Skip to content
English
  • There are no suggestions because the search field is empty.

Veonics® Portal Security & Data Protection Overview

Security by Design for Identity Credential Management

Veonics® Portal is a cloud-hosted identity credential management and badge-issuance platform supported by layered technical, administrative, physical, and workforce safeguards. 

eXpress badging® approaches cybersecurity as an ongoing risk-management responsibility—not as a one-time software feature. Security considerations are incorporated into the Portal’s architecture, access controls, development practices, hosting environment, data-management processes, production operations, and employee responsibilities.

Customer data, photos, badge designs, and related identity assets remain customer-owned. eXpress badging does not sell customer information or use it for unrelated commercial purposes. Customer information is processed only as necessary to provide contracted products and services, and it is not disclosed to unauthorized third parties.


Table of Contents


Executive Security Summary

Veonics® Portal and its supporting operations include the following safeguards:

  • AWS-hosted application, database, and photo-storage infrastructure
  • Separate AWS services for structured identity data and badge-photo assets
  • Encryption at rest and encryption in transit
  • HTTPS connections using TLS 1.2 and TLS 1.3
  • Organization-based data segmentation
  • Role-based access control and least-privilege permissions
  • Unique user accounts, configurable session timeouts, and optional multi-factor authentication
  • User and administrative activity history
  • Quarterly vulnerability scanning
  • Annual external penetration testing
  • Documented remediation and verification processes
  • Enterprise firewall, endpoint-protection, and monitoring controls
  • Secure API, SFTP, Portal, and encrypted upload options
  • Defined data-retention and secure-deletion processes
  • U.S.-based badge-production services
  • Controlled facility access and CCTV monitoring
  • Employee background screening and ongoing cybersecurity training
  • Errors & Omissions/Cyber, General Liability, and Workers’ Compensation insurance coverage

The Portal’s production environment uses Amazon RDS for structured cardholder data, Amazon S3 for badge-photo storage, and Amazon EC2 for application and web services. Data is encrypted at rest using AWS encryption services and protected in transit through HTTPS and current TLS protocols.


Security Scope and Shared Responsibility

Security for a cloud-hosted platform is a shared responsibility involving AWS, eXpress badging, and each Veonics® Portal customer.

AWS Responsibilities

AWS is responsible for the security of the cloud, including the underlying data-center facilities, physical infrastructure, foundational networking, power, environmental safeguards, and core cloud services.

AWS maintains independent security and compliance programs for its cloud infrastructure. Those AWS attestations support the underlying hosting environment; they should not be interpreted as a separate SOC 2 or ISO 27001 certification of the Veonics® Portal itself.

eXpress badging Responsibilities

eXpress badging is responsible for security within the Veonics® Portal environment, including:

  • Application configuration
  • Database and photo-storage configuration
  • Encryption settings
  • Network and firewall rules
  • Role and permission structures
  • Vulnerability management
  • Secure development practices
  • Monitoring and incident response
  • Backup and recovery processes
  • Internal endpoint and network security
  • Workforce and physical-production controls

Customer Responsibilities

Customers are responsible for:

  • Selecting authorized Portal administrators and users
  • Assigning (or requesting) appropriate user rights
  • Removing access when it is no longer required
  • Enabling available authentication protections appropriate to their risk profile
  • Limiting submitted information to the data needed for badge issuance
  • Using approved secure data-transfer methods
  • Managing active records in customer-controlled Portal accounts
  • Maintaining required exports or backups
  • Promptly reporting suspected unauthorized access

This shared-responsibility model allows each party to manage the controls within its authority while supporting a coordinated security posture.


Cloud Architecture and Encryption

aws_access_architecture1

aws_architecture1

Security Oversight

Veonics® Portal security architecture and technical operations are designed and maintained with oversight from professionals holding cybersecurity and AWS-related credentials, including CISSP and AWS certifications.

Security requirements are incorporated into architecture, development, deployment, and operational decisions. The objective is to identify and reduce risk during system design rather than attempting to add security only after software development is complete.

