Trust & Security
SnapKey controls access to buildings and critical infrastructure, so the way we host, protect and operate the platform has to stand up to scrutiny. This page collects the documents we share with our customers’ security, legal and procurement teams, and a short summary of what we do.
Documents
Short English-language summaries, kept current and verified against production. Open them in the browser or copy a link to forward.
What SnapKey does
The ten commitments behind the Security Overview, in one place.
API and database hosted in AWS eu-north-1 (Stockholm); all customer data stays in the EU/EEA.
TLS 1.2+ in transit and AES-256 at rest, with keys held in AWS KMS.
Two-factor authentication an account can enforce for every user, and enterprise SSO via SAML 2.0/OIDC with SCIM.
Tenant isolation: every account and location is kept apart, and every request is scoped to it.
Dependency scanning on every change, with a software bill of materials (SBOM).
An audit log of every administrative action, kept for 24 months.
External availability monitoring, published at status.snapkey.dk.
Encrypted backups with a 5-minute recovery point objective.
Affected customers notified of security incidents within 24 hours of SnapKey becoming aware.
Responsible vulnerability disclosure via security.txt.
Contact
Security questions, vulnerability reports and everything else.
Security and vulnerability reports: security@snapkey.dk
Support and general questions: support@snapkey.dk