Last updated 31 August 2026

Candidates did not choose Passa.

They gave their details to an agency, or applied to a company, and the file reached us afterwards. This page sets out where that data sits, who can reach it, how long we keep it, and which claims we have not yet earned the right to make.

GDPR

In force today

Standard Contractual Clauses

In our DPA today

SOC 2 Type II

Not yet certified

ISO 27001

Not yet certified

External penetration test

Scheduled for 2026

The first two are commitments already in force. The other three are documents we do not hold. A SOC 2 Type II observation window and a first external penetration test are both planned for 2026, and the results will be published here when they exist. Until then nothing on this page is a certification claim, and any report we do have goes out under a mutual non disclosure agreement.

Data protection

Three things we can state today, with no auditor in the room and no report to wait for.

Data in transit

Every connection to Passa is forced over HTTPS and encrypted with TLS 1.3 or higher. Older protocol versions are refused rather than quietly downgraded.

Data at rest

All datastores are encrypted at rest with AES 256. The fields inside a candidate profile that identify a person directly are encrypted again at the application layer, so a stolen database copy is not a readable CV.

Backups

We take point in time backups of the production database and keep them in the same jurisdiction as the primary, under the same encryption and the same access restrictions. The exact retention window sits in our Data Processing Agreement rather than on this page, so that it is contractual instead of promotional.

Where the data lives

Passa AS is registered in Oslo and operates inside the EEA. Our production environment, our database and our backups run in European Union regions. In the normal course of the service, no candidate record is replicated to a region outside the EEA.

Application and database

Hosted in a European Union region of our cloud provider, with disaster recovery backups held in a second European Union region. We will name the provider and the exact region codes in writing for any customer who asks, and in the Data Processing Agreement.

Files and attachments

CVs, portfolios and anything else a candidate uploads sit in European Union object storage, behind the same access rules and the same encryption as the database.

Transfers out of the EEA

Where a sub processor sits outside the EEA, the transfer is governed by the EU Standard Contractual Clauses incorporated into our Data Processing Agreement. The Clauses stand on their own. We do not lean on an adequacy decision to make them work.

How a candidate file moves

Passa sits between two parties who both hold a relationship with the candidate. That is the real privacy question in a marketplace, so here is the whole route.

European Economic Area

Company

Passa

Agency

The brief travels out to the agencies matched to it, and to nobody else

The candidate file travels back, and only the shortlist reaches the company

Into Passa

A company writes a brief. An agency that accepts the brief submits a candidate, and the candidate file enters Passa at that moment. We do not scrape candidate data, we do not buy candidate lists, and we do not build a shadow database of people nobody submitted.

Through Passa

Matching runs over the brief and the profiles submitted against it. The reasoning attached to a shortlist is generated from that brief and that profile, at the moment you ask for it. Candidate data is not used to train models, ours or anyone else’s, and any model provider we use is contractually forbidden from doing so.

Out of Passa

A shortlist goes to the company that wrote the brief. An agency sees its own submissions and the briefs it has been matched to. It never sees another agency’s candidates and it never sees the rest of your pipeline.

Who can see a candidate file

Employee access

Access to production candidate data is restricted to a small number of named engineers with a business need. It is granted by request, reviewed on a schedule, and removed the day a person changes role or leaves. Nobody in sales and nobody in marketing has it.

Production access

Administrative access to production is logged and auditable. Sensitive operations require a second person to approve them. Every individual who can reach candidate data is a Passa employee under a confidentiality agreement that outlives their contract, and we use no offshore support contractors.

Logging and review

We review the access list every quarter and strip out anything that has gone unused. Access logs are retained so that the question of who read a particular record has an answer rather than an opinion.

Customer side visibility

Inside the product, a company sees the candidates submitted to its own briefs. An agency sees its own submissions and the briefs it has accepted. Neither can see the other side’s wider activity, and no agency can see another agency’s candidates.

Candidate rights, and who answers them

In almost every case Passa is a processor rather than a controller. The company that wrote the brief controls the candidate data it receives, and the agency that introduced the candidate controls its own relationship with that person. We hold the data on their instructions, which is why some requests cannot be settled by us alone.

Send a request to privacy@passa.no. We acknowledge it, tell you who the controller is, and pass it on within five working days. Where we can act ourselves, we do. The statutory deadline for a full response under the GDPR is one month, and that is the clock we work to.