AWS Service Architecture

Veonics® Portal is hosted on Amazon Web Services in the United States.

The core production architecture uses separate AWS service layers:

  • Amazon EC2: Application and web-service processing
  • Amazon RDS: Structured cardholder, organization, configuration, and transaction data
  • Amazon S3: Badge photos, images, and applicable file objects

Separating structured identity data from photo assets allows each information type to be managed through purpose-specific AWS services, security policies, storage controls, and application-layer associations.

Multi-Tenant Data Segmentation

The standard Veonics® Portal environment is a managed, multi-tenant SaaS platform.

Customer access is segmented through:

  • Organization hierarchy
  • Child-organization structure
  • Card Properties and defined datasets
  • Role-based access
  • User permissions
  • Application-layer visibility controls

Customer users cannot access organizations above or outside their authorized hierarchy. Where contractually required, a customer may request a separately scoped or dedicated environment subject to technical review, additional implementation requirements, and separate pricing.

Encryption at Rest

Structured data stored in Amazon RDS is encrypted using AWS Key Management Service controls.

Photo and image assets stored in Amazon S3 are encrypted using Amazon S3 server-side encryption. The documented environment uses AES-256 encryption for applicable data and photo storage.

Encryption in Transit

Veonics® Portal connections and supported data transmissions are protected using HTTPS.

The production environment supports:

  • TLS 1.2
  • TLS 1.3

Deprecated TLS and SSL protocols are disabled or removed from approved production configurations.

Network Segmentation and Firewall Protection

AWS security groups and applicable network controls function as virtual firewalls around cloud resources. Rules are restricted to necessary sources, protocols, and ports.

The eXpress badging internal network is protected by an enterprise firewall, controlled access lists, endpoint protection, resource segmentation, and monitored connections. External inbound and outbound connections are processed through applicable cloud or on-premises firewall controls.

Backup and Resilience

The Veonics® Portal uses AWS-native backup, snapshot, replication, and recovery capabilities.

Structured data and badge-photo assets are backed up within the AWS environment. Backup data inherits the applicable encryption and access protections of the production environment. Backup and restoration procedures are documented and periodically reviewed.


Identity, Access, and Audit Controls

Organization-Based Access

Every customer account begins within a defined Veonics® Portal Organization.

Users are associated with an authorized organization and may be restricted to:

  • Their assigned organization
  • Approved child organizations
  • Specific Card Properties
  • Defined datasets
  • Approved functions and workflows

This structure helps prevent users from viewing or modifying identity records outside their authorized operational scope.

Role-Based Access Control

Veonics® Portal uses role-based access control (RBAC).

Users may be assigned preconfigured roles or selected individual permissions based on their responsibilities. Access is intended to follow the principle of least privilege: each user receives only the functions and information necessary to perform the user’s authorized duties.

Depending on the Portal configuration, roles may distinguish among:

  • Customer administrators
  • Managers
  • Card managers
  • Data-entry personnel
  • Printing users
  • Other purpose-specific users

Role and permission changes require authorized administrative action.

Unique User Accounts

Each Portal user must have unique credentials. Shared user accounts are prohibited unless expressly approved as a documented technical exception. 

User access requires an authenticated session and assigned Portal rights.

Password Protection

Veonics® Portal applies password requirements and cryptographic protections for authentication.

Documented protections include:

  • Password-complexity requirements
  • Protection of passwords during transmission
  • Cryptographic protection of stored credentials
  • Account lockout after repeated unsuccessful login attempts
  • Administrative ability to disable a suspected or compromised account

Passwords are protected in transit via TLS-secured login endpoints.

Multi-Factor Authentication

Multi-factor authentication is available for supported Portal accounts and configurations.

Customers with elevated authentication requirements should identify those requirements during licensing, onboarding, or an enterprise security review so that the available configuration can be confirmed.

Session Timeout Enforcement

Veonics® Portal enforces inactivity-based session timeouts.

Timeout duration may be configurable according to the user or customer account configuration. A timed-out user must reauthenticate before continuing access.

