Compliance

Compliance

Pensti holds no certifications. This page shows which controls in the product support your own compliance work, framework by framework.

This page describes controls in Pensti. It is not legal advice, a certification or a guarantee that your organisation meets a framework.

GDPR

Supported by Pensti

The EU General Data Protection Regulation. The sender of a document is the controller for the signers' data, and Bullmade ApS is the processor.

Controls in Pensti

  • Data processing agreement available on request
  • Data minimisation: only data needed to document the signature is recorded
  • Export of a data subject's personal data (access and portability)
  • Erasure or pseudonymisation of personal data
  • Configurable retention of signed documents and signers' IP addresses
  • Location is derived from the IP address in a local database without passing the IP on
  • Data hosted in the EU (Germany)

ePrivacy

Supported by Pensti

The rules on cookies and similar technologies.

Controls in Pensti

  • The app uses only strictly necessary cookies: sign-in session, language and selected workspace
  • pensti.com uses no tracking or analytics cookies
  • No advertising or third-party trackers

AI Act

Supported by Pensti

The EU Artificial Intelligence Act. Pensti's AI drafting is a limited-risk use where transparency and human oversight are central.

Controls in Pensti

  • AI-generated drafts are clearly labelled and recorded in the audit trail
  • An AI draft is never sent automatically – a person always reviews and approves it
  • AI is only used when a user chooses AI drafting
  • The description is sent to the AI provider Anthropic; do not use AI drafting for information that must not be shared

Data Act

Supported by Pensti

The EU Data Act, including access to data and switching between cloud services.

Controls in Pensti

  • Full workspace export: documents, signed PDFs, evidence and contacts
  • Documented REST API (OpenAPI 3.1) for accessing and moving data
  • Evidence travels with the signed PDF as machine-readable JSON

ISO/IEC 27001

Pensti is not certified

The standard for information security management systems.

Controls in Pensti

  • Workspace audit log: members, roles, API keys, webhooks and settings (supports A.8.15 Logging)
  • Role-based access and invite-only users (supports A.5.15 and A.5.18)
  • Sign-in via Hexclave with MFA and passkeys available
  • Encryption in transit (TLS)

NIS2

Pensti is not certified

The EU cybersecurity directive. The obligations apply to your organisation; Pensti is a supplier in your supply chain.

Controls in Pensti

  • Access control, audit log and scoped API keys (support the measures in Art. 21)
  • Security headers and rate limiting
  • Documentation of operations and sub-processors available on request

CIS18

Pensti is not certified

The CIS Critical Security Controls – 18 prioritised security controls.

Controls in Pensti

  • Account management and role-based access control (Controls 5 and 6)
  • Exportable audit log (Control 8)
  • Data protection in transit (Control 3)

DORA

Pensti is not certified

The EU Digital Operational Resilience Act for the financial sector.

Controls in Pensti

  • Documentation for your ICT third-party risk assessment available on request
  • Exit strategy: full data export and documented API
  • Audit log and evidence for every signature

D-Seal

Not obtained

The Danish labelling scheme for IT security and responsible data ethics in companies.

Controls in Pensti

  • Bullmade ApS has not obtained the D-Seal
  • The controls on this page can feed into your own assessment

Hosting and sub-processors

Hosting and database
Hetzner Online GmbH – EU (Germany)
Email
SMTP2GO – EU endpoint
Sign-in
Hexclave (SSO with MFA and passkeys)
AI drafting
Anthropic – only when a user chooses AI drafting
Read about eIDAS and electronic signatures →Contact usNeed a data processing agreement or documentation for a supplier assessment?