AuthOrigin
Security

Security you can put in front of a regulator

AuthOrigin protects medicines, infant formula and other safety-critical products — so trust is the product. Here's how we protect authenticity and your data, in plain terms.

Authenticity

Protecting what's real

Unclonable codes

Every code is 256-bit random and stored only as a hash. A database leak can never be used to mint valid codes — there's nothing to copy.

Honest verdicts

A genuine product always verifies as genuine. We hold false-negatives to zero; warnings and fraud flags never block a real item — they inform.

Tenant isolation by default

Your data is isolated at the database level with row-level security, enforced by the database itself — not just application code — so it's never visible to another organization.

Your data

Protecting your information

Encrypted in transit & at rest

All traffic is served over TLS. Data is encrypted at rest, and sensitive secrets (signing keys, MFA seeds) are additionally encrypted at the column level and held in a managed key vault.

Data minimisation

We record an approximate country/region for a scan from its IP for fraud detection — we don't store the raw IP alongside it. Consumers share contact details only if they choose to.

Full audit trail

Every state-changing action is recorded to an immutable audit log with the actor and time, so you can see exactly who did what — visible to you in the portal.

Access

Accounts, keys & integrations

Scoped, expiring credentials

API keys carry least-privilege scopes, a mandatory bounded expiry, rotation and revocation, and optional IP allowlists. Secrets are shown once and stored only as hashes.

Strong account security

Role-based access control, multi-factor authentication (required for privileged roles), and a strong password policy. A password change immediately revokes existing sessions.

Signed webhooks

Every webhook delivery is signed with HMAC-SHA256 over a timestamped payload, so you can verify it's genuine and reject replays.

Platform

Secure by construction

Hardened cloud infrastructure

Runs on Microsoft Azure with private networking, a managed key vault for secrets, and least-privilege, credential-less (OIDC) deployments — no long-lived cloud keys.

Secure by construction

Every change runs through automated secret scanning, static application security testing (SAST) and dependency vulnerability scanning before it can ship.

Recall & response built in

A recall flags every affected unit worldwide on the next scan, and suspicious activity is risk-scored in real time — so you can act on a problem the moment it appears.

Compliance & data protection

Where we are — honestly

We build to recognised security practices and design for data-protection regulations (such as the GDPR and Nigeria's NDPR) — including data minimisation, encryption, access controls, audit logging, and honouring access and deletion requests.

We are working toward SOC 2 and ISO 27001. We are not certified yet, and we won't claim to be — when we achieve them, they'll be listed here. In the meantime we're happy to share our current controls, complete a security questionnaire, and provide a Data Processing Agreement on request.

Found a security issue? Please report it to us through the contact page and we'll respond promptly — we welcome responsible disclosure.

Have a security review or questionnaire?

Talk to us — we'll walk your team through our controls and share the documentation you need.