Security & EU Hosting
Passinstance's primary application data is hosted in the AWS Europe (Frankfurt) region in Germany. We implement technical and organisational measures designed to protect data, including encryption in transit, access controls, environment isolation, monitoring and regular backups.
GDPR & data processing
Passinstance supports GDPR-aligned workflows for EU customers, including Data Processing Agreements (DPAs) on request. Customers remain controllers of their end-customer pass data unless otherwise agreed in writing.
Encryption & access control
Traffic to Passinstance services is protected with TLS in transit. Access to production systems is restricted by role-based controls, environment isolation, and authenticated API keys or session credentials.
API authentication & webhooks
API access uses authenticated credentials scoped to the customer tenant. Webhooks are designed for signed delivery so receivers can verify authenticity before acting on events.
What Wallet tracking can and cannot prove
Download-page opens, CTA clicks, and .pkpass downloads are not the same as confirmed Wallet installation. Device registration is the reliable install signal for Apple Wallet updates.
- Download page opened — does not alone prove Wallet installation
- Add-to-Wallet CTA clicked — does not alone prove Wallet installation
- .pkpass downloaded — does not alone prove Wallet installation
- Google Wallet save URL opened — does not alone prove Wallet installation
- Wallet device registered — can support an install signal
- Pass lifecycle ACTIVE — does not alone prove Wallet installation
- Device unregistered / pass removed — does not alone prove Wallet installation
Billing active-pass / active-registration counts are based on billable installed registrations, not merely that a pass record exists or a download page was opened.
Certifications
Passinstance does not currently claim independent SOC 2, ISO 27001, or PCI DSS certification. Where we reference ISO 27001 or SOC reports, we mean certifications of the underlying cloud provider infrastructure (AWS), not a Passinstance product audit.
Security contact
For security questionnaires, DPAs, or vulnerability reports, contact support@passinstance.com with the subject “Security”.