Skip to content

Security & Trust

Verifiable security practices for Wallet infrastructure

Only claims we can support with hosting, product, or legal evidence. No invented certifications.

EU-Hosted (Frankfurt) • GDPR-ready workflows

Security & EU Hosting

Passinstance's primary application data is hosted in the AWS Europe (Frankfurt) region in Germany. We implement technical and organisational measures designed to protect data, including encryption in transit, access controls, environment isolation, monitoring and regular backups.

GDPR & data processing

Passinstance supports GDPR-aligned workflows for EU customers, including Data Processing Agreements (DPAs) on request. Customers remain controllers of their end-customer pass data unless otherwise agreed in writing.

Encryption & access control

Traffic to Passinstance services is protected with TLS in transit. Access to production systems is restricted by role-based controls, environment isolation, and authenticated API keys or session credentials.

API authentication & webhooks

API access uses authenticated credentials scoped to the customer tenant. Webhooks are designed for signed delivery so receivers can verify authenticity before acting on events.

What Wallet tracking can and cannot prove

Download-page opens, CTA clicks, and .pkpass downloads are not the same as confirmed Wallet installation. Device registration is the reliable install signal for Apple Wallet updates.

  • Download page opened — does not alone prove Wallet installation
  • Add-to-Wallet CTA clicked — does not alone prove Wallet installation
  • .pkpass downloaded — does not alone prove Wallet installation
  • Google Wallet save URL opened — does not alone prove Wallet installation
  • Wallet device registered — can support an install signal
  • Pass lifecycle ACTIVE — does not alone prove Wallet installation
  • Device unregistered / pass removed — does not alone prove Wallet installation

Billing active-pass / active-registration counts are based on billable installed registrations, not merely that a pass record exists or a download page was opened.

Certifications

Passinstance does not currently claim independent SOC 2, ISO 27001, or PCI DSS certification. Where we reference ISO 27001 or SOC reports, we mean certifications of the underlying cloud provider infrastructure (AWS), not a Passinstance product audit.

Security contact

For security questionnaires, DPAs, or vulnerability reports, contact support@passinstance.com with the subject “Security”.