INTYGIO

Intygio Trust Center

Security is not a feature. It is the product. Every Digital Product Passport we issue must remain verifiable for decades, across EU member states, and through the post-quantum transition. Every claim on this page is verifiable.

Controls

28 controls. Security in the foundation of everything we build.

Our approach

Security is embedded in how Intygio builds, not layered on top. Controls here reflect what Intygio actually does: documented practices, automated gates, and recurring obligations. Each is cross-walked against multiple cybersecurity frameworks so a single practice satisfies several at once.

Where a control carries a date, Last performed is the most recent execution. Planned next is the committed forward date.

Govern (GV)

How Intygio sets, communicates, and oversees its cybersecurity risk strategy. Covers risk management, supply chain governance, and policy.

Control
  • Documented cybersecurity strategy

    Cybersecurity strategy and risk appetite are documented and reviewed by leadership every quarter. Strategy is cross-walked against NIS 2 Article 21 and the NIST Cybersecurity Framework so a single statement of intent maps to both.

    NIST CSF GV.SC-01, GV.RM-01 NIS 2 Art 21(2)(a) ISO 27001 A.5.1
    Last performed: 2026-09-03 Planned next: Q4 2026
  • Supply chain risk management

    Third-party providers processing customer data are inventoried in the Subprocessor Register. Each entry carries purpose, region, services consumed, and last-review date. New providers are announced before activation.

    NIST CSF GV.SC-04, GV.SC-07 NIS 2 Art 21(2)(d) ISO 27001 A.5.19, A.5.20
    Last performed: 2026-09-03 Planned next: Q4 2026
  • Effectiveness assessment of security measures

    Security measures are continuously evaluated through automated gates on every code change, plus quarterly third-party penetration testing. Closure of every confirmed finding produces either a permanent regression test or a new automated check.

    NIST CSF GV.OV-01, GV.OV-03 NIS 2 Art 21(2)(f)
  • Roles, responsibilities, and authorities

    Security responsibilities are documented; ownership of each control category is explicit. Leadership has decision authority and accountability for security outcomes per NIS 2 governance requirements.

    NIST CSF GV.RR-02 NIS 2 Art 20 ISO 27001 A.5.2

Identify (ID)

How Intygio understands its asset landscape, business environment, and risk exposure.

Control
  • Production asset inventory

    Production system assets are inventoried through infrastructure-as-code. Inventory includes ownership, data classification, and change history. Refreshed automatically on every deploy.

    NIST CSF ID.AM-01, ID.AM-02 NIS 2 Art 21(2)(i) ISO 27001 A.5.9
  • Risk assessment cadence

    Risk assessments are performed quarterly and on any material change to the environment, regulation or supplier set. Each assessment produces a prioritised mitigation backlog with named owners.

    NIST CSF ID.RA-01, ID.RA-05 NIS 2 Art 21(2)(a) ISO 27001 A.5.1, A.5.7
    Planned next: Q4 2026
  • Data classification and inventory

    Customer data and trust-path data are classified; processing and retention are documented in the Data Processing Agreement.

    NIST CSF ID.AM-07 ISO 27001 A.5.12, A.5.13

Protect (PR)

How Intygio prevents, limits, and contains security events. Covers identity, data security, platform security, and supplier protections.

Control
  • eIDAS-aligned electronic seals on every passport

    Every Digital Product Passport is signed with an eIDAS-aligned advanced electronic seal. A Qualified Electronic Seal (QSealC) from an EU-listed Qualified Trust Service Provider is contracted and activates when our QSCD is operational. Signing keys are sealed at rest and never stored in plaintext.

    NIST CSF PR.DS-01 NIS 2 Art 21(2)(h) ISO 27001 A.8.24
  • Post-quantum-ready signatures

    Signing infrastructure is designed to remain verifiable through the cryptographic transition ahead. Passports issued today do not require re-signing as standards evolve.

    NIST CSF PR.DS-02, PR.PS-06 NIS 2 Art 21(2)(h) ISO 27001 A.8.24
  • Key management policy

    A documented key management policy covers generation, storage, rotation, use, and destruction of every cryptographic key on the trust path. Trust-path signing keys are held in certified hardware security modules.

    NIST CSF PR.DS-01, PR.AA-01 NIS 2 Art 21(2)(h) ISO 27001 A.8.24
    Last performed: 2026-09-03 Planned next: Q4 2026
  • Data encryption at rest and in transit

    Customer data and credentials are encrypted at rest. All network traffic between Intygio services and between Intygio and customers is encrypted in transit. Trust-path key material never leaves the secure boundary in plaintext.

    NIST CSF PR.DS-01, PR.DS-02 NIS 2 Art 21(2)(h) ISO 27001 A.8.24
  • Personal identifier minimisation in operational data

    Email addresses and other direct identifiers do not appear in operational logs or audit metadata. Where a log entry must be associated with an account, only an indirect identifier is recorded.

    NIST CSF PR.DS-05 ISO 27001 A.5.34, A.8.11
  • Least-privilege production access

    Production system access is least-privilege, time-bounded, and audit-logged. Access reviews run quarterly with documented outcomes. Multi-factor authentication is enforced for all human access to production systems.

