Compliance
Pensti holds no certifications. This page shows which controls in the product support your own compliance work, framework by framework.
This page describes controls in Pensti. It is not legal advice, a certification or a guarantee that your organisation meets a framework.
GDPR
Supported by PenstiThe EU General Data Protection Regulation. The sender of a document is the controller for the signers' data, and Bullmade ApS is the processor.
Controls in Pensti
- Data processing agreement available on request
- Data minimisation: only data needed to document the signature is recorded
- Export of a data subject's personal data (access and portability)
- Erasure or pseudonymisation of personal data
- Configurable retention of signed documents and signers' IP addresses
- Location is derived from the IP address in a local database without passing the IP on
- Data hosted in the EU (Germany)
ePrivacy
Supported by PenstiThe rules on cookies and similar technologies.
Controls in Pensti
- The app uses only strictly necessary cookies: sign-in session, language and selected workspace
- pensti.com uses no tracking or analytics cookies
- No advertising or third-party trackers
AI Act
Supported by PenstiThe EU Artificial Intelligence Act. Pensti's AI drafting is a limited-risk use where transparency and human oversight are central.
Controls in Pensti
- AI-generated drafts are clearly labelled and recorded in the audit trail
- An AI draft is never sent automatically – a person always reviews and approves it
- AI is only used when a user chooses AI drafting
- The description is sent to the AI provider Anthropic; do not use AI drafting for information that must not be shared
Data Act
Supported by PenstiThe EU Data Act, including access to data and switching between cloud services.
Controls in Pensti
- Full workspace export: documents, signed PDFs, evidence and contacts
- Documented REST API (OpenAPI 3.1) for accessing and moving data
- Evidence travels with the signed PDF as machine-readable JSON
ISO/IEC 27001
Pensti is not certifiedThe standard for information security management systems.
Controls in Pensti
- Workspace audit log: members, roles, API keys, webhooks and settings (supports A.8.15 Logging)
- Role-based access and invite-only users (supports A.5.15 and A.5.18)
- Sign-in via Hexclave with MFA and passkeys available
- Encryption in transit (TLS)
NIS2
Pensti is not certifiedThe EU cybersecurity directive. The obligations apply to your organisation; Pensti is a supplier in your supply chain.
Controls in Pensti
- Access control, audit log and scoped API keys (support the measures in Art. 21)
- Security headers and rate limiting
- Documentation of operations and sub-processors available on request
CIS18
Pensti is not certifiedThe CIS Critical Security Controls – 18 prioritised security controls.
Controls in Pensti
- Account management and role-based access control (Controls 5 and 6)
- Exportable audit log (Control 8)
- Data protection in transit (Control 3)
DORA
Pensti is not certifiedThe EU Digital Operational Resilience Act for the financial sector.
Controls in Pensti
- Documentation for your ICT third-party risk assessment available on request
- Exit strategy: full data export and documented API
- Audit log and evidence for every signature
D-Seal
Not obtainedThe Danish labelling scheme for IT security and responsible data ethics in companies.
Controls in Pensti
- Bullmade ApS has not obtained the D-Seal
- The controls on this page can feed into your own assessment
Hosting and sub-processors
- Hosting and database
- Hetzner Online GmbH – EU (Germany)
- SMTP2GO – EU endpoint
- Sign-in
- Hexclave (SSO with MFA and passkeys)
- AI drafting
- Anthropic – only when a user chooses AI drafting