Last updated 31 August 2026
Candidates did not choose Passa.
They gave their details to an agency, or applied to a company, and the file reached us afterwards. This page sets out where that data sits, who can reach it, how long we keep it, and which claims we have not yet earned the right to make.
GDPR
In force today
Standard Contractual Clauses
In our DPA today
SOC 2 Type II
Not yet certified
ISO 27001
Not yet certified
External penetration test
Scheduled for 2026
The first two are commitments already in force. The other three are documents we do not hold. A SOC 2 Type II observation window and a first external penetration test are both planned for 2026, and the results will be published here when they exist. Until then nothing on this page is a certification claim, and any report we do have goes out under a mutual non disclosure agreement.
On this page
Documents
Our Data Processing Agreement is pre signed by Passa and takes effect when you sign up. Security overviews and the current sub processor list go out on request.
Request security documentation
Data protection
Three things we can state today, with no auditor in the room and no report to wait for.
Data in transit
Every connection to Passa is forced over HTTPS and encrypted with TLS 1.3 or higher. Older protocol versions are refused rather than quietly downgraded.
Data at rest
All datastores are encrypted at rest with AES 256. The fields inside a candidate profile that identify a person directly are encrypted again at the application layer, so a stolen database copy is not a readable CV.
Backups
We take point in time backups of the production database and keep them in the same jurisdiction as the primary, under the same encryption and the same access restrictions. The exact retention window sits in our Data Processing Agreement rather than on this page, so that it is contractual instead of promotional.
Where the data lives
Passa AS is registered in Oslo and operates inside the EEA. Our production environment, our database and our backups run in European Union regions. In the normal course of the service, no candidate record is replicated to a region outside the EEA.
Application and database
Hosted in a European Union region of our cloud provider, with disaster recovery backups held in a second European Union region. We will name the provider and the exact region codes in writing for any customer who asks, and in the Data Processing Agreement.
Files and attachments
CVs, portfolios and anything else a candidate uploads sit in European Union object storage, behind the same access rules and the same encryption as the database.
Transfers out of the EEA
Where a sub processor sits outside the EEA, the transfer is governed by the EU Standard Contractual Clauses incorporated into our Data Processing Agreement. The Clauses stand on their own. We do not lean on an adequacy decision to make them work.
How a candidate file moves
Passa sits between two parties who both hold a relationship with the candidate. That is the real privacy question in a marketplace, so here is the whole route.
European Economic Area
Company
Passa
Agency
The brief travels out to the agencies matched to it, and to nobody else
The candidate file travels back, and only the shortlist reaches the company
Into Passa
A company writes a brief. An agency that accepts the brief submits a candidate, and the candidate file enters Passa at that moment. We do not scrape candidate data, we do not buy candidate lists, and we do not build a shadow database of people nobody submitted.
Through Passa
Matching runs over the brief and the profiles submitted against it. The reasoning attached to a shortlist is generated from that brief and that profile, at the moment you ask for it. Candidate data is not used to train models, ours or anyone else’s, and any model provider we use is contractually forbidden from doing so.
Out of Passa
A shortlist goes to the company that wrote the brief. An agency sees its own submissions and the briefs it has been matched to. It never sees another agency’s candidates and it never sees the rest of your pipeline.
Who can see a candidate file
Employee access
Access to production candidate data is restricted to a small number of named engineers with a business need. It is granted by request, reviewed on a schedule, and removed the day a person changes role or leaves. Nobody in sales and nobody in marketing has it.
Production access
Administrative access to production is logged and auditable. Sensitive operations require a second person to approve them. Every individual who can reach candidate data is a Passa employee under a confidentiality agreement that outlives their contract, and we use no offshore support contractors.
Logging and review
We review the access list every quarter and strip out anything that has gone unused. Access logs are retained so that the question of who read a particular record has an answer rather than an opinion.
Customer side visibility
Inside the product, a company sees the candidates submitted to its own briefs. An agency sees its own submissions and the briefs it has accepted. Neither can see the other side’s wider activity, and no agency can see another agency’s candidates.
