Security you can put in front of a regulator
AuthOrigin protects medicines, infant formula and other safety-critical products — so trust is the product. Here's how we protect authenticity and your data, in plain terms.
Protecting what's real
Unclonable codes
Every code is 256-bit random and stored only as a hash. A database leak can never be used to mint valid codes — there's nothing to copy.
Honest verdicts
A genuine product always verifies as genuine. We hold false-negatives to zero; warnings and fraud flags never block a real item — they inform.
Tenant isolation by default
Your data is isolated at the database level with row-level security, enforced by the database itself — not just application code — so it's never visible to another organization.
Protecting your information
Encrypted in transit & at rest
All traffic is served over TLS. Data is encrypted at rest, and sensitive secrets (signing keys, MFA seeds) are additionally encrypted at the column level and held in a managed key vault.
Data minimisation
We record an approximate country/region for a scan from its IP for fraud detection — we don't store the raw IP alongside it. Consumers share contact details only if they choose to.
Full audit trail
Every state-changing action is recorded to an immutable audit log with the actor and time, so you can see exactly who did what — visible to you in the portal.
Accounts, keys & integrations
Scoped, expiring credentials
API keys carry least-privilege scopes, a mandatory bounded expiry, rotation and revocation, and optional IP allowlists. Secrets are shown once and stored only as hashes.
Strong account security
Role-based access control, multi-factor authentication (required for privileged roles), and a strong password policy. A password change immediately revokes existing sessions.
Signed webhooks
Every webhook delivery is signed with HMAC-SHA256 over a timestamped payload, so you can verify it's genuine and reject replays.
Secure by construction
Hardened cloud infrastructure
Runs on Microsoft Azure with private networking, a managed key vault for secrets, and least-privilege, credential-less (OIDC) deployments — no long-lived cloud keys.
Secure by construction
Every change runs through automated secret scanning, static application security testing (SAST) and dependency vulnerability scanning before it can ship.
Recall & response built in
A recall flags every affected unit worldwide on the next scan, and suspicious activity is risk-scored in real time — so you can act on a problem the moment it appears.
Where we are — honestly
We build to recognised security practices and design for data-protection regulations (such as the GDPR and Nigeria's NDPR) — including data minimisation, encryption, access controls, audit logging, and honouring access and deletion requests.
We are working toward SOC 2 and ISO 27001. We are not certified yet, and we won't claim to be — when we achieve them, they'll be listed here. In the meantime we're happy to share our current controls, complete a security questionnaire, and provide a Data Processing Agreement on request.
Found a security issue? Please report it to us through the contact page and we'll respond promptly — we welcome responsible disclosure.
Have a security review or questionnaire?
Talk to us — we'll walk your team through our controls and share the documentation you need.
AuthOrigin