Veonics® Portal Security & Data Protection Overview
Security by Design for Identity Credential Management
Veonics® Portal is a cloud-hosted identity credential management and badge-issuance platform supported by layered technical, administrative, physical, and workforce safeguards.
eXpress badging® approaches cybersecurity as an ongoing risk-management responsibility—not as a one-time software feature. Security considerations are incorporated into the Portal’s architecture, access controls, development practices, hosting environment, data-management processes, production operations, and employee responsibilities.
Customer data, photos, badge designs, and related identity assets remain customer-owned. eXpress badging does not sell customer information or use it for unrelated commercial purposes. Customer information is processed only as necessary to provide contracted products and services, and it is not disclosed to unauthorized third parties.
Table of Contents
- Executive Security Summary
- Security Scope and Shared Responsibility
- Cloud Architecture and Encryption
- Identity, Access, and Audit Controls
- Cybersecurity Operations
- Data Ownership, Secure Transfer, and Privacy
- Data and Photo Retention
- Secure Deletion and Physical Destruction
- Physical Security and Workforce Controls
- Framework Alignment and Assurance
- Insurance Coverage
- Customer Security Responsibilities
- Supporting Security Documentation
- Security Reviews and Evidence Requests
Executive Security Summary
Veonics® Portal and its supporting operations include the following safeguards:
- AWS-hosted application, database, and photo-storage infrastructure
- Separate AWS services for structured identity data and badge-photo assets
- Encryption at rest and encryption in transit
- HTTPS connections using TLS 1.2 and TLS 1.3
- Organization-based data segmentation
- Role-based access control and least-privilege permissions
- Unique user accounts, configurable session timeouts, and optional multi-factor authentication
- User and administrative activity history
- Quarterly vulnerability scanning
- Annual external penetration testing
- Documented remediation and verification processes
- Enterprise firewall, endpoint-protection, and monitoring controls
- Secure API, SFTP, Portal, and encrypted upload options
- Defined data-retention and secure-deletion processes
- U.S.-based badge-production services
- Controlled facility access and CCTV monitoring
- Employee background screening and ongoing cybersecurity training
- Errors & Omissions/Cyber, General Liability, and Workers’ Compensation insurance coverage
The Portal’s production environment uses Amazon RDS for structured cardholder data, Amazon S3 for badge-photo storage, and Amazon EC2 for application and web services. Data is encrypted at rest using AWS encryption services and protected in transit through HTTPS and current TLS protocols.
Security Scope and Shared Responsibility
Security for a cloud-hosted platform is a shared responsibility involving AWS, eXpress badging, and each Veonics® Portal customer.
AWS Responsibilities
AWS is responsible for the security of the cloud, including the underlying data-center facilities, physical infrastructure, foundational networking, power, environmental safeguards, and core cloud services.
AWS maintains independent security and compliance programs for its cloud infrastructure. Those AWS attestations support the underlying hosting environment; they should not be interpreted as a separate SOC 2 or ISO 27001 certification of the Veonics® Portal itself.
eXpress badging Responsibilities
eXpress badging is responsible for security within the Veonics® Portal environment, including:
- Application configuration
- Database and photo-storage configuration
- Encryption settings
- Network and firewall rules
- Role and permission structures
- Vulnerability management
- Secure development practices
- Monitoring and incident response
- Backup and recovery processes
- Internal endpoint and network security
- Workforce and physical-production controls
Customer Responsibilities
Customers are responsible for:
- Selecting authorized Portal administrators and users
- Assigning (or requesting) appropriate user rights
- Removing access when it is no longer required
- Enabling available authentication protections appropriate to their risk profile
- Limiting submitted information to the data needed for badge issuance
- Using approved secure data-transfer methods
- Managing active records in customer-controlled Portal accounts
- Maintaining required exports or backups
- Promptly reporting suspected unauthorized access
This shared-responsibility model allows each party to manage the controls within its authority while supporting a coordinated security posture.
Cloud Architecture and Encryption


Security Oversight
Veonics® Portal security architecture and technical operations are designed and maintained with oversight from professionals holding cybersecurity and AWS-related credentials, including CISSP and AWS certifications.