User Lifecycle Management

Customer administrators and authorized eXpress badging administrators can create, modify, deactivate, and remove Portal users.

Access should be disabled immediately when a user:

  • Leaves the customer’s organization
  • Changes responsibilities
  • No longer requires Portal access
  • Is suspected of credential compromise
  • Violates applicable security requirements

Inactive Portal user accounts are subject to automatic deactivation after 90 days unless another documented customer configuration or contractual requirement applies.

Audit History

Key Portal activities are associated with user identity and date-and-time information.

Record audit and activity history may include:

  • Record creation
  • Record modification
  • Photo linking or approval
  • Printing activity
  • Record deactivation or deletion
  • Batch activity
  • Organization events
  • User events
  • Administrative changes

Audit information supports accountability, troubleshooting, operational review, and investigation of suspected unauthorized activity.

Tokenized Recipient Workflows

Not every badge recipient requires a standard Portal user account.

Features such as Veonics CELLfie™ may use a limited, tokenized link that allows an authorized recipient to submit a photo or approved information. The token may be restricted by use, workflow state, and expiration. Once the submission is completed and accepted, the recipient's edit access can be disabled.


Cybersecurity Operations

Quarterly Vulnerability Scanning

eXpress badging uses Fortra vulnerability-management services to perform quarterly vulnerability scanning across applicable servers, endpoints, network devices, the Veonics® Portal, and supporting infrastructure.

The vulnerability-management process includes:

  1. Identification of vulnerabilities and configuration weaknesses
  2. Severity-based prioritization
  3. Assignment to an accountable owner
  4. Documented remediation
  5. Rescanning or retesting
  6. Verification before closure
  7. Management review or formal risk acceptance where remediation is not immediately feasible

Findings are tracked through documented operational and ticket-management processes.

Annual External Penetration Testing

Annual penetration testing is performed against applicable internet-facing components, including the Veonics® Portal, APIs, AWS environment, authentication and authorization controls, network perimeter, cloud configuration, and relevant OWASP testing areas.

Redacted proof-of-testing or summary documentation may be available to qualified enterprise customers under an appropriate nondisclosure agreement.

Firewall and Network Controls

The eXpress badging on-premises network uses enterprise firewall protection for inbound and outbound traffic.

Cloud controls may include:

  • AWS security groups
  • Virtual private cloud restrictions
  • Network access controls
  • Restricted ports and protocols
  • Logged firewall activity
  • Segmentation of public-facing and administrative resources

Firewall and access-control rules are reviewed as part of ongoing security governance and vulnerability-management activities.

Endpoint Protection

Company-managed workstations and servers use layered endpoint protections that may include:

  • Endpoint antivirus
  • Endpoint detection and response
  • Microsoft Defender protections
  • DNS filtering
  • Automated alerting
  • Threat monitoring
  • Encryption at rest
  • Security updates and patching

The documented endpoint environment uses Datto antivirus and endpoint-detection capabilities together with Microsoft security controls.

Security Monitoring

Security tooling and managed monitoring services support detection, escalation, and response to suspicious endpoint, network, and system activity.

Alerts may be correlated across:

  • Endpoint security
  • Firewalls
  • DNS filtering
  • Vulnerability-management tools
  • Backup platforms
  • Authentication activity
  • Application and system logs

Removable Media Restrictions

Portable storage devices are prohibited for transferring or storing customer data within eXpress badging operations.

Customer PII and badge-project files must be transferred through approved electronic channels. Physical thumb drives, portable USB storage, and similar removable media are not approved data-exchange methods.

Secure Development Practices

Security is considered throughout the development and maintenance lifecycle.

Relevant practices include:

  • Security requirements during design
  • Restricted development and administrative access
  • Authentication and authorization testing
  • Input-validation controls
  • Change management
  • Vulnerability testing
  • Review of OWASP-related application risks
  • Documented remediation of identified issues

Incident Response

eXpress badging maintains documented cybersecurity incident and breach-response procedures.

