Trust & Security
This website loads no third-party resources and sets no tracking cookies. No CDN scripts, no external fonts or icon libraries, no analytics, no advertising pixels. Every request a visitor's browser makes while viewing this site stays on our own infrastructure. (The one exception: our Outlook add-in, which runs inside Microsoft Outlook and loads Microsoft's own office.js from appsforoffice.microsoft.com, as Microsoft requires.)
Hosting
VisitorPass runs on IONOS Cloud infrastructure in data centres located in Germany. IONOS publishes its data centre certifications at cloud.ionos.de/zertifikate.
Data location
All customer and visitor data is stored and processed exclusively within the European Union. There is no third-country data transfer.
Sub-processors
We use exactly one sub-processor: IONOS SE, for hosting and outbound e-mail delivery (SMTP). That is the complete list — we do not route data through any other third-party service. If that ever changes, this page will be updated before the change takes effect.
Encryption in transit
All connections use TLS 1.3. HSTS is enabled with a one-year max-age and preload.
Password storage
Passwords are hashed with bcrypt at a cost factor of 12.
Sessions
Session cookies are set with Secure, HttpOnly and SameSite=Strict, with an absolute session lifetime of eight hours.
Access control
Accounts are assigned one of six role levels, from organisation administration down to individual employees. Every account is scoped to its own organisation, site or gatehouse, and that scope is re-checked by the server on every request — not just enforced in the interface.
Logging
Every GDPR-relevant action — access, export, anonymisation, modification — is written to an immutable processing log recording the acting user, their IP address and a UTC timestamp. Log entries are retained for three years.
Retention & deletion
Each organisation configures its own visitor data retention period. A nightly automated job anonymises identifying fields and deletes photos for checked-in visits once that period has elapsed — no manual clean-up step is required. This currently applies to visits that were checked in; records for expected visitors who never arrived are not yet covered by the automated run.
Data Processing Agreement
A GDPR Article 28 Data Processing Agreement is included with every subscription plan at no extra cost. A specimen copy is available on request.
Security contact
Report a security issue to security@visitorpass.eu. We acknowledge every report within 72 hours.
Certifications
auristec GmbH is not currently ISO 27001 certified. Our hosting provider, IONOS, operates its data centres under ISO 27001.
What we don't claim. We don't currently have an independent penetration test report, SOC 2 or TISAX attestation, a measured uptime SLA, or multi-factor authentication — so none of those appear on this page or elsewhere on this site. If any of these become available, we'll add them here with the supporting evidence.
Questions
For anything not covered here — a security questionnaire, a specific control you need documented, or a copy of our DPA — contact security@visitorpass.eu or sales@visitorpass.eu.