Security requirements are incorporated into architecture, development, deployment, and operational decisions. The objective is to identify and reduce risk during system design rather than attempting to add security only after software development is complete.
AWS Service Architecture
Veonics® Portal is hosted on Amazon Web Services in the United States.
The core production architecture uses separate AWS service layers:
- Amazon EC2: Application and web-service processing
- Amazon RDS: Structured cardholder, organization, configuration, and transaction data
- Amazon S3: Badge photos, images, and applicable file objects
Separating structured identity data from photo assets allows each information type to be managed through purpose-specific AWS services, security policies, storage controls, and application-layer associations.
Multi-Tenant Data Segmentation
The standard Veonics® Portal environment is a managed, multi-tenant SaaS platform.
Customer access is segmented through:
- Organization hierarchy
- Child-organization structure
- Card Properties and defined datasets
- Role-based access
- User permissions
- Application-layer visibility controls
Customer users cannot access organizations above or outside their authorized hierarchy. Where contractually required, a customer may request a separately scoped or dedicated environment subject to technical review, additional implementation requirements, and separate pricing.
Encryption at Rest
Structured data stored in Amazon RDS is encrypted using AWS Key Management Service controls.
Photo and image assets stored in Amazon S3 are encrypted using Amazon S3 server-side encryption. The documented environment uses AES-256 encryption for applicable data and photo storage.
Encryption in Transit
Veonics® Portal connections and supported data transmissions are protected using HTTPS.
The production environment supports:
- TLS 1.2
- TLS 1.3
Deprecated TLS and SSL protocols are disabled or removed from approved production configurations.
Network Segmentation and Firewall Protection
AWS security groups and applicable network controls function as virtual firewalls around cloud resources. Rules are restricted to necessary sources, protocols, and ports.
The eXpress badging internal network is protected by an enterprise firewall, controlled access lists, endpoint protection, resource segmentation, and monitored connections. External inbound and outbound connections are processed through applicable cloud or on-premises firewall controls.
Backup and Resilience
The Veonics® Portal uses AWS-native backup, snapshot, replication, and recovery capabilities.
Structured data and badge-photo assets are backed up within the AWS environment. Backup data inherits the applicable encryption and access protections of the production environment. Backup and restoration procedures are documented and periodically reviewed.
Identity, Access, and Audit Controls
Organization-Based Access
Every customer account begins within a defined Veonics® Portal Organization.
Users are associated with an authorized organization and may be restricted to:
- Their assigned organization
- Approved child organizations
- Specific Card Properties
- Defined datasets
- Approved functions and workflows
This structure helps prevent users from viewing or modifying identity records outside their authorized operational scope.
Role-Based Access Control
Veonics® Portal uses role-based access control (RBAC).
Users may be assigned preconfigured roles or selected individual permissions based on their responsibilities. Access is intended to follow the principle of least privilege: each user receives only the functions and information necessary to perform the user’s authorized duties.
Depending on the Portal configuration, roles may distinguish among:
- Customer administrators
- Managers
- Card managers
- Data-entry personnel
- Printing users
- Other purpose-specific users
Role and permission changes require authorized administrative action.
Unique User Accounts
Each Portal user must have unique credentials. Shared user accounts are prohibited unless expressly approved as a documented technical exception.
User access requires an authenticated session and assigned Portal rights.
Password Protection
Veonics® Portal applies password requirements and cryptographic protections for authentication.
Documented protections include:
- Password-complexity requirements
- Protection of passwords during transmission
- Cryptographic protection of stored credentials
- Account lockout after repeated unsuccessful login attempts
- Administrative ability to disable a suspected or compromised account
Passwords are protected in transit via TLS-secured login endpoints.
Multi-Factor Authentication
Multi-factor authentication is available for supported Portal accounts and configurations.
Customers with elevated authentication requirements should identify those requirements during licensing, onboarding, or an enterprise security review so that the available configuration can be confirmed.
Session Timeout Enforcement
Veonics® Portal enforces inactivity-based session timeouts.
Timeout duration may be configurable according to the user or customer account configuration. A timed-out user must reauthenticate before continuing access.
User Lifecycle Management
Customer administrators and authorized eXpress badging administrators can create, modify, deactivate, and remove Portal users.
