Skip to content

Security

Trust Center. Everything you need for procurement, DPIA and data protection decisions, gathered in one place.

We only write what is true today. What we are working toward is clearly marked as in progress. If something is missing from your requirements specification, get in touch.

Partnership

Secure operation of Praktorests on shared responsibility

01

Secure operation is a partnership. Prakto is built for transparency and control at every step: we maintain the security foundation and operational stability, while you as an education provider or company define the policies and boundaries that suit your operation.

What we ensure

  • Prakto runs within the boundaries you have set
  • Enterprise-grade security and operational stability
  • Compliance with applicable data protection requirements
  • The platform's availability and performance
  • Ongoing testing, monitoring and vulnerability management

What you define

  • Prakto's goals and intended uses within your organisation
  • Scope, roles and boundaries for your organisation
  • Procedures for more complex or sensitive workflows
  • Which integrations and data connections to enable
  • Requirements for testing, approval and validation before production

Data storage and region

All data in the EU,no exceptions

02

Customer data, authentication and background processing take place exclusively within the EU/EEA. We maintain a public list of all subprocessors with region and purpose, and we do not change providers without notifying customers who have the right to object. For public-sector customers we offer a data processing agreement in connection with signing the contract.

GDPR
  • EU regions

    Primary infrastructure with providers whose data centres are within the EU/EEA. Persistent customer data never leaves the EU.

  • Public subprocessor list

    A list with region, purpose and data categories. Subscribers receive advance notice of any change.

  • DPA on request

    A standard DPA is available as a downloadable PDF. A tailored version is provided in connection with signing the contract for public-sector customers.

  • Subprocessors and providers

    A limited number of carefully selected subprocessors for hosting, email delivery, payments and operational monitoring. All within the EU/EEA or via an approved transfer mechanism under Article 46 GDPR. Due diligence on new providers covers security documentation, certification status and references from Swedish public-sector customers.

Data protection and privacy

Data protection standardsyou can rely on

03

Prakto meets demanding requirements for data protection, privacy and responsible AI. Every layer of the platform, from infrastructure to model management, is built to protect your operation and your users.

Information security

Independent reviews confirm that data is encrypted, monitored and protected with enterprise controls.

  • ISO 27001 (framework)
  • SOC 2 Type II in progress

AI governance

Responsible AI with bias detection, risk management and transparent decision processes.

  • ISO 42001 (framework)
  • Model cards per use case

Privacy protection

The customer's data remains the customer's. We fully comply with GDPR and Swedish data protection practice.

  • GDPR compliance
  • Skolverket guidance for pupil data

Data protection in AI training

We never train models on your operational data without an explicit agreement. Anonymised data is deleted within 30 days.

FIG 3.A
Data protection and privacy, frameworks and certifications

Identity and access

Identity and access,with no blind spots

04

Every sign-in passes through your identity provider. Role-based access control and tenant isolation ensure that data never leaks between schools or companies. All events are recorded in an audit trail available to data protection officers on request.

Identity providers

Who signs in

  • Students

    Sign in with BankID or email and password. Access limited to their own profile, their own applications and their own communication.

    • BankID
    • Email + password
    • 2FA (optional)
  • School and company admins

    SSO via your identity provider. Two-factor authentication is enforced. They see only their own organisation's data.

    • SSO (Entra ID / Google)
    • 2FA required
    • SCIM provisioning
  • Platform admin (Prakto)

    SSO + hardware key. Access to customer data requires an approved support ticket ID and is logged visibly for the customer.

    • SSO + WebAuthn
    • Just-in-time access
    • Tamper-evident audit

Encryption

Four layersof encrypted data

05

Sensitive information is encrypted at four levels: at rest, in transit, at the application layer and in backups. Each level has its own key management and its own rotation schedule. The spec below is the same one we provide as a procurement appendix.

ENCRYPTION SPEC

PRAKTO/05REV 2026-05
  • AT REST

    AES-256-GCM

    Disk encryption on all persistent volumes and databases.

  • IN TRANSIT

    TLS 1.2+ · PFS · modern cipher suite

    Perfect forward secrecy on all public endpoints.

  • APP LAYER

    Per-environment keys · scheduled rotation

    Access keys, secrets, password hashes and BankID signatures are encrypted before storage.

  • BACKUP

    AES-256 · TLS in transit · access-logged

    A limited group has access. All restores are logged.

REJECTED
  • SSLv3
  • TLS 1.0
  • TLS 1.1
  • Passwords are stored hashed with Argon2id, never in plain text.
  • Key material is kept in a managed KMS, separate per environment.

Integrations

Connect Prakto withthe systems you already use

06

All data exchange with external systems takes place over TLS 1.2+ with authenticated tokens and clearly defined data contracts. No shared passwords, no open network paths, no files exported over email.

  • LMS integration

    Sync students, courses, enrolments and grades with Moodle and Canvas over encrypted APIs. Placements, supervisors and results flow back into the learning platform without manual export.

  • Communication

    Send notifications about new placements, approvals and warning flags directly to Slack and Microsoft Teams channels via signed webhooks. The right person reacts in seconds, not days.

  • SSO and sign-in

    Let students and staff sign in with the school's Microsoft 365 or Google Workspace accounts via Entra ID and Google SSO. No extra password, no parallel user directory, no synced local database.

  • Webhooks and automation

    Send any event in Prakto as signed JSON to your own HTTPS endpoint. Build internal automations, from CRM updates to reporting pipelines, with verifiable sender signatures.

Prakto integrations: Moodle, Canvas, Slack, Teams, Entra ID, Google Workspace and Webhook

FAQ

Frequently asked questions

07

Answers to the questions we most often get from procurement teams, data protection officers, IT managers and security researchers.

  • Where do I send security questions from procurement or a data protection officer?

    Send a formal request to security@prakto.se. We reply within two business days and attach relevant documentation (DPA, subprocessor list, security description).

  • How do I report a security vulnerability?

    Send technical details to security@prakto.se. We normally reply the same day and remediate valid issues according to severity. We take no legal action against good-faith reporters.

  • Where can I see ongoing incidents and operational history?

    Real-time status and history are available at status.prakto.se. Subscribe to updates via RSS or email directly on the status page.

  • How do I obtain the DPA and full security documentation?

    The standard DPA, subprocessor list, privacy policy and SLA are available for download at the bottom of this page. For a public-sector-adapted DPA, contact security@prakto.se.

  • Does Prakto train AI models on our data?

    No. We never train models on your operational data without an explicit agreement. Anonymised data used for model evaluation is deleted within 30 days.

  • Where is our data stored?

    Customer data, authentication and background processing take place exclusively within the EU/EEA. We do not change providers without notifying customers who have the right to object.

Security you cantrust today