The response process is intended to support:

  • Event identification
  • Initial triage
  • Containment
  • Investigation
  • Evidence preservation
  • Remediation
  • Recovery
  • Management escalation
  • Customer notification where required
  • Post-incident review

Customer notification is handled according to the circumstances of the event, applicable contractual obligations, and relevant legal or regulatory requirements.

Business Continuity and Recovery

AWS backup and resiliency capabilities support recovery of Veonics® Portal services.

eXpress badging also maintains backup and continuity controls for applicable internal systems. Recovery procedures and restoration capabilities are reviewed periodically.


Data Ownership, Secure Transfer, and Privacy

Customer Ownership

Customer-provided data, photos, badge designs, and related credential assets remain the property of the customer.

eXpress badging:

  • Does not sell customer data
  • Does not use customer data for unrelated commercial purposes
  • Limits use to the contracted service
  • Restricts access to authorized personnel and systems
  • Does not disclose customer data to unauthorized third parties

Where an approved service provider must process information to support the contracted service, access is limited to the necessary purpose and subject to applicable contractual and security controls.

Data Minimization

Customers should submit only the data necessary to create, manage, print, or issue the intended credential.

The Portal is designed primarily for identity-badge information such as:

  • Name
  • Photo
  • Employee, student, contractor, or member identifier
  • Department
  • Title
  • Badge or credential number
  • Approved organizational attributes

Customers should not submit protected health information, financial account information, Social Security numbers, or other high-risk regulated information unless the data type has been expressly reviewed, approved, and included in the contracted scope.

Approved Secure Submission Methods

Supported secure submission methods may include:

  • Direct entry into the Veonics® Portal
  • Authorized Portal import tools
  • Veonics Credential Database API integration
  • SFTP integration
  • eXpress badging Upload Center powered by Citrix ShareFile
  • Tokenized Veonics CELLfie™ photo-submission workflows

The available method depends on the customer’s subscription, technical requirements, and contracted services.

Do Not Send PII Through Standard Email

Customer PII, badge data, and photo files should not be submitted through ordinary email attachments.

Customers must use the Portal, approved integration, or secure Upload Center. Customer-facing mailboxes may reject or remove attachments containing project data and direct the sender to an approved secure channel.

No Physical-Media Transfers

Customer data is transferred electronically through approved secure channels. Physical media is not used as a standard method for transferring customer PII.


Data and Photo Retention

Retention depends on the contracted service and on whether eXpress badging or the customer controls the active Portal records.

eXpress badging-Managed Printing Projects

For Upload Center submissions, complementary Portal environments, and applicable contracted We Print services, project-specific data and photos are generally deleted within 30 calendar days after printing or project completion unless the customer provides documented authorization for a different retention period.

Customer-controlled retention options may be documented as part of the service engagement.

Active Paid Veonics Portal Subscriptions

For an active paid Veonics® Portal subscription, badge records, photos, card designs, and associated configuration information may be retained for the duration of the subscription or service agreement.

During the active subscription, authorized customer administrators are responsible for managing records in accordance with the customer’s retention requirements.

Data is not automatically deleted 30 days after each badge-printing event within an active paid subscription unless that behavior has been expressly requested or contracted for.

Customer-Managed Printing

For You Print or other customer-managed issuance arrangements, the customer is responsible for managing and deleting active badge data and photos during the subscription term.

eXpress badging can provide guidance, but the customer remains accountable for its internal record-retention requirements.

License Expiration or Non-Renewal

When a Veonics® Portal license expires or is not renewed:

  • The account is identified for closure
  • Customer data is flagged for removal
  • Data is scheduled for secure deletion
  • Deletion generally occurs 30 calendar days after non-renewal unless a different contractual period, legal hold, or documented requirement applies

Customers should export any records, photos, user lists, or badge designs they are required to retain before the account is closed.

Customer-Requested Deletion

Customers may request accelerated deletion where permitted by the applicable contract and where no legal, regulatory, security, or operational hold prevents deletion.

A Certificate of Destruction or written deletion confirmation may be available upon request.

