CirculeID

Security

What we can see, and what we cannot

A platform that hosts a passport and resolves it on request necessarily processes the data. Rather than claiming otherwise, this page sets out where our access exists, how it is constrained, and what you can hold outside it.

Residency
Selectable, EU available
Key custody
HSM or yours
Access
Credential-gated

Definition

How is Digital Product Passport data secured?

Passport data is encrypted in transit and at rest, isolated per tenant, and reachable only through scoped credentials whose use is logged. Restricted tiers are gated by verifiable credentials rather than accounts, and signing keys are held in a hardware security module or retained entirely by the issuing organisation.

The distinction that matters in a vendor assessment is between data we process in order to serve the passport, and keys that let someone assert something in your name. The first is unavoidable; the second is yours to keep.

Access model

Who can reach what

Written the way a vendor assessment asks it, rather than as a list of reassuring adjectives.
Access to passport data by party and the control that governs it
PartyWhat they can reachWhat governs it
Anyone with the carrierThe public tier of the passportThe product group’s access policy
A verified recycler or repairerTreatment and repair tiersA credential issued by a trusted party, revocable
A market surveillance authorityThe compliance dataset and its evidence chainRegulatory scope, not commercial scope
Your own systemsEverything in your tenantScoped API keys, per environment and capability
CirculeID operationsProduction data, for an approved reasonRestricted, reason-required, and logged

Controls

The controls behind that model

  • Encryption

    In transit and at rest, with keys managed separately from the data they protect.

  • Tenancy isolation

    Your records, events and credentials are separated from every other tenant’s.

  • Key custody options

    Signing keys in a hardware security module, or held entirely by you.

  • Scoped credentials

    Keys are scoped per environment and capability, so an issuer cannot read restricted tiers.

  • Audit logging

    Who read or changed what, and when — including our own operational access.

  • Data residency

    Selectable per tenant, so regulated product data stays in the region you need.

Answers

Frequently asked questions

Can CirculeID staff read our passport data?

Production access is restricted, requires an approved reason, and is logged. We do not claim zero-knowledge: the platform hosts the record and resolves it on request, so it necessarily processes the data. Any vendor claiming otherwise while also serving a public passport is describing something the architecture cannot do.

Where is data held, and can we choose?

Residency is selectable per tenant, and EU-resident deployments keep passport records, events and credentials within the EU. This matters more than usual for passport data, because a market surveillance authority may need to reach it for the lifetime of the product rather than the lifetime of the contract.

Who holds the signing keys?

Either we do, in a hardware security module, or you do, and CirculeID never sees the private key. The second option is more work to operate and is the right choice where the credential asserts something you would not want anyone else able to sign on your behalf — authenticity claims, most obviously.

How is access to restricted tiers controlled?

By verifiable credential rather than by account. A recycler or repairer presents a credential issued by a party the access policy trusts, and the resolver returns the tier that credential entitles them to. Credentials can be revoked, which matters when a facility loses its permit.

What happens in an incident?

Our disclosure policy and response commitments are on the company security page. Reports are acknowledged and triaged before any public discussion, and customers affected by a confirmed issue are notified directly rather than through a status page alone.

Next step

Send us your vendor assessment

We would rather answer the questionnaire directly than have you infer the answers from a page of adjectives.

Index