Candidate rights, and who answers them
In almost every case Passa is a processor rather than a controller. The company that wrote the brief controls the candidate data it receives, and the agency that introduced the candidate controls its own relationship with that person. We hold the data on their instructions, which is why some requests cannot be settled by us alone.
Send a request to privacy@passa.no. We acknowledge it, tell you who the controller is, and pass it on within five working days. Where we can act ourselves, we do. The statutory deadline for a full response under the GDPR is one month, and that is the clock we work to.
Access
A copy of the personal data we hold about you, and an account of where it came from.
Rectification
Correction of anything inaccurate or incomplete in a profile.
Erasure
Deletion of your data. We remove it from Passa and forward the request to the controller, because a company’s own applicant tracking system is outside our reach. We tell you who we forwarded it to.
Restriction
Processing paused while a dispute about accuracy or lawfulness is settled.
Portability
Your data returned in a structured, commonly used, machine readable format.
Objection
A stop on any processing carried out on the basis of legitimate interests.
Complaint
A complaint to a supervisory authority. In Norway that is Datatilsynet, and you do not need to come through us first.
Retention and deletion
We keep a candidate record for as long as it is being used to fill roles and for as long as the controller instructs us to, unless a longer period is required by law. When a company closes its Passa account, the personal data attached to that account is deleted or irreversibly anonymised, except where we are obliged to retain something for legal or accounting reasons.
There is no fixed number of days printed here, and that is deliberate. A number on a security page becomes a contractual promise the moment a buyer reads it. The retention periods that apply to your account are set out in the Data Processing Agreement, where they can be negotiated, versioned and enforced, and we will walk you through them before anyone signs.
Sub processors
A short list of third parties helps us run the service. The categories are published here. The current named list, with each vendor’s legal jurisdiction, hosting region and the exact fields it receives, carries its own date and goes out on request and with the Data Processing Agreement.
Cloud hosting
Runs the application, the database and the object storage that holds uploaded files. Located in the European Union. This is the only category with access to a complete candidate profile.
Email delivery
Sends transactional messages such as invitations, shortlist notifications and password resets. Receives a name and an email address. Never receives a CV.
Product analytics
Tells us which parts of the product are used and where people get stuck. Receives pseudonymous usage events, not candidate content.
Error monitoring
Captures stack traces when something breaks so that we can fix it. Configured to scrub personal data out of payloads before they leave our servers.
Payments and invoicing
Handles success fee invoicing for hiring companies. Receives company billing details. Never receives candidate data.
We give at least 30 days of notice before adding or replacing a sub processor, and you may object inside that window. Each one is assessed before it is onboarded and reviewed again every year. Anything that would move candidate data outside the EEA is treated as a change to the agreement, not as an implementation detail.
How we build and run it
Code review
Every change to source code is reviewed before it merges. Anything that touches authentication, authorisation or candidate data requires review by a second engineer, and the review includes an explicit note on what the change could be abused to do.
Deployment
Changes ship through an automated pipeline with tests and dependency scanning in front of them. Nobody deploys by hand and nobody edits production directly.
Dependencies
Third party packages are scanned continuously for known vulnerabilities and patched on a schedule. Anything rated critical is taken out of the normal cycle and shipped on its own.
Environments
Production, staging and development are separated. Production data is never copied into staging and never lands on a laptop for debugging. Test environments run on generated data that resembles real profiles without being them.
Monitoring
Infrastructure and application logs are centralised and alert on anomalies. Access to those logs is restricted the same way access to production is, because logs are candidate data too.
People and devices
The team
Everyone who can reach candidate data is a Passa employee in Oslo, under a confidentiality agreement that survives the end of their contract. We use no offshore support contractors and no unvetted freelancers.
Training
Security and data protection training happens at onboarding and again every year. It is written around what a recruitment marketplace actually gets wrong rather than around generic awareness slides.
Devices
Company laptops are managed. Disk encryption, screen lock, automatic updates and a password manager are enforced rather than suggested, and access to Passa systems requires multi factor authentication without exception.
