
Pakera
Trust Center
Security, privacy, and compliance are at the core of everything we build. Explore how Pakera protects your data and maintains high standards of enterprise trust.
99.6%
Uptime SLA
ISO 27001
In Progress
GDPR
Compliant
AES-256-GCM
Data-at-Rest Encryption
TLS 1.3
Transport Encryption
bcrypt
Password Hashing
Pakera adheres to the rigorous international security and compliance frameworks.
Certification of the Information Security Management System. Pakera is working to implement a comprehensive ISMS to protect customer data from threats and vulnerabilities.
Full compliance with the EU General Data Protection Regulation. We implement privacy by design and ensure lawful data processing for all EU customers.
Pakera is designed to support compliance with the EU Packaging and Packaging Waste Regulation 2025/40, enabling full packaging transparency and documentation.
Enforced
AES-256-GCM Encryption
All data at rest and in transit is encrypted using AES-256-GCM and TLS 1.3 protocols. Zero plaintext storage - your data is always encrypted.
Optional
Bring Your Own Key (BYOK)
Available for Business & Enterprise subscriptions
Optional
SSO, MFA & Passkeys
Secure access with single sign-on, multi-factor authentication, and passkeys. Give teams centralized identity control, stronger verification, and passwordless sign-in.
SSO only available for Enterprise subscriptions
Pakera is built with security at every layer - from infrastructure to application to organizational process.
Pakera operates on a highly available cloud infrastructure in Germany. Physical security measures, redundant power supplies, and network isolation provide additional reliability. No data is transferred to third countries when using Pakera workflow functions.
Role-Based Access Control (RBAC), SSO, Passkeys and Multi-Factor Authentication (MFA) enable targeted control of permissions. Security-related activities are logged in a traceable manner.
Regular penetration tests conducted by qualified security experts help identify potential vulnerabilities early on and address them in a structured manner.
Automated security checks support the continuous detection of vulnerabilities in code and dependencies. Critical findings are prioritized and addressed according to defined processes.
Security Posture
Encryption Coverage
100%
GDPR Controls Implemented
100%
Security Training Completion
100%
ISO 27001 Controls
83%
0
Data Breaches Ever
24h
Critical Patch Response
365
Days/Year Monitored
SSO in Progress
Enterprise Single Sign-On
Daily Backups
Automated & encrypted
Audit Logs
Full activity traceability
Network Isolation
VPC with strict egress rules
Pakera processes personal data in a transparent manner and for specific purposes. In doing so, we adhere to the principles of the GDPR and assist you in exercising your data protection rights.
We limit the processing of personal data to what is necessary for the respective purpose and use it exclusively for specified processing purposes.
You may request the correction of inaccurate personal data or the completion of incomplete personal data. We will process such requests within the time limits prescribed by law.
Under the terms of the GDPR, you may request the deletion of your personal data. We process such requests in accordance with applicable legal requirements.
Under the provisions of the GDPR, you have the right to object to the processing of your personal data or to request that such processing be restricted. Please feel free to contact us regarding this matter.
Data Protection Officer
If you have any questions about data protection or the processing of your personal data, you can contact our Data Protection Officer directly.
Pakera operates its central platform infrastructure and stores all associated project and application data exclusively in Germany. For selected support services, documented subprocessors may be used, including service providers operating internationally. Where necessary, these subprocessors are engaged on the basis of appropriate data processing agreements and in accordance with suitable contractual, technical, and organizational safeguards.
German Server Infrastructure
Data centers in Frankfurt, Limburg, and Nuremberg
No transfers of core data to third countries
Customer data encrypted in transit and at rest
Physically secure data centers with early fire detection systems
91% green electricity used for servers (OVH Cloud)
Core application data is stored in Germany in accordance with the agreed-upon hosting and contractual terms. The provisions governing data processing and the use of subcontractors are documented in the Data Processing Agreement (DPA).
Automated backups facilitate data recovery in the event of a failure. Backups are encrypted and stored separately from production data. They are retained for 14 days.
A comprehensive Data Processing Agreement (DPA) is available for our customers here. It addresses Art. 28 GDPR requirements, technical and organizational measures, subprocessors, and international data transfers, including EU Standard Contractual Clauses where applicable.
Server certifications
Our primary hosting provider maintains a broad portfolio of internationally recognized security, privacy, healthcare, financial-services, and environmental standards.
ISO 27001
ISO 27017
ISO 27018
SOC 1–3
HDS
HIPAA
EBA
C5
ACN
ENS
ACPR PSEE
G-Cloud UK
ISO 14001
ISO 50001
ISO 9001
GDPR
Pakera complies with relevant regulatory requirements for industrial software, information security, and packaging processes.
GDPR — General Data Protection Regulation
EU Regulation 2016/679 · Full Compliance
Compliant
PPWR — Packaging and Packaging Waste Regulation
EU PPWR 2025/40 · Platform Ready
Ready
BDSG — Federal Data Protection Act
German Federal Data Protection Act · Full Compliance
Compliant
ISO 27001
Information Security Management System · In Progress
In Progress
Detailed information about how Pakera processes your data, including data retention, usage, and sharing practices.
Pakera stores customer and project data in accordance with the agreed-upon contractual terms and defined retention periods. Upon termination of the contractual relationship or upon receipt of a valid request for deletion, data will be deleted in accordance with applicable legal and contractual requirements.
CAD files and packaging designs
Pakera does not disclose core data, project data, geometry data, or other process-related information to third parties. To the extent necessary for technical operations or select marketing functions, certain data may be processed by service providers bound by contract. Such processing is carried out exclusively on behalf of Pakera and in accordance with relevant data processing agreements.
Documented and contractually bound service providers
Pakera uses selected, contractually bound subcontractors for clearly defined technical and operational purposes. The service providers used and relevant information regarding data processing are listed transparently below.
Transfer Mechanism
(for third countries)
Entity /Server location
EU Standard Contractual
Clauses + EU-US Data
Privacy Framework, if applicable
Germany / processing on servers in Germany
EU Standard Contractual
Clauses + EU-US Data
Privacy Framework, if applicable
USA / processing on global servers
EU Standard Contractual
Clauses + EU-US Data
Privacy Framework, if applicable
Ireland / processing on servers in EU
EU Standard Contractual
Clauses + EU-US Data
Privacy Framework, if applicable
Ireland / processing on global servers
EU Standard Contractual
Clauses + EU-US Data
Privacy Framework, if applicable
USA / processing on servers in Germany