Access should be disabled immediately when a user:
- Leaves the customer’s organization
- Changes responsibilities
- No longer requires Portal access
- Is suspected of credential compromise
- Violates applicable security requirements
Inactive Portal user accounts are subject to automatic deactivation after 90 days unless another documented customer configuration or contractual requirement applies.
Audit History
Key Portal activities are associated with user identity and date-and-time information.
Record audit and activity history may include:
- Record creation
- Record modification
- Photo linking or approval
- Printing activity
- Record deactivation or deletion
- Batch activity
- Organization events
- User events
- Administrative changes
Audit information supports accountability, troubleshooting, operational review, and investigation of suspected unauthorized activity.
Tokenized Recipient Workflows
Not every badge recipient requires a standard Portal user account.
Features such as Veonics CELLfie™ may use a limited, tokenized link that allows an authorized recipient to submit a photo or approved information. The token may be restricted by use, workflow state, and expiration. Once the submission is completed and accepted, the recipient's edit access can be disabled.
Cybersecurity Operations
Quarterly Vulnerability Scanning
eXpress badging uses Fortra vulnerability-management services to perform quarterly vulnerability scanning across applicable servers, endpoints, network devices, the Veonics® Portal, and supporting infrastructure.
The vulnerability-management process includes:
- Identification of vulnerabilities and configuration weaknesses
- Severity-based prioritization
- Assignment to an accountable owner
- Documented remediation
- Rescanning or retesting
- Verification before closure
- Management review or formal risk acceptance where remediation is not immediately feasible
Findings are tracked through documented operational and ticket-management processes.
Annual External Penetration Testing
Annual penetration testing is performed against applicable internet-facing components, including the Veonics® Portal, APIs, AWS environment, authentication and authorization controls, network perimeter, cloud configuration, and relevant OWASP testing areas.
Redacted proof-of-testing or summary documentation may be available to qualified enterprise customers under an appropriate nondisclosure agreement.
Firewall and Network Controls
The eXpress badging on-premises network uses enterprise firewall protection for inbound and outbound traffic.
Cloud controls may include:
- AWS security groups
- Virtual private cloud restrictions
- Network access controls
- Restricted ports and protocols
- Logged firewall activity
- Segmentation of public-facing and administrative resources
Firewall and access-control rules are reviewed as part of ongoing security governance and vulnerability-management activities.
Endpoint Protection
Company-managed workstations and servers use layered endpoint protections that may include:
- Endpoint antivirus
- Endpoint detection and response
- Microsoft Defender protections
- DNS filtering
- Automated alerting
- Threat monitoring
- Encryption at rest
- Security updates and patching
The documented endpoint environment uses Datto antivirus and endpoint-detection capabilities together with Microsoft security controls.
Security Monitoring
Security tooling and managed monitoring services support detection, escalation, and response to suspicious endpoint, network, and system activity.
Alerts may be correlated across:
- Endpoint security
- Firewalls
- DNS filtering
- Vulnerability-management tools
- Backup platforms
- Authentication activity
- Application and system logs
Removable Media Restrictions
Portable storage devices are prohibited for transferring or storing customer data within eXpress badging operations.
Customer PII and badge-project files must be transferred through approved electronic channels. Physical thumb drives, portable USB storage, and similar removable media are not approved data-exchange methods.
Secure Development Practices
Security is considered throughout the development and maintenance lifecycle.
Relevant practices include:
- Security requirements during design
- Restricted development and administrative access
- Authentication and authorization testing
- Input-validation controls
- Change management
- Vulnerability testing
- Review of OWASP-related application risks
- Documented remediation of identified issues
Incident Response
eXpress badging maintains documented cybersecurity incident and breach-response procedures.
The response process is intended to support:
- Event identification
- Initial triage
- Containment
- Investigation
- Evidence preservation
- Remediation
- Recovery
- Management escalation
- Customer notification where required
- Post-incident review
Customer notification is handled according to the circumstances of the event, applicable contractual obligations, and relevant legal or regulatory requirements.
Business Continuity and Recovery
AWS backup and resiliency capabilities support recovery of Veonics® Portal services.
eXpress badging also maintains backup and continuity controls for applicable internal systems. Recovery procedures and restoration capabilities are reviewed periodically.