Access

A copy of the personal data we hold about you, and an account of where it came from.

Rectification

Correction of anything inaccurate or incomplete in a profile.

Erasure

Deletion of your data. We remove it from Passa and forward the request to the controller, because a company’s own applicant tracking system is outside our reach. We tell you who we forwarded it to.

Restriction

Processing paused while a dispute about accuracy or lawfulness is settled.

Portability

Your data returned in a structured, commonly used, machine readable format.

Objection

A stop on any processing carried out on the basis of legitimate interests.

Complaint

A complaint to a supervisory authority. In Norway that is Datatilsynet, and you do not need to come through us first.

Retention and deletion

We keep a candidate record for as long as it is being used to fill roles and for as long as the controller instructs us to, unless a longer period is required by law. When a company closes its Passa account, the personal data attached to that account is deleted or irreversibly anonymised, except where we are obliged to retain something for legal or accounting reasons.

There is no fixed number of days printed here, and that is deliberate. A number on a security page becomes a contractual promise the moment a buyer reads it. The retention periods that apply to your account are set out in the Data Processing Agreement, where they can be negotiated, versioned and enforced, and we will walk you through them before anyone signs.

Sub processors

A short list of third parties helps us run the service. The categories are published here. The current named list, with each vendor’s legal jurisdiction, hosting region and the exact fields it receives, carries its own date and goes out on request and with the Data Processing Agreement.

Cloud hosting

Runs the application, the database and the object storage that holds uploaded files. Located in the European Union. This is the only category with access to a complete candidate profile.

Email delivery

Sends transactional messages such as invitations, shortlist notifications and password resets. Receives a name and an email address. Never receives a CV.

Product analytics

Tells us which parts of the product are used and where people get stuck. Receives pseudonymous usage events, not candidate content.

Error monitoring

Captures stack traces when something breaks so that we can fix it. Configured to scrub personal data out of payloads before they leave our servers.

Payments and invoicing

Handles success fee invoicing for hiring companies. Receives company billing details. Never receives candidate data.

We give at least 30 days of notice before adding or replacing a sub processor, and you may object inside that window. Each one is assessed before it is onboarded and reviewed again every year. Anything that would move candidate data outside the EEA is treated as a change to the agreement, not as an implementation detail.

How we build and run it

Code review

Every change to source code is reviewed before it merges. Anything that touches authentication, authorisation or candidate data requires review by a second engineer, and the review includes an explicit note on what the change could be abused to do.

Deployment

Changes ship through an automated pipeline with tests and dependency scanning in front of them. Nobody deploys by hand and nobody edits production directly.

Dependencies

Third party packages are scanned continuously for known vulnerabilities and patched on a schedule. Anything rated critical is taken out of the normal cycle and shipped on its own.

Environments

Production, staging and development are separated. Production data is never copied into staging and never lands on a laptop for debugging. Test environments run on generated data that resembles real profiles without being them.

Monitoring

Infrastructure and application logs are centralised and alert on anomalies. Access to those logs is restricted the same way access to production is, because logs are candidate data too.

People and devices

The team

Everyone who can reach candidate data is a Passa employee in Oslo, under a confidentiality agreement that survives the end of their contract. We use no offshore support contractors and no unvetted freelancers.

Training

Security and data protection training happens at onboarding and again every year. It is written around what a recruitment marketplace actually gets wrong rather than around generic awareness slides.

Devices

Company laptops are managed. Disk encryption, screen lock, automatic updates and a password manager are enforced rather than suggested, and access to Passa systems requires multi factor authentication without exception.

Reporting a vulnerability

If you have found something, we would rather hear it from you than read about it later. There is one address, a person reads it, and you will not be met with a lawyer.

What we expect from you

Send it to security@passa.no before you tell anyone else.

Give us enough detail to reproduce it.

Do not access, change or delete data that is not yours.

No automated scanning against production, and nothing that degrades the service for other people.

What you can expect from us

An acknowledgement within five working days.

A named person on the report and honest updates while it is open.

Credit in the advisory if you want it, and none if you do not.

No legal action against anyone acting in good faith under this policy.

In scope

passa.no, app.passa.no and the Passa API, including anything that exposes a brief, a candidate profile or an account to someone who should not see it.

