Security at Penbox
Our customers entrust us with sensitive data, often that of their own customers. Protecting it drives every decision we make: the architecture of the platform, the infrastructure, our processes and how our team is organised.
This page describes the measures we have in place in detail. To go further (security questionnaire, certificate, DPA), contact us at security@penbox.io.
At a glance
ISO/IEC 27001 certified, monitored in real time.
Our information security management system covers the entire organisation and all of our products. Compliance is monitored continuously with Probo, and security with Aikido.
100% European Union.
Hosting, backups, AI processing, logs and support: the entire processing chain is located in the EU.
Your data stays yours.
It is never used to train AI models, and you decide how long it is kept.
Tested by independent third parties.
External penetration tests based on the OWASP ASVS standard, complemented by continuous security analysis of the platform.
1. Compliance and certifications
ISO/IEC 27001. Penbox is ISO/IEC 27001 certified with a full scope: the organisation and all of its products. The certification requires a continuous improvement cycle, internal audits, annual external surveillance audits and periodic management reviews. The certificate is available on request.
Real-time compliance monitoring. Beyond the annual certification cycle, our compliance is monitored in real time with Probo, a compliance monitoring platform: controls, policies and evidence are tracked continuously, not only at audit time.
GDPR. When providing our services, Penbox acts as a processor within the meaning of the GDPR: our customers remain the data controllers and keep full control over their data. Our commitments are set out in a data processing agreement (DPA) compliant with Article 28 of the GDPR.
Data Protection Officer. Penbox has appointed an external DPO, who can be contacted for any question relating to data protection.
2. Hosting and data location
The entire processing chain is located in the European Union, without exception.
Component | Location |
|---|---|
Application servers | Germany (Frankfurt), Amazon Web Services |
Databases | Germany (Frankfurt), Amazon Web Services |
File storage | Germany (Frankfurt), Amazon Web Services |
Backups | Belgium, at a site separate from production |
AI processing (all AI modules) | European Union |
Technical logs | European Union |
The entire Penbox team is based in Europe: no access to data, including for support, takes place from outside the European Union. No data is transferred outside the EU.
3. Architecture and customer isolation
Penbox is a SaaS platform: the infrastructure is shared, and each customer's data is strictly isolated at every layer.
At the database level. Isolation is enforced by the database engine itself, using PostgreSQL Row-Level Security. Every row is tied to its organisation, and the engine rejects any read or write outside the customer’s scope. Isolation therefore does not rely solely on application code.
At the application level. Every request goes through a server-side authorisation check scoped to the organisation concerned. Tokens and sessions are strictly bound to the organisation that issued them.
At the file storage level. Each customer has a dedicated storage space. Files are never accessible through a public URL or a shareable link: every access goes through the Penbox platform, after an authorisation check.
Continuous verification. This isolation is tested automatically on every deployment, and external penetration tests explicitly cover cross-customer access scenarios.
Immutable infrastructure. Our production infrastructure is fully managed and immutable: there is no direct access to servers, no administration port is exposed to the internet, and instances are rebuilt on every deployment rather than modified.
4. Encryption
In transit. All communications are encrypted with TLS, both between users and the platform and between our services.
At rest. Databases and file storage are encrypted at rest.
Backups. Backups are encrypted before they are even stored, with a key held exclusively by Penbox: the storage operator never has access to it. The storage servers are themselves encrypted.
5. Access management
For your teams
Single sign-on (SSO). Authentication can be delegated to your own identity provider. Your password, multi-factor authentication and access restriction policies then apply natively, and the account lifecycle remains governed by your IAM.
Roles and permissions. You assign and review roles in your workspace yourself. Only an administrator can create another administrator.
Self-service administration. Your administrators configure the security of their workspace themselves: link validity period, one-time code policy, data retention period, accepted file types and sizes. All administration actions are logged.
Test environments. Environments separate from production can be made available to you, so that any configuration change can be validated before it goes live.
For the Penbox team
Least privilege. Access to production environments is limited to a small number of authorised people, on a need-to-know basis, using named accounts.
Strong authentication. All internal access goes through single sign-on with mandatory multi-factor authentication.
Access reviews. Access rights are reviewed every quarter as part of our ISO 27001 certification, and revoked immediately when an employee leaves.
Traceability. All administration actions are logged immutably.
6. Security of your recipients’ journeys
The people you send a Penbox form to access their journey securely.
Secure links. Each journey is accessed through a unique link, whose validity period you define.
Identity verification. Access can be protected by a one-time code sent by email or SMS.
Control over uploaded files. You define the accepted file types and sizes. Uploaded documents are stored in your dedicated space and are never publicly exposed.
Consistency checks. You can configure answer consistency checks and rules that block a journey.
7. Artificial intelligence
All Penbox AI modules (Document Intelligence, Email Intelligence, Case Intelligence, AI agents and more) are subject to the same guarantees.
Hosted in Europe. The AI models are deployed in a private enterprise environment hosted in the European Union. All AI processing takes place there.
No retention. The environment in which the models run does not retain any data: data is processed, the result is returned to the Penbox platform, and nothing is kept on the AI side.
