Security
Trust Center. Everything you need for procurement, DPIA and data protection decisions, gathered in one place.
We only write what is true today. What we are working toward is clearly marked as in progress. If something is missing from your requirements specification, get in touch.
Partnership
Secure operation of Praktorests on shared responsibility
Secure operation is a partnership. Prakto is built for transparency and control at every step: we maintain the security foundation and operational stability, while you as an education provider or company define the policies and boundaries that suit your operation.
What we ensure
- Prakto runs within the boundaries you have set
- Enterprise-grade security and operational stability
- Compliance with applicable data protection requirements
- The platform's availability and performance
- Ongoing testing, monitoring and vulnerability management
What you define
- Prakto's goals and intended uses within your organisation
- Scope, roles and boundaries for your organisation
- Procedures for more complex or sensitive workflows
- Which integrations and data connections to enable
- Requirements for testing, approval and validation before production
Data storage and region
All data in the EU,no exceptions
Customer data, authentication and background processing take place exclusively within the EU/EEA. We maintain a public list of all subprocessors with region and purpose, and we do not change providers without notifying customers who have the right to object. For public-sector customers we offer a data processing agreement in connection with signing the contract.
EU regions
Primary infrastructure with providers whose data centres are within the EU/EEA. Persistent customer data never leaves the EU.
Public subprocessor list
A list with region, purpose and data categories. Subscribers receive advance notice of any change.
DPA on request
A standard DPA is available as a downloadable PDF. A tailored version is provided in connection with signing the contract for public-sector customers.
Subprocessors and providers
A limited number of carefully selected subprocessors for hosting, email delivery, payments and operational monitoring. All within the EU/EEA or via an approved transfer mechanism under Article 46 GDPR. Due diligence on new providers covers security documentation, certification status and references from Swedish public-sector customers.
Data protection and privacy
Data protection standardsyou can rely on
Prakto meets demanding requirements for data protection, privacy and responsible AI. Every layer of the platform, from infrastructure to model management, is built to protect your operation and your users.
Information security
Independent reviews confirm that data is encrypted, monitored and protected with enterprise controls.
- ISO 27001 (framework)
- SOC 2 Type II in progress
AI governance
Responsible AI with bias detection, risk management and transparent decision processes.
- ISO 42001 (framework)
- Model cards per use case
Privacy protection
The customer's data remains the customer's. We fully comply with GDPR and Swedish data protection practice.
- GDPR compliance
- Skolverket guidance for pupil data
Data protection in AI training
We never train models on your operational data without an explicit agreement. Anonymised data is deleted within 30 days.

Identity and access
Identity and access,with no blind spots
Every sign-in passes through your identity provider. Role-based access control and tenant isolation ensure that data never leaks between schools or companies. All events are recorded in an audit trail available to data protection officers on request.
Identity providers
Who signs in
Students
Sign in with BankID or email and password. Access limited to their own profile, their own applications and their own communication.
- BankID
- Email + password
- 2FA (optional)
School and company admins
SSO via your identity provider. Two-factor authentication is enforced. They see only their own organisation's data.
- SSO (Entra ID / Google)
- 2FA required
- SCIM provisioning
Platform admin (Prakto)
SSO + hardware key. Access to customer data requires an approved support ticket ID and is logged visibly for the customer.
- SSO + WebAuthn
- Just-in-time access
- Tamper-evident audit
Encryption
Four layersof encrypted data
Sensitive information is encrypted at four levels: at rest, in transit, at the application layer and in backups. Each level has its own key management and its own rotation schedule. The spec below is the same one we provide as a procurement appendix.
ENCRYPTION SPEC
- AT REST
AES-256-GCM
Disk encryption on all persistent volumes and databases.
- IN TRANSIT
TLS 1.2+ · PFS · modern cipher suite
Perfect forward secrecy on all public endpoints.
- APP LAYER
Per-environment keys · scheduled rotation
Access keys, secrets, password hashes and BankID signatures are encrypted before storage.
- BACKUP
AES-256 · TLS in transit · access-logged
A limited group has access. All restores are logged.
- SSLv3
- TLS 1.0
- TLS 1.1
- Passwords are stored hashed with Argon2id, never in plain text.
- Key material is kept in a managed KMS, separate per environment.
Integrations
Connect Prakto withthe systems you already use
All data exchange with external systems takes place over TLS 1.2+ with authenticated tokens and clearly defined data contracts. No shared passwords, no open network paths, no files exported over email.
LMS integration
Sync students, courses, enrolments and grades with Moodle and Canvas over encrypted APIs. Placements, supervisors and results flow back into the learning platform without manual export.
Communication
Send notifications about new placements, approvals and warning flags directly to Slack and Microsoft Teams channels via signed webhooks. The right person reacts in seconds, not days.
SSO and sign-in
Let students and staff sign in with the school's Microsoft 365 or Google Workspace accounts via Entra ID and Google SSO. No extra password, no parallel user directory, no synced local database.
Webhooks and automation
Send any event in Prakto as signed JSON to your own HTTPS endpoint. Build internal automations, from CRM updates to reporting pipelines, with verifiable sender signatures.

FAQ
Frequently asked questions
Answers to the questions we most often get from procurement teams, data protection officers, IT managers and security researchers.
Where do I send security questions from procurement or a data protection officer?
Send a formal request to security@prakto.se. We reply within two business days and attach relevant documentation (DPA, subprocessor list, security description).
How do I report a security vulnerability?
Send technical details to security@prakto.se. We normally reply the same day and remediate valid issues according to severity. We take no legal action against good-faith reporters.
Where can I see ongoing incidents and operational history?
Real-time status and history are available at status.prakto.se. Subscribe to updates via RSS or email directly on the status page.
How do I obtain the DPA and full security documentation?
The standard DPA, subprocessor list, privacy policy and SLA are available for download at the bottom of this page. For a public-sector-adapted DPA, contact security@prakto.se.
Does Prakto train AI models on our data?
No. We never train models on your operational data without an explicit agreement. Anonymised data used for model evaluation is deleted within 30 days.
Where is our data stored?
Customer data, authentication and background processing take place exclusively within the EU/EEA. We do not change providers without notifying customers who have the right to object.