Built securely. Enterprise ready.

Panop is built with security, privacy and operational reliability at its core.

Our platform is designed to meet the requirements of modern enterprise environments through mature security controls, trusted Swiss infrastructure, secure engineering practices and governance processes designed to evolve alongside regulatory, contractual and operational requirements.

Mature controls. Real operational security.

Security is a core component of our platform, operations and culture. Our security program incorporates governance, risk management, secure engineering practices, operational controls, employee security awareness and training, continuous monitoring and compliance practices designed to protect customer data, ensure service availability and support regulatory and contractual requirements.

We maintain documented security policies, standards, and procedures that establish the governance framework for our information security program and guide how security is implemented, managed, and continuously improved.

Security policies cover

  • Information security governance
  • Access control and identity management
  • Secure software development
  • Vulnerability management
  • Incident response
  • Data classification and handling
  • Cryptography and key management
  • Vendor and third-party risk management
  • Business continuity and disaster recovery
  • Endpoint and device security

Policies are reviewed regularly and updated to address evolving threats, business requirements and regulatory obligations.

Security controls include

  • Data encryption in transit and at rest
  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)
  • Role-Based Access Control (RBAC)
  • Centralized identity management
  • Least-privilege access principles
  • Segregation of duties
  • Secure onboarding and offboarding processes
  • Periodic access reviews
  • Audit logging of privileged activities
  • Vulnerability monitoring and remediation processes
  • Incident management and response procedures
  • Business continuity and recovery measures
  • Continuous monitoring and alerting
  • Web Application Firewall (WAF)

Secure by design. Validated Continuously.

Security is integrated throughout Panop’s software development lifecycle.

Our engineering teams follow secure coding practices and security-by-design principles supported by

  • Peer-reviewed code changes through pull requests
  • Mandatory approval workflows before code can be merged
  • Automated testing throughout the continuous integration process
  • Static security scanning
  • Dependency security scanning
  • Controlled build and deployment pipelines
  • Separation of development, testing and production environments

Software artifacts are generated through controlled build pipelines and cryptographically signed before deployment where applicable.

Production releases follow structured change management processes including

  • Code review and approval requirements
  • Automated validation and testing
  • Release authorization controls
  • Deployment traceability and auditability
  • Rollback procedures supporting rapid recovery when required

Reliability built for continuous operations.

Panop is designed to support reliability, resilience and operational continuity through:

  • Infrastructure monitoring and alerting
  • Capacity planning and performance monitoring
  • Backup and recovery procedures
  • Incident response and escalation processes
  • Redundant system components where appropriate

Service availability and operational status can be monitored at:

Panop Status

Privacy built into every process.

Panop applies administrative, technical and organizational safeguards designed to protect customer information throughout its lifecycle.

This includes:

  • Personal data management controls
  • Data retention policies
  • Access governance processes
  • Opt-in and opt-out management procedures
  • Controlled access to sensitive information
  • Documented data handling practices

Access to systems and customer data is restricted to authorized personnel who require access to perform their job responsibilities. Access requests are reviewed, approved and periodically reassessed according to documented procedures.

Privacy considerations are integrated throughout the platform lifecycle and operational processes.

Confidentiality and Data Protection.

Confidential information is handled according to documented security policies and data handling procedures.

Customer information is protected through multiple layers of security controls.

Encryption in transit is enforced using industry-standard protocols such as TLS, while customer data stored within our systems is protected through strong encryption mechanisms at rest.

Encryption key management processes are implemented to support the confidentiality and integrity of protected information.

Swiss sovereignty enterprise-grade protection.

Customer data is hosted in Switzerland and benefits from enterprise-grade physical and logical security controls, certified data centers and a shared responsibility model that clearly defines infrastructure security responsibilities between providers and customers.

Our infrastructure partners develop and maintain compliance frameworks incorporating:

  • Security governance
  • Privacy controls
  • Risk management
  • Network security
  • Endpoint protection
  • Cryptographic controls
  • Business continuity
  • Continuous monitoring practices

Their infrastructure is independently audited and aligned with internationally recognized regulatory and security frameworks, including:

GDPR

SOC 2

HIPAA

FDPA

Swiss Federal Data Protection Act

This approach combines Swiss data residency with enterprise-grade operational practices designed to support strong security, resilience and data protection requirements.

Clear boundaries. Shared accountability.

In our cloud environment, security and compliance is a shared responsibility between Panop, our cloud service providers and our customers. The division of responsibility is as follows.

Security of the cloud

Cloud providers

  • Infrastructure The underlying infrastructure, including data centers, networks and hardware.
  • Software The hypervisor and orchestration software that provide the cloud services.
  • Physical security Protecting the physical infrastructure against unauthorized access, damage and interference.

Security in the cloud

Panop

  • Data Protecting the confidentiality, integrity and availability of our data in the cloud.
  • Applications Ensuring our applications are secure and free of vulnerabilities.
  • Access management Controlling who has access to our resources, including multi-factor authentication and least-privilege principles.
  • Configuration Properly configuring our cloud resources to prevent security misconfigurations.

Security of your environment

Customers

  • User data Protecting the confidentiality, integrity and availability of their data.
  • User access management Managing who has access to their data and resources.
  • User configuration Properly configuring their user settings to maintain security.
  • Customer-managed scanners Scanners deployed, hosted or operated by customers remain their responsibility.
Shared responsibility matrix
ResponsibilityCloud providerPanopCustomer
Infrastructure Cloud provider
Software Cloud provider
Physical security Cloud provider
Data Panop
Applications Panop
Access management Panop
Configuration Panop
User data Customer
User access management Customer
User configuration Customer
Customer-managed scanners Customer

Scanners deployed, hosted or operated by customers in their own environment remain the customer’s responsibility. This includes installation, configuration, credentials, access control, maintenance, updates and the security of data processed by those scanners.

By understanding and adhering to this shared responsibility model, we can ensure a secure and compliant cloud environment.

A trusted Swiss ecosystem.

Panop is built and operated in Switzerland, supported by Innosuisse Initial and Core Coaching and Trust Valley, and developed in partnership with leading Swiss AI research institutions.

As part of a trusted Swiss ecosystem, Panop gives you full control over data sovereignty: your exposure intelligence, the most sensitive data your organisation generates, never crosses a border you have not explicitly chosen.

Innosuisse

The Swiss Innovation Agency. Panop is supported through Innosuisse Initial and Core Coaching, backing applied research and the development of sovereign security technology in Switzerland.

Innosuisse

Trust Valley

Western Switzerland’s cybersecurity and digital trust cluster. Panop is backed through Tech4Trust, alongside research institutions and operators building trusted digital infrastructure.

Trust Valley

Cloud Security Alliance

The Cloud Security Alliance (CSA) Security, Trust, Assurance and Risk (STAR) program is a globally recognized framework that promotes transparency in cloud security. 

Our CSA STAR Level 1 registration demonstrates our commitment to openly documenting our security controls and aligning them with the CSA Cloud Controls Matrix (CCM), enabling customers to assess our cloud security practices with confidence.

CSA Star Registry

Trust is a continuous commitment.

Panop’s infrastructure, operational controls and governance processes are designed around industry-recognized security principles and modern enterprise expectations.

Formal certification processes are currently underway, with additional audit and compliance milestones planned over the coming months.

While certifications are in progress, our platform, infrastructure and operational practices have been designed from the outset to align with the security, privacy and governance standards expected by enterprise organizations.

Additional security documentation, compliance information and supporting audit materials can be provided upon request.