No training on your data. Our customers’ data is never used to train AI models.
The same framework as the rest of the platform. AI processing is covered by our ISO 27001 certification, the GDPR and our DPA, just like the rest of our services.
8. Logging and traceability
What is logged. All platform events: authentication (link access, sending and validation of one-time codes), access to and actions on cases, forms and tasks, actions by case handlers and administrators, configuration changes and API calls.
No personal data in logs. Logs contain only technical identifiers (user, object concerned, timestamp, IP address, action and result), never business or personal data.
Immutable and separate. Logs are append-only: no one, including at Penbox, can modify or delete them. They are hosted on a logging pipeline separate from the application environment, so a compromise of the application could not alter the audit trail.
Retention. Logs are kept for 365 days and can be made available to you on request, for example as part of an investigation.
9. Retention, deletion and reversibility
You set the retention period. The data retention period is defined by your administrators in your workspace configuration.
Automatic, verifiable purge. When the retention period expires, an automatic purge runs. Every purge is logged and can be viewed in real time by your administrators in the application: you have direct proof of deletion. Your administrators can also trigger a deletion at any time.
Permanent deletion. Deletion in production is permanent. Deleted data then disappears from backups at the end of the rolling 30-day window. There is no archiving beyond that.
At the end of the contract. Your data is deleted no later than 60 days after the end of the contract, or immediately at your request. You receive a certificate of destruction.
10. Application security and testing
External penetration tests. The platform undergoes penetration tests carried out by an independent provider, NVISO, following the OWASP Application Security Verification Standard (ASVS) at level 2. The tests cover both authenticated and unauthenticated perspectives, and all ASVS domains: authentication, session management, authorisation, APIs, file handling, cryptography, configuration and data protection. Each campaign is followed by a retest of the fixes. A summary is available on request.
Real-time security monitoring. We use Aikido, a leading platform for real-time security monitoring, which continuously analyses our code, our dependencies and open source components, the potential presence of secrets, our cloud configuration and our internet-facing attack surface. Detected vulnerabilities are handled within timeframes defined by severity level.
Automated tests. Security tests, including cross-customer isolation tests, run automatically on every deployment.
Customer assessments. Our customers regularly carry out their own security assessments of the platform: audits, questionnaires and technical tests.
11. Monitoring and incident management
Monitoring. The platform is monitored continuously, with alerts on abnormal behaviour and service availability.
Incident management procedure. Penbox has a security incident management procedure documented as part of its ISO 27001 ISMS: detection, qualification, containment, remediation, post-incident review and improvement measures.
Notification. In the event of a personal data breach, we inform our customers without undue delay, in accordance with the GDPR and our DPA, so that they can meet their own notification obligations.
12. Business continuity and backups
Regular backups. Data is backed up automatically, over a rolling 30-day window, at a site located in Belgium and separate from the production environment.
Encrypted and isolated. Backups are encrypted before storage with a key held only by Penbox.
High availability. The production infrastructure runs on Amazon Web Services managed services, designed for redundancy and failure recovery.
13. Organisation and people
Awareness. All employees are trained in information security and data protection, with regular sessions.
Confidentiality commitments. Every employee is bound by a confidentiality obligation.
Onboarding and offboarding. Access is granted according to role on arrival and revoked immediately on departure, following a formal procedure.
Documented policies. Our security policies (access control, incident management, supplier management, business continuity) are documented, reviewed periodically and audited as part of the ISO 27001 certification.
14. Documents available on request
For your security, compliance or procurement teams, we provide:
our ISO/IEC 27001 certificate;
the summary of the latest penetration test;
our data processing agreement (DPA);
the detailed list of our sub-processors;
answers to your security questionnaires.
Write to us at security@penbox.io.
15. Report a vulnerability
Think you have found a vulnerability in Penbox? Email security@penbox.io with a description of the issue and how to reproduce it. We acknowledge reports promptly and handle each one as a priority. We ask that you do not exploit the vulnerability beyond what is needed to demonstrate it, do not access other users’ data, and give us time to fix it before any disclosure.
Frequently asked questions
Is data anonymised before being processed by the AI?
No, and this is by design: the purpose of our AI modules is to extract information from the content they process, which requires processing it as it is. Protection relies on other guarantees: processing in a private environment in the European Union, no retention on the AI side, no use for training, encryption and per-customer isolation.
Which AI model do you use?
We do not disclose the details of the models we use. We do, however, document precisely the framework in which they operate: hosting in the European Union, no data retention, no training on your data.
Is my data used to train AI?
No, never.
Where is my data stored?
In Germany (Frankfurt) for production and in Belgium for backups. AI processing also takes place within the European Union. Your data never leaves the EU.
What happens to my data if we stop using Penbox?
It is deleted no later than 60 days after the end of the contract, or immediately at your request, and you receive a certificate of destruction. It then disappears from backups within 30 days.
Who at Penbox can access my data?
A small number of authorised people, only when necessary, with strong authentication and full traceability of every action. No access takes place from outside the European Union.
Can I use my own SSO?
Yes. Your teams' authentication can be delegated to your identity provider, which then applies your own rules (MFA, access restrictions).