Out of scope

Raw output from an automated scanner with no proof of exploitability. Missing security headers on their own. Social engineering of our team or our customers. Denial of service. Reports about software we do not run.

We do not run a paid bounty at the moment. If that changes it will be announced here rather than negotiated report by report.

Documents

What exists, what does not, and how to get the ones that do.

Data Processing Agreement

Pre signed by Passa

Pre signed by Passa

Sub processor list, dated

On request

On request

Security overview

On request

On request

Answers to your security questionnaire

On request

On request

Penetration test summary

Planned for 2026

Planned for 2026

SOC 2 Type II report

Not yet available

Not yet available

ISO 27001 certificate

Not yet available

Not yet available

Write to security@passa.no or privacy@passa.no and name the document you need. Anything not already public goes out under a mutual non disclosure agreement, usually the same day.

Questions

Straight answers

Including the ones where the answer is no. If a buyer is going to ask it in the first email, it belongs here instead.

Is Passa SOC 2 certified?

No. We hold no SOC 2 report and we will not imply that we do. A Type II observation window is planned for 2026 and the report will be published here once it is issued. In the meantime we answer security questionnaires in full and will walk you through every control described on this page.

Is Passa ISO 27001 certified?

No. ISO 27001 sits behind SOC 2 in the plan and no date is fixed. If a certificate matters to you more than the controls underneath it, we would rather you knew that now than three weeks into a procurement review.

Who is the controller of a candidate's data?

In almost every case the hiring company that wrote the brief, and the agency that introduced the candidate, are the controllers. Passa is the processor acting on their instructions. That is why some requests have to be routed to them rather than settled by us alone.

Can a candidate ask Passa to delete their data?

Yes, and we act on the part that is ours to act on. We remove the record from Passa and forward the request to the controller, because a company's own applicant tracking system is outside our reach. We tell the candidate who we forwarded it to, so the trail does not go cold.

Which agencies can see my brief?

Only the agencies matched to it, and only once they accept it. An agency sees the brief and its own submissions against it. It never sees another agency's candidates and it never sees the rest of your hiring pipeline.

Do you use candidate data to train models?

No. Candidate data is not used to train models, ours or anyone else's, and any model provider we use is contractually forbidden from doing so. Matching and shortlist reasoning run over your brief and the profiles submitted to it, at the moment you ask for them.

Where is candidate data stored?

In European Union regions, with disaster recovery backups in a second European Union region. Passa AS is registered in Oslo, inside the EEA. Where a sub processor sits outside the EEA, the EU Standard Contractual Clauses in our Data Processing Agreement govern the transfer.

What happens if there is a breach?

We notify affected controllers without undue delay and within 72 hours of becoming aware, which is the deadline the GDPR sets. You get what we know when we know it, including the parts that are still uncertain, and we publish a summary once the people affected have been told.

Can we run our own penetration test?

Yes, against a staging environment with the real architecture and generated data, once scope and timing are agreed in writing. We will not expose live candidate data to a test, including one you are paying for.

Do you sign our Data Processing Agreement or do we sign yours?

Ours is pre signed by Passa and takes effect when you sign up, which is the faster route. If your legal team needs its own paper, send it over and we will review it rather than refuse it.

Contact

Two addresses, and a person behind each.

Vulnerability reports

Data subject requests

For a security overview, the current sub processor list or a copy of the Data Processing Agreement, write to either address and name the document. Both are monitored by the people who built the system, not by a queue.

Passa AS · Oslo, Norway · Registered in the Norwegian Register of Business Enterprises

Curated candidates.

You pay for the hire, not the hunt.

0445 334 1235

Company

Case studies (coming soon)

Blog (coming soon)

© 2026 Passa AS. All rights reserved.

Oslo, Norway

Curated candidates.

You pay for the hire, not the hunt.

0445 334 1235

Company

Case studies (coming soon)

Blog (coming soon)

© 2026 Passa AS. All rights reserved.

Oslo, Norway

Curated candidates.

You pay for the hire, not the hunt.

0445 334 1235

Company

Case studies (coming soon)

Blog (coming soon)

© 2026 Passa AS. All rights reserved.

Oslo, Norway

Curated candidates.

You pay for the hire, not the hunt.

0445 334 1235

Company

Case studies (coming soon)

Blog (coming soon)

© 2026 Passa AS. All rights reserved.

Oslo, Norway