Visamundi

· Security

Your documents are worth a safewe treat them like one

Passport, supporting documents, ID photos, payment data. Here is concretely how Visamundi protects this information, where it is stored, and who can access it.

EU hosting (France)TLS 1.3 + AES-256 encryptionRegular audits

Independent audit

Our latest BonjourCyber audit

In 2026, independent firm BonjourCyber audited the cybersecurity of our infrastructure and applications. Verdict: passed with no major reservation. An external review — because trust is proven, not claimed.

Date
2026
Scope
Infra & applications
Result
Passed
BonjourCyber audit · 2026Passed
BonjourCyber

Independent cybersecurity audit passed with no major reservation.

🇪🇺 EU-hostedAES-256

What we process

The data you entrust to us

To produce a visa, ETA, or arrival card, certain documents are mandatory. We never ask for more than what the consular administration requires.

  • Passport

    Scan or photo of the ID page. Used to pre-fill the consular form.

  • ID photo

    Format required by the destination. Auto-cropping if needed.

  • Travel documents

    Plane ticket, hotel booking, accommodation proof. Required by some countries.

  • Personal information

    Civil status, profession, address — to fill the official form.

  • Payment

    Card or SEPA. No card number is stored with us: everything transits encrypted via Stripe.

  • Previous visas

    Pages of previously obtained visas, if the destination requires history. Storage limited to the file duration.

Technical measures

Six lines of defense, in plain English

No jargon, no vague promises. Here's exactly what protects your data at every step.

  • Encryption at rest

    All stored data is AES-256 encrypted on disk. Attachments (passports, photos) sit on private object storage, never publicly accessible.

  • Encryption in transit

    TLS 1.3 mandatory on all connections. HSTS enabled on all our domains. No data travels in clear text, even internally between our services.

  • EU hosting

    Databases and storage hosted within the European Union (France and Germany). No transfer outside the EU for traveler data.

  • Strict access control

    Mandatory 2FA for our team. Role-based access (RBAC): an agent only sees files they're assigned to. All accesses are logged.

  • Data minimization

    We only collect what is strictly necessary for your formality. Data is erased or anonymized as soon as the legal retention period ends.

  • Audits & logging

    Access logs kept 12 months, quarterly security review, automated vulnerability scanning on infrastructure and application code.

Under the hood

Tech stack & subprocessors

Full transparency on our infrastructure providers. All our subprocessors are GDPR-compliant and host data within the EU (or rely on Standard Contractual Clauses for the rare exceptions).

Database
Supabase (EU region — Frankfurt)

Managed PostgreSQL, AES-256 encryption at rest, Row Level Security enabled.

Frontend & API
Netlify (Europe region)

Edge functions and CDN, TLS 1.3 enforced, Let's Encrypt certificates auto-renewed.

Payments
Stripe (PCI DSS Level 1)

Card numbers never reach our servers. Tokenization on Stripe's side.

Transactional email
Brevo (EU)

Customer and support notifications. DKIM/SPF/DMARC active on all domains.

$ Vulnerability Disclosure

Found a vulnerability? Tell us.

We welcome good-faith security reports. No public bug bounty, but we acknowledge every useful report and prioritize fixes — always within a legal framework that protects you.

it@visamundi.co
  • How to report

    Email it@visamundi.co. Describe the issue type, the URL or feature affected, steps to reproduce, and estimated impact.

  • In scope

    All our visamundi.co and visamundi.app domains, the public API, and partner SaaS. Out of scope: third-party services (Stripe, Supabase, Netlify) — report those to them directly.

  • Not accepted

    Noisy automated scans, social engineering against our teams, denial of service, unauthorized access to real traveler data. Use test accounts.

  • Safe harbor

    Good-faith research compliant with this policy will not be prosecuted. We commit to keeping you informed on fixes and crediting you if you wish.

Going further

Personal data, AI, compliance

Technical security only makes sense with clear governance. Read our Privacy Policy and AI Manifesto for the full framework.

Travelers data security — Visamundi