    NIST CSF PR.AA-01, PR.AA-05 NIS 2 Art 21(2)(i), 21(2)(j) ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18
    Planned next: Q4 2026
  • Secure software development lifecycle

    Software development follows a documented lifecycle with automated security checks at key stages. No change reaches production without passing defined gates.

    NIST CSF PR.PS-01, PR.PS-06 NIS 2 Art 21(2)(e) ISO 27001 A.8.25, A.8.27, A.8.28
  • Trust-critical dependency control

    Software dependencies on the signing and verification path are actively managed and reviewed before adoption. Vulnerable dependencies are addressed on a documented schedule.

    NIST CSF GV.SC-07, PR.PS-02 NIS 2 Art 21(2)(d), 21(2)(e) ISO 27001 A.8.8, A.8.30
  • EU data residency by default

    Customer data is processed and stored within the European Union by default. Region is configurable per tenant under contract when a customer requires it.

    NIST CSF PR.DS-01 ISO 27001 A.5.34
  • Cyber hygiene and training

    Operating personnel follow documented cyber-hygiene practices including secret management, secure development training, and incident-recognition awareness. Training is refreshed annually.

    NIST CSF PR.AT-01 NIS 2 Art 21(2)(g) ISO 27001 A.6.3
    Planned next: Q4 2026

Detect (DE)

How Intygio discovers anomalies, attacks, and integrity violations.

Control
  • Continuous vulnerability scanning

    Software dependencies and production systems are continuously scanned against authoritative vulnerability databases. Critical and high-severity findings carry documented remediation SLAs and are tracked to closure.

    NIST CSF DE.CM-08, DE.CM-09 NIS 2 Art 21(2)(e) ISO 27001 A.8.8
  • Append-only audit chain per passport

    Every lifecycle event for every passport is recorded in a tamper-evident log. The complete event chain is available for audit purposes.

    NIST CSF DE.AE-03, PR.PS-04 ISO 27001 A.8.15
  • Trust-path integrity monitoring

    EU trust list infrastructure is verified on a regular schedule. Trust store health is monitored continuously and any degradation is treated as a service concern.

    NIST CSF DE.CM-01 ISO 27001 A.8.16
  • Quarterly adversarial penetration testing

    Adversarial penetration testing runs every quarter across the signing, verification and trust-path surfaces. Every finding is closed with a permanent regression test or a new automated check, so a closed finding cannot silently reopen. An independent third-party engagement follows when revenue justifies the audit cycle.

    NIST CSF ID.RA-01, DE.AE-02 NIS 2 Art 21(2)(f) ISO 27001 A.5.36, A.8.29
    Last performed: 2026-09-03 Planned next: Q4 2026

Respond (RS)

How Intygio contains and communicates security events.

Control
  • Documented incident response runbook

    Security and privacy incidents follow a documented response runbook with defined detection, escalation, customer notification timers, and post-incident review. NIS 2 Article 23 timers apply when scope-triggered.

    NIST CSF RS.MA-01, RS.CO-02 NIS 2 Art 21(2)(b), Art 23 ISO 27001 A.5.24, A.5.25, A.5.26
    Planned next: Q4 2026
  • Customer notification commitments

    Customers are notified of security-relevant incidents per the timers in the Master Service Agreement. Material incidents are escalated immediately with a follow-up written report within 72 hours.

    NIST CSF RS.CO-02 NIS 2 Art 23 ISO 27001 A.5.27, A.6.8
  • Emergency revocation drill

    A drill exercising the key-compromise revocation path runs annually. Covers signer suspension, customer notification, and re-issuance under a fresh credential.

    NIST CSF RS.MA-02 NIS 2 Art 21(2)(c) ISO 27001 A.5.29
    Last performed: 2026-09-03 Planned next: Q4 2026
  • Anonymous concern reporting

    A confidential channel is available for reporting security or compliance concerns. Reports are reviewed by leadership and resolved with documented outcomes.

    NIST CSF GV.RR-04 ISO 27001 A.6.7, A.6.8

Recover (RC)

How Intygio restores normal operations after an incident and learns from it.

Control
  • Business continuity and disaster recovery plans

    Business continuity and disaster recovery plans document recovery time and recovery point objectives per service tier. Plans are tested annually with documented exercise outcomes.

    NIST CSF RC.RP-01, RC.CO-03 NIS 2 Art 21(2)(c) ISO 27001 A.5.29, A.5.30, A.8.13, A.8.14
    Planned next: Q4 2026
  • Customer data backup and restore

    Customer data backups follow a documented schedule and recovery procedure. Restore drills are run at documented cadence; restore success is verified, not assumed.

    NIST CSF RC.RP-01 NIS 2 Art 21(2)(c) ISO 27001 A.8.13
    Last performed: 2026-09-03 Planned next: Q4 2026
  • Post-incident improvement loop

    Every incident produces a post-incident review with concrete improvement actions. Improvements feed into either a regression test or a new automated check, never a memo-only resolution.

    NIST CSF RC.IM-01, GV.OV-03