Data Ownership, Secure Transfer, and Privacy
Customer Ownership
Customer-provided data, photos, badge designs, and related credential assets remain the property of the customer.
eXpress badging:
- Does not sell customer data
- Does not use customer data for unrelated commercial purposes
- Limits use to the contracted service
- Restricts access to authorized personnel and systems
- Does not disclose customer data to unauthorized third parties
Where an approved service provider must process information to support the contracted service, access is limited to the necessary purpose and subject to applicable contractual and security controls.
Data Minimization
Customers should submit only the data necessary to create, manage, print, or issue the intended credential.
The Portal is designed primarily for identity-badge information such as:
- Name
- Photo
- Employee, student, contractor, or member identifier
- Department
- Title
- Badge or credential number
- Approved organizational attributes
Customers should not submit protected health information, financial account information, Social Security numbers, or other high-risk regulated information unless the data type has been expressly reviewed, approved, and included in the contracted scope.
Approved Secure Submission Methods
Supported secure submission methods may include:
- Direct entry into the Veonics® Portal
- Authorized Portal import tools
- Veonics Credential Database API integration
- SFTP integration
- eXpress badging Upload Center powered by Citrix ShareFile
- Tokenized Veonics CELLfie™ photo-submission workflows
The available method depends on the customer’s subscription, technical requirements, and contracted services.
Do Not Send PII Through Standard Email
Customer PII, badge data, and photo files should not be submitted through ordinary email attachments.
Customers must use the Portal, approved integration, or secure Upload Center. Customer-facing mailboxes may reject or remove attachments containing project data and direct the sender to an approved secure channel.
No Physical-Media Transfers
Customer data is transferred electronically through approved secure channels. Physical media is not used as a standard method for transferring customer PII.
Data and Photo Retention
Retention depends on the contracted service and on whether eXpress badging or the customer controls the active Portal records.
eXpress badging-Managed Printing Projects
For Upload Center submissions, complementary Portal environments, and applicable contracted We Print services, project-specific data and photos are generally deleted within 30 calendar days after printing or project completion unless the customer provides documented authorization for a different retention period.
Customer-controlled retention options may be documented as part of the service engagement.
Active Paid Veonics Portal Subscriptions
For an active paid Veonics® Portal subscription, badge records, photos, card designs, and associated configuration information may be retained for the duration of the subscription or service agreement.
During the active subscription, authorized customer administrators are responsible for managing records in accordance with the customer’s retention requirements.
Data is not automatically deleted 30 days after each badge-printing event within an active paid subscription unless that behavior has been expressly requested or contracted for.
Customer-Managed Printing
For You Print or other customer-managed issuance arrangements, the customer is responsible for managing and deleting active badge data and photos during the subscription term.
eXpress badging can provide guidance, but the customer remains accountable for its internal record-retention requirements.
License Expiration or Non-Renewal
When a Veonics® Portal license expires or is not renewed:
- The account is identified for closure
- Customer data is flagged for removal
- Data is scheduled for secure deletion
- Deletion generally occurs 30 calendar days after non-renewal unless a different contractual period, legal hold, or documented requirement applies
Customers should export any records, photos, user lists, or badge designs they are required to retain before the account is closed.
Customer-Requested Deletion
Customers may request accelerated deletion where permitted by the applicable contract and where no legal, regulatory, security, or operational hold prevents deletion.
A Certificate of Destruction or written deletion confirmation may be available upon request.
Backup Rotation
Deleted production information may remain temporarily within encrypted backup media until the applicable backup-rotation cycle replaces it.
Backup copies are not treated as active production records and are protected through encryption, access controls, and restricted recovery procedures.
Secure Deletion and Physical Destruction
Digital Secure Deletion
Secure-deletion processes address applicable production databases, photo-storage locations, file repositories, and supporting systems controlled by eXpress badging.