Backup Rotation

Deleted production information may remain temporarily within encrypted backup media until the applicable backup-rotation cycle replaces it.

Backup copies are not treated as active production records and are protected through encryption, access controls, and restricted recovery procedures.


Secure Deletion and Physical Destruction

Digital Secure Deletion

Secure-deletion processes address applicable production databases, photo-storage locations, file repositories, and supporting systems controlled by eXpress badging.

Deletion activities may include:

  • Removal from production database records
  • Removal from active file and photo storage
  • Removal from applicable local processing locations
  • Removal from secure file-transfer locations
  • Expiration through encrypted backup rotation
  • Internal logging or confirmation of the deletion process

Secure sanitization practices should be maintained in alignment with the current NIST SP 800-88 Revision 2, Guidelines for Media Sanitization, as applicable to the relevant storage technology and service model. NIST published Revision 2 in September 2025, replacing the withdrawn Revision 1.

Printed Badge Materials

Production errors, rejected badges, obsolete credential materials, and other printed items containing customer-specific information are securely destroyed or professionally shredded.

Customer-supplied RFID card stock and other sensitive production materials are stored in controlled locations when held by eXpress badging.


Physical Security and Workforce Controls

U.S.-Based Badge Production

eXpress badging performs its badge-printing services in the United States.

Where customer data is processed by eXpress badging production personnel, it is handled within controlled company systems and operating procedures.

Facility Access

Physical access to eXpress badging facilities is controlled through safeguards that include:

  • Controlled doors and access authorization
  • Card-reader or managed-entry controls
  • CCTV monitoring
  • Restricted production and storage areas
  • Key and access-management procedures
  • Locked storage for sensitive customer materials

AWS is separately responsible for the physical and environmental controls at the cloud data centers hosting Veonics® Portal production systems.

Personnel Screening

eXpress badging personnel undergo pre-employment background screening.

The documented personnel security program also includes annual background rechecks or ongoing monitoring, as required by company policy and role requirements.

PII Handling

Employees with access to badge-project information are trained in:

  • Personally identifiable information handling
  • Approved secure-transfer methods
  • Data minimization
  • Clean-desk and storage expectations
  • Customer confidentiality
  • Secure disposal
  • Incident reporting
  • Access-control responsibilities

Customer information may not be stored on unapproved local devices or transferred through unapproved media.

Cybersecurity Awareness

Cybersecurity training begins during employee onboarding and is reinforced through periodic education.

Training and awareness activities may include:

  • Social-engineering awareness
  • Phishing recognition
  • Malware and ransomware awareness
  • Password and credential security
  • Secure handling of customer information
  • Physical-security awareness
  • Periodic simulated phishing or social-engineering exercises
  • Refresher training and internal reviews

The documented program includes quarterly refresher activities and periodic simulations.

Employee Access Termination

When employment or assigned responsibilities end, applicable system and network access is removed promptly.

Credentials are not reassigned to another person, and access changes are documented through the applicable administrative or audit process.

Remote Support

Remote technical support sessions require customer authorization and use encrypted remote support technology.

Customers can terminate an active support session. Remote access does not create permanent or unattended access unless separately authorized through a documented support arrangement.


Framework Alignment and Assurance

NIST Cybersecurity Framework 2.0

The eXpress badging cybersecurity program and Veonics® Portal security documentation are aligned to the risk-management principles of the NIST Cybersecurity Framework 2.0.

NIST CSF 2.0 is organized around six functions:

  • Govern: Establish accountability, policy, oversight, and risk-management expectations
  • Identify: Understand systems, assets, data, threats, and risk
  • Protect: Apply safeguards such as access control, encryption, and training
  • Detect: Monitor for vulnerabilities, anomalies, and potential incidents
  • Respond: Contain, investigate, communicate, and remediate incidents
  • Recover: Restore services, validate recovery, and improve controls

NIST describes CSF 2.0 as flexible guidance for organizations of different sizes, sectors, and maturity levels. Alignment with the Framework is not the same as formal certification.

