |
| Lemon Squeezy (Stripe) | Merchant of Record — payment, billing, tax, subscription management | United States | Independent controller (not a sub-processor) — EU-U.S. DPF / SCC; processes payment and billing data only; no access to npass.io service data |
Netcube, Inc. commits to notifying customers of any changes to sub-processors at least 30 days in advance. Customers have the right to object to new sub-processors on data protection grounds. To subscribe to sub-processor change notifications:
Email security@netcube.com with the subject "Sub-Processor Notification Subscription"
npass.io undergoes regular security testing:
For security concerns, vulnerabilities, or incident reporting:
Responsible Disclosure : We appreciate security researchers who responsibly disclose vulnerabilities. Please do not publicly disclose security issues before we have had reasonable time to address them. We are committed to working with researchers to understand and fix any issues.