Deletion activities may include:
- Removal from production database records
- Removal from active file and photo storage
- Removal from applicable local processing locations
- Removal from secure file-transfer locations
- Expiration through encrypted backup rotation
- Internal logging or confirmation of the deletion process
Secure sanitization practices should be maintained in alignment with the current NIST SP 800-88 Revision 2, Guidelines for Media Sanitization, as applicable to the relevant storage technology and service model. NIST published Revision 2 in September 2025, replacing the withdrawn Revision 1.
Printed Badge Materials
Production errors, rejected badges, obsolete credential materials, and other printed items containing customer-specific information are securely destroyed or professionally shredded.
Customer-supplied RFID card stock and other sensitive production materials are stored in controlled locations when held by eXpress badging.
Physical Security and Workforce Controls
U.S.-Based Badge Production
eXpress badging performs its badge-printing services in the United States.
Where customer data is processed by eXpress badging production personnel, it is handled within controlled company systems and operating procedures.
Facility Access
Physical access to eXpress badging facilities is controlled through safeguards that include:
- Controlled doors and access authorization
- Card-reader or managed-entry controls
- CCTV monitoring
- Restricted production and storage areas
- Key and access-management procedures
- Locked storage for sensitive customer materials
AWS is separately responsible for the physical and environmental controls at the cloud data centers hosting Veonics® Portal production systems.
Personnel Screening
eXpress badging personnel undergo pre-employment background screening.
The documented personnel security program also includes annual background rechecks or ongoing monitoring, as required by company policy and role requirements.
PII Handling
Employees with access to badge-project information are trained in:
- Personally identifiable information handling
- Approved secure-transfer methods
- Data minimization
- Clean-desk and storage expectations
- Customer confidentiality
- Secure disposal
- Incident reporting
- Access-control responsibilities
Customer information may not be stored on unapproved local devices or transferred through unapproved media.
Cybersecurity Awareness
Cybersecurity training begins during employee onboarding and is reinforced through periodic education.
Training and awareness activities may include:
- Social-engineering awareness
- Phishing recognition
- Malware and ransomware awareness
- Password and credential security
- Secure handling of customer information
- Physical-security awareness
- Periodic simulated phishing or social-engineering exercises
- Refresher training and internal reviews
The documented program includes quarterly refresher activities and periodic simulations.
Employee Access Termination
When employment or assigned responsibilities end, applicable system and network access is removed promptly.
Credentials are not reassigned to another person, and access changes are documented through the applicable administrative or audit process.
Remote Support
Remote technical support sessions require customer authorization and use encrypted remote support technology.
Customers can terminate an active support session. Remote access does not create permanent or unattended access unless separately authorized through a documented support arrangement.
Framework Alignment and Assurance
NIST Cybersecurity Framework 2.0
The eXpress badging cybersecurity program and Veonics® Portal security documentation are aligned to the risk-management principles of the NIST Cybersecurity Framework 2.0.
NIST CSF 2.0 is organized around six functions:
- Govern: Establish accountability, policy, oversight, and risk-management expectations
- Identify: Understand systems, assets, data, threats, and risk
- Protect: Apply safeguards such as access control, encryption, and training
- Detect: Monitor for vulnerabilities, anomalies, and potential incidents
- Respond: Contain, investigate, communicate, and remediate incidents
- Recover: Restore services, validate recovery, and improve controls
NIST describes CSF 2.0 as flexible guidance for organizations of different sizes, sectors, and maturity levels. Alignment with the Framework is not the same as formal certification.
NIST SP 800-171
NIST SP 800-171 is a separate publication addressing the protection of Controlled Unclassified Information in nonfederal systems.
eXpress badging does not represent NIST CSF 2.0 and NIST SP 800-171 as the same framework. SP 800-171 requirements may be evaluated or mapped where a customer contract specifically involves CUI or a federal safeguarding obligation.
SOC 2 and ISO 27001
The Veonics® Portal has not represented that it has completed a separate SOC 2 examination or ISO/IEC 27001 certification.
The Portal and supporting security program are designed to align with relevant principles found in:
- SOC 2 Trust Services Criteria
- ISO/IEC 27001 controls
- NIST CSF 2.0
- OWASP guidance
- AWS security practices
AWS maintains its own independent cloud certifications and audit reports. Those AWS reports apply to AWS’s underlying cloud services and do not automatically certify every application hosted on AWS.