Reporting a vulnerability
If you have found something, we would rather hear it from you than read about it later. There is one address, a person reads it, and you will not be met with a lawyer.
What we expect from you
Send it to security@passa.no before you tell anyone else.
Give us enough detail to reproduce it.
Do not access, change or delete data that is not yours.
No automated scanning against production, and nothing that degrades the service for other people.
What you can expect from us
An acknowledgement within five working days.
A named person on the report and honest updates while it is open.
Credit in the advisory if you want it, and none if you do not.
No legal action against anyone acting in good faith under this policy.
In scope
passa.no, app.passa.no and the Passa API, including anything that exposes a brief, a candidate profile or an account to someone who should not see it.
Out of scope
Raw output from an automated scanner with no proof of exploitability. Missing security headers on their own. Social engineering of our team or our customers. Denial of service. Reports about software we do not run.
We do not run a paid bounty at the moment. If that changes it will be announced here rather than negotiated report by report.
Documents
What exists, what does not, and how to get the ones that do.
Data Processing Agreement
Sub processor list, dated
Security overview
Answers to your security questionnaire
Penetration test summary
SOC 2 Type II report
ISO 27001 certificate
Write to security@passa.no or privacy@passa.no and name the document you need. Anything not already public goes out under a mutual non disclosure agreement, usually the same day.
Questions
Straight answers
Including the ones where the answer is no. If a buyer is going to ask it in the first email, it belongs here instead.
Is Passa SOC 2 certified?
No. We hold no SOC 2 report and we will not imply that we do. A Type II observation window is planned for 2026 and the report will be published here once it is issued. In the meantime we answer security questionnaires in full and will walk you through every control described on this page.
Is Passa ISO 27001 certified?
No. ISO 27001 sits behind SOC 2 in the plan and no date is fixed. If a certificate matters to you more than the controls underneath it, we would rather you knew that now than three weeks into a procurement review.
Who is the controller of a candidate's data?
In almost every case the hiring company that wrote the brief, and the agency that introduced the candidate, are the controllers. Passa is the processor acting on their instructions. That is why some requests have to be routed to them rather than settled by us alone.
Can a candidate ask Passa to delete their data?
Yes, and we act on the part that is ours to act on. We remove the record from Passa and forward the request to the controller, because a company's own applicant tracking system is outside our reach. We tell the candidate who we forwarded it to, so the trail does not go cold.
Which agencies can see my brief?
Only the agencies matched to it, and only once they accept it. An agency sees the brief and its own submissions against it. It never sees another agency's candidates and it never sees the rest of your hiring pipeline.
Do you use candidate data to train models?
No. Candidate data is not used to train models, ours or anyone else's, and any model provider we use is contractually forbidden from doing so. Matching and shortlist reasoning run over your brief and the profiles submitted to it, at the moment you ask for them.
Where is candidate data stored?
In European Union regions, with disaster recovery backups in a second European Union region. Passa AS is registered in Oslo, inside the EEA. Where a sub processor sits outside the EEA, the EU Standard Contractual Clauses in our Data Processing Agreement govern the transfer.
What happens if there is a breach?
We notify affected controllers without undue delay and within 72 hours of becoming aware, which is the deadline the GDPR sets. You get what we know when we know it, including the parts that are still uncertain, and we publish a summary once the people affected have been told.
Can we run our own penetration test?
Yes, against a staging environment with the real architecture and generated data, once scope and timing are agreed in writing. We will not expose live candidate data to a test, including one you are paying for.
Do you sign our Data Processing Agreement or do we sign yours?
Ours is pre signed by Passa and takes effect when you sign up, which is the faster route. If your legal team needs its own paper, send it over and we will review it rather than refuse it.
Contact
Two addresses, and a person behind each.
Vulnerability reports
Data subject requests
For a security overview, the current sub processor list or a copy of the Data Processing Agreement, write to either address and name the document. Both are monitored by the people who built the system, not by a queue.
Passa AS · Oslo, Norway · Registered in the Norwegian Register of Business Enterprises
