Trust & security
A battery passport is only worth what its records can prove. Every entry in Passoria is built to survive an audit by someone who does not trust us.
Four properties, each one enforced
Append-only
History cannot be edited. The database itself rejects updates and deletes on lifecycle records - not our application code, the database. Corrections are new entries that name what they correct and explain why.
Tamper-evident
If anything is altered, it shows. Every record is hashed and chained to the one before it. Change one byte anywhere in the past and every later link breaks.
Non-repudiation
Every lifecycle event is signed by the organization that acted. A claim can always be traced to the party that made it, and cannot be denied later.
Independently verifiable
You do not have to take our word. Chain heads are published, sealed by an external timestamp authority and checkable with standard tooling outside our platform.
Transfers are signed on both sides
When a battery changes hands, the transfer is a two-step handshake. The sender signs an offer that cites the exact chain head of the passport at that moment. The receiver signs the acceptance. The receiver holds cryptographic proof of exactly which history they accepted, and the sender holds proof of discharge.
A recycler's intake claim is signed by the receiving organization, not typed in by the shipper. Every transfer hands the chain head to the party with the strongest incentive to check it, so tampering has to defeat not one database but every counterparty that ever held the record.
Every transfer distributes proof to the parties most motivated to verify it.
Check us, don't trust us
The strongest security claim is the one you can test from outside.
- Public chain head. The QR page of every passport shows its ledger chain head. Save the value: if any past entry is altered later, the head you saved will no longer match.
- Signed extracts. A passport exports as a signed, self-verifiable bundle: events, hashes, chain and public keys. It verifies with standard tooling and no Passoria account.
- Continuous verification. Every chain is recomputed from its genesis and every signature re-checked, fleet-wide. A single broken link raises an alert naming the exact record.
- External timestamps. Chain heads are sealed by an independent RFC 3161 timestamp authority, proving records existed before a given point in time - even to someone who distrusts our clock.
Everyone sees exactly what the law entitles them to
Annex XIII of Regulation (EU) 2023/1542 defines who may see which data. Passoria enforces it field by field, on every view.
Public
Anyone who scans the QR code sees the public data block: identity, composition, circularity. Restricted sections appear as locked cards with counts - proof the data exists, without leaking a value.
Legitimate interest
Recyclers, second-life operators and the current custodian see the technical blocks they need: dismantling data, safety, state of health. Custody itself grants access, and revokes it when the battery moves on.
Regulators
Market surveillance authorities and the Commission see everything, including test results and compliance documentation. Every field of every data model is mapped to its tier.
European data, under European rules
Passoria runs on European cloud infrastructure. Passport data is stored and processed in data centers inside the European Union, under European jurisdiction, and it does not leave the EU.
GDPR is not a layer added at the end, it is in the data model: a lawful basis for every processing activity, minimization in what the passport records, and personal identities kept out of hash coverage so the right to erasure is always honored.
- EU data residency. Storage, processing and backups all stay inside the European Union.
- GDPR end to end. Erasure requests are honored without breaking the ledger, and a data processing agreement comes with every contract.
- Certified hosting. Our hosting provider's data centers are certified against ISO/IEC 27001.