Security Evidence
Depending on the customer’s subscription, risk profile, and contractual requirements, eXpress badging may provide selected evidence such as:
- Security-policy summaries
- Vulnerability-scan confirmation
- Redacted penetration-test confirmation
- Remediation statements
- Insurance certificates
- Data-destruction confirmation
- Architecture and data-flow information
- Completed security questionnaires
Detailed reports, sensitive architecture evidence, or testing outputs may require a nondisclosure agreement and an enterprise compliance engagement.
Insurance Coverage
eXpress badging® maintains a layered commercial insurance program and obtains additional contract-specific coverage when required. Coverage categories include:
- Commercial General Liability
- Workers’ Compensation and Employers’ Liability
- Umbrella/Excess Liability
- Professional Liability and Technology Errors & Omissions
- Privacy and Network Security/Cyber Liability
- Commercial Crime and Third-Party Fidelity coverage
- Hired and Non-Owned Automobile Liability, when contractually required
Current published limits include:
- Commercial General Liability: $1 million per occurrence / $2 million aggregate
- Workers’ Compensation and Employers’ Liability: $1 million
- Umbrella/Excess Liability: $1 million
- E&O/Cyber: $3 million
- Third-Party Crime: $1 million
- Hired and Non-Owned Automobile Liability: $1 million, obtained as required
Certificates of Insurance and supporting evidence of coverage are available to qualified customers upon request. Coverage is subject to the applicable policies, endorsements, limits, deductibles, conditions, and exclusions.
Customer Security Responsibilities
Security controls are most effective when customers actively manage their portion of the Portal environment.
Customers should:
- Designate a primary Portal administrator
- Provide each user with a unique account
- Avoid shared credentials
- Assign the minimum rights required
- Enable available MFA where appropriate
- Review users and permissions periodically
- Disable users immediately when access is no longer required
- Limit submitted data to information needed for credential issuance
- Never send PII through ordinary email
- Use the Portal, API, SFTP, CELLfie, or approved Upload Center
- Secure customer-managed endpoints and browsers
- Maintain required exports and internal backups
- Establish a documented customer retention schedule
- Delete obsolete active records
- Notify eXpress badging promptly of suspected unauthorized access
- Comply with the Veonics® Portal User License Agreement and applicable service terms
Customers remain responsible for the accuracy, authorization, lawful use, and internal governance of the data they submit.
Supporting Security Documentation
Related Security and Compliance Documentation
Cloud, Architecture, and Infrastructure
- Veonics® Portal Cloud Security & Data Management Policy
- Veonics® Portal History and System Architecture
- Deployment & Infrastructure Security Controls
- Firewalls & Network Security Controls
- Data & Photos Backup, Storage, and Recovery Process
Identity and Access Management
- Security Roles & Responsibilities in the Veonics® Ecosystem
- Authentication & Credential Security Controls
- System Access Control & Remote Access Policy
- User Rights & Access Review Process
Vulnerability and Incident Management
- Vulnerability Management, Assessments & Penetration Testing
- Cybersecurity Incident and Breach Resources & Roles
- Comprehensive Incident Response & Breach Notification Procedures
- Endpoint Protection Policy
Data Protection and Privacy
- Customer Data Privacy Policy
- Veonics® Portal Data Retention & Secure Deletion Policy
- Identification Badge Data Classification & Retention Standards
- External Network Connections & Data Transfer Policy
- How Are Data, Photos, and Other Files Securely Submitted?
Compliance and Governance
- Veonics® Portal Cybersecurity & Compliance Overview
- Contracting & Compliance Index
- Risk Assessment & Management Program
- Cybersecurity Awareness Education and Training
- Enterprise Compliance Program
Security Reviews and Evidence Requests
Customers with security questionnaires, vendor-risk reviews, insurance requirements, architecture questions, or requests for testing evidence should contact their eXpress badging representative.
Requests involving confidential technical evidence, redacted testing information, or detailed infrastructure documentation may require:
- Verification of the requesting organization
- A nondisclosure agreement
- Defined scope and business purpose
- Enterprise compliance onboarding
- Professional-service or compliance-review fees where applicable
This process protects both customer interests and the security of the Veonics® Portal environment.