Security
What we can see, and what we cannot
A platform that hosts a passport and resolves it on request necessarily processes the data. Rather than claiming otherwise, this page sets out where our access exists, how it is constrained, and what you can hold outside it.
- Residency
- Selectable, EU available
- Key custody
- HSM or yours
- Access
- Credential-gated
Definition
How is Digital Product Passport data secured?
Passport data is encrypted in transit and at rest, isolated per tenant, and reachable only through scoped credentials whose use is logged. Restricted tiers are gated by verifiable credentials rather than accounts, and signing keys are held in a hardware security module or retained entirely by the issuing organisation.
The distinction that matters in a vendor assessment is between data we process in order to serve the passport, and keys that let someone assert something in your name. The first is unavoidable; the second is yours to keep.
Access model
Who can reach what
| Party | What they can reach | What governs it |
|---|---|---|
| Anyone with the carrier | The public tier of the passport | The product group’s access policy |
| A verified recycler or repairer | Treatment and repair tiers | A credential issued by a trusted party, revocable |
| A market surveillance authority | The compliance dataset and its evidence chain | Regulatory scope, not commercial scope |
| Your own systems | Everything in your tenant | Scoped API keys, per environment and capability |
| CirculeID operations | Production data, for an approved reason | Restricted, reason-required, and logged |
Controls
The controls behind that model
Encryption
In transit and at rest, with keys managed separately from the data they protect.
Tenancy isolation
Your records, events and credentials are separated from every other tenant’s.
Key custody options
Signing keys in a hardware security module, or held entirely by you.
Scoped credentials
Keys are scoped per environment and capability, so an issuer cannot read restricted tiers.
Audit logging
Who read or changed what, and when — including our own operational access.
Data residency
Selectable per tenant, so regulated product data stays in the region you need.
Answers
Frequently asked questions
Can CirculeID staff read our passport data?
Production access is restricted, requires an approved reason, and is logged. We do not claim zero-knowledge: the platform hosts the record and resolves it on request, so it necessarily processes the data. Any vendor claiming otherwise while also serving a public passport is describing something the architecture cannot do.
Where is data held, and can we choose?
Residency is selectable per tenant, and EU-resident deployments keep passport records, events and credentials within the EU. This matters more than usual for passport data, because a market surveillance authority may need to reach it for the lifetime of the product rather than the lifetime of the contract.
Who holds the signing keys?
Either we do, in a hardware security module, or you do, and CirculeID never sees the private key. The second option is more work to operate and is the right choice where the credential asserts something you would not want anyone else able to sign on your behalf — authenticity claims, most obviously.
How is access to restricted tiers controlled?
By verifiable credential rather than by account. A recycler or repairer presents a credential issued by a party the access policy trusts, and the resolver returns the tier that credential entitles them to. Credentials can be revoked, which matters when a facility loses its permit.
What happens in an incident?
Our disclosure policy and response commitments are on the company security page. Reports are acknowledged and triaged before any public discussion, and customers affected by a confirmed issue are notified directly rather than through a status page alone.
Next step
Send us your vendor assessment
We would rather answer the questionnaire directly than have you infer the answers from a page of adjectives.