NIST SP 800-171

NIST SP 800-171 is a separate publication addressing the protection of Controlled Unclassified Information in nonfederal systems.

eXpress badging does not represent NIST CSF 2.0 and NIST SP 800-171 as the same framework. SP 800-171 requirements may be evaluated or mapped where a customer contract specifically involves CUI or a federal safeguarding obligation.

SOC 2 and ISO 27001

The Veonics® Portal has not represented that it has completed a separate SOC 2 examination or ISO/IEC 27001 certification.

The Portal and supporting security program are designed to align with relevant principles found in:

  • SOC 2 Trust Services Criteria
  • ISO/IEC 27001 controls
  • NIST CSF 2.0
  • OWASP guidance
  • AWS security practices

AWS maintains its own independent cloud certifications and audit reports. Those AWS reports apply to AWS’s underlying cloud services and do not automatically certify every application hosted on AWS.

Security Evidence

Depending on the customer’s subscription, risk profile, and contractual requirements, eXpress badging may provide selected evidence such as:

  • Security-policy summaries
  • Vulnerability-scan confirmation
  • Redacted penetration-test confirmation
  • Remediation statements
  • Insurance certificates
  • Data-destruction confirmation
  • Architecture and data-flow information
  • Completed security questionnaires

Detailed reports, sensitive architecture evidence, or testing outputs may require a nondisclosure agreement and an enterprise compliance engagement.


Insurance Coverage

eXpress badging® maintains a layered commercial insurance program and obtains additional contract-specific coverage when required. Coverage categories include:

  • Commercial General Liability
  • Workers’ Compensation and Employers’ Liability
  • Umbrella/Excess Liability
  • Professional Liability and Technology Errors & Omissions
  • Privacy and Network Security/Cyber Liability
  • Commercial Crime and Third-Party Fidelity coverage
  • Hired and Non-Owned Automobile Liability, when contractually required

Current published limits include:

  • Commercial General Liability: $1 million per occurrence / $2 million aggregate
  • Workers’ Compensation and Employers’ Liability: $1 million
  • Umbrella/Excess Liability: $1 million
  • E&O/Cyber: $3 million
  • Third-Party Crime: $1 million
  • Hired and Non-Owned Automobile Liability: $1 million, obtained as required

Certificates of Insurance and supporting evidence of coverage are available to qualified customers upon request. Coverage is subject to the applicable policies, endorsements, limits, deductibles, conditions, and exclusions.

 


Customer Security Responsibilities

Security controls are most effective when customers actively manage their portion of the Portal environment.

Customers should:

  • Designate a primary Portal administrator
  • Provide each user with a unique account
  • Avoid shared credentials
  • Assign the minimum rights required
  • Enable available MFA where appropriate
  • Review users and permissions periodically
  • Disable users immediately when access is no longer required
  • Limit submitted data to information needed for credential issuance
  • Never send PII through ordinary email
  • Use the Portal, API, SFTP, CELLfie, or approved Upload Center
  • Secure customer-managed endpoints and browsers
  • Maintain required exports and internal backups
  • Establish a documented customer retention schedule
  • Delete obsolete active records
  • Notify eXpress badging promptly of suspected unauthorized access
  • Comply with the Veonics® Portal User License Agreement and applicable service terms

Customers remain responsible for the accuracy, authorization, lawful use, and internal governance of the data they submit.


Supporting Security Documentation

 Related Security and Compliance Documentation 

Cloud, Architecture,  and Infrastructure

Identity and Access Management

Vulnerability and Incident Management

Data Protection and Privacy

Compliance and Governance


Security Reviews and Evidence Requests

Customers with security questionnaires, vendor-risk reviews, insurance requirements, architecture questions, or requests for testing evidence should contact their eXpress badging representative.

Requests involving confidential technical evidence, redacted testing information, or detailed infrastructure documentation may require:

  • Verification of the requesting organization
  • A nondisclosure agreement
  • Defined scope and business purpose
  • Enterprise compliance onboarding
  • Professional-service or compliance-review fees where applicable

This process protects both customer interests and the security of the Veonics® Portal environment.