EN
Login Sign Up

Trust & standards

A passport is only as trustworthy as what it stands on. dpp.gs is built on the first European DPP standards, signed with open cryptography, and operated on certified EU infrastructure by Sensoneo, which runs national deposit-return IT in nine countries.

Built on the EU standards baseline

CEN/CENELEC JTC 24 published the first six European DPP standards in May 2026 and the two security standards on 16 September 2026. Each governs one layer, and we implement all of them — rather than a format of our own.

EN 18219 — identifiers

Five identifier schemes are recognised. GS1 Digital Link is our default and every passport is a resolvable URL, but EPC, UUID, DID and MA-DPP are equally valid.

EN 18220 — data carriers

QR carrying the full URL, and GS1 DataMatrix with a proper FNC1 header, generated for every product.

EN 18216 — data exchange

Plain HTTPS with content negotiation: a phone gets HTML, a system gets JSON-LD, from the same URL.

EN 18222 — lifecycle & search

A versioned /dpp/v1 API to search, retrieve and query passport lifecycle.

EN 18223 — interoperability

JSON-LD on schema.org plus the GS1 vocabulary and a dpp: namespace — a machine-readable semantic graph.

EN 18246 — authentication and integrity

Passports issuable as W3C Verifiable Credentials signed with Ed25519, verifiable offline.

Certifications and assurances

Group-level, independently audited, and maintained — not self-declarations. Where we are not certified, we say so.

ISO 9001 · 14001 · 27001

Quality, environmental and information-security management across the Sensoneo group that operates the platform.

SOC 2

Independent controls assurance through our parent group, which runs EU-wide deposit-return IT at national scale.

EU hosting, Germany

All product data stored in the EU. EU jurisdiction, GDPR-compliant, and it does not leave.

GS1 conformance-tested

Our resolver passes the official GS1 Digital Link Conformance Test Suite.

Signed, not chained

Ed25519 Verifiable Credentials, verified offline against a public key. No blockchain, no token, no wallet.

MIT-licensed schemas

JSON Schema and the OpenAPI 3.1 spec are public and MIT-licensed, and everything exports as CSV and JSON-LD.

Frequently asked questions

Is dpp.gs certified against the EN DPP standards?

No, and neither is anyone else: EN 18216 and EN 18219–18223 were published in May 2026 and cited in the Official Journal, the two security standards EN 18239 and EN 18246 followed on 16 September 2026, and no certification scheme exists for any of them yet. We implement the same open standards the series rests on, and we would rather state that than imply a certificate nobody can currently hold.

Where is our data stored?

In the European Union, in Germany. EU jurisdiction, GDPR-compliant, and it does not leave the EU. A second region in the United States serves passports quickly there; it does not move EU product data.

Do you use blockchain?

No. Passports can be issued as W3C Verifiable Credentials signed with Ed25519 and verified offline against our public key. That gives tamper-evidence without a chain, a token or a wallet.

What happens to my passports if we stop being a customer?

Everything exports as CSV and JSON-LD, and the schemas and OpenAPI spec are MIT-licensed. Your identifiers are URLs you own. Leaving should cost a migration, not your data.

See what a passport carries

Open a fully populated battery passport — materials, substances, documents and a verifiable credential.

Open a live passport