Security
Article describing data security in piqlConnect
Summary
piqlConnect is a data lifecycle management system delivered as a Software-as-a-Service. A simple to use platform for data transfer and data access where security is a cornerstone of piqlConnect’s value proposition, and built on Microsoft Azure’s cloud infrastructure in Norway, the product inherits world-class security infrastructure while keeping data under European jurisdiction.
Each layer of the application is secured:
- encryption safeguards data at rest in databases, file shares, and blobs;
- TLS and network controls protect data in transit;
- Azure AD (Entra ID) and role-based access enforce authentication and authorisation; and comprehensive logging provides auditability.
- Azure Key Vault ensures that secret keys remain secret, Azure Database for MySQL and storage accounts ensure that archived data is safe from unauthorised access or breaches,
- and Azure’s Norwegian data centres ensure data residency for sovereignty and GDPR alignment.
- Integration with Stripe adds secure, compliant payment processing without exposing sensitive financial data to the application.
In a secure digital archiving platform like piqlConnect, protecting who can access what is just as critical as protecting the data itself. That’s why piqlConnect uses Auth0 as its identity platform, combined with optional Microsoft Entra ID (Azure Active Directory) integration, to ensure secure, flexible, and user-friendly access control for Clients.
By leveraging these technologies, piqlConnect offers its customers peace of mind that their digital records and files are handled with the highest security standards. The combination of Azure’s security features and compliance certifications with piqlConnect’s thoughtful architecture means that customers can focus on using the platform, confident that the data is private, protected, and compliant with European data protection laws. In a world where digital data sometimes must be preserved for decades and even centuries, piqlConnect’s secure Azure foundation ensures those files remain safe against both modern threats and evolving regulatory requirements – today and in the future.
Fully integrated with the most secure storage media out there, piqlFilm, Piql offer unprecedented data security for storage of critical files and information.
In-depth
We will now describe how each component of piqlConnect’s architecture
- Identity and Access
- Key Management
- Databases
- Storage
- Payment processing
– provides security for data at rest and in transit
Click here for a brief definition if you are unfamiliar with these terms.
Lastly, we also describe how Azure’s Norway regions support data sovereignty and compliance for European data laws.
Identity and Access
Argon2 serves as the identify and authentication backbone of piqlConnect for Users, managing user identities, login flows, and session handling.
To improve the security of user credentials, piqlConnect chose Argon2, a modern, memory-hard password hashing algorithm designed to resist brute-force and GPU-based attacks. Compared to older algorithms like bcrypt or PBKDF2, Argon2 provides superior protection against password cracking, particularly in the event of a database breach. Its design intentionally increases the computational and memory cost for attackers while maintaining efficiency for legitimate authentication.
In addition, by running our authentication solution on our own Azure infrastructure (rather than relying solely on a third-party identity platform), we retain full control over how user data is processed, stored, and secured. Hosting authentication on a dedicated Azure server located in Norway ensures that:
- All identity-related data remains within EU/EEA borders, supporting GDPR compliance and data sovereignty.
- Security configurations (e.g., key rotation, monitoring, firewall rules) are managed directly by our team, allowing for fine-grained access control and auditability.
- Integration with other Azure services (e.g., Key Vault, Azure Monitor, Private Networking) can be fully leveraged for enterprise-grade protection.
This architecture ensures that customer identities are handled with the highest level of transparency, control, and cryptographic security — aligning with piqlConnect’s commitment to secure and compliant digital archiving.
In addition, the identify and access functionality also include:
Two-Factor Authentication (2FA)
To strengthen security beyond simple passwords, piqlConnect supports multi-factor authentication (MFA/2FA). This means that even if a user’s password is compromised, an attacker cannot access the system without the second factor like a time-based one-time password (TOTP) via an app like Google Authenticator or Microsoft Authenticator. This
- Mitigates phishing and credential theft
- Adds a second layer of defence to user accounts
- Enforces compliance with regulations that require MFA (e.g., GDPR for sensitive access)
Microsoft Entra Login
piqlConnect also allows social and enterprise login using Microsoft Entra ID (formerly Azure Active Directory). This allows end users to log in using their existing Microsoft accounts, such as:
- Personal Microsoft accounts (e.g., Outlook.com, Hotmail)
- Work or school accounts tied to Microsoft Entra tenants
Benefits of Microsoft Login Integration:
- Single Sign-On (SSO): Users don’t need to manage a separate password — they use their Microsoft credentials to access piqlConnect.
- Inherits enterprise policies: Password policies, conditional access, and MFA settings from the organisation’s Azure AD tenant are enforced.
- Reduces friction for adoption among enterprise users and increases trust.
This is implemented securely via OAuth 2.0 and OpenID Connect (OIDC) protocols through Argon2, which acts as a federated identity broker.
Role-Based Access Control (RBAC)
Once authenticated, users are assigned roles and permissions within piqlConnect — such as Viewer, Editor, or Administrator. These roles determine:
- Which data and metadata the user can edit
- Which Team they belong to
- Whether they can manage other users or change system configurations
RBAC ensures the principle of least privilege is enforced: users only have access to the data and functions necessary for their tasks.
Secure Key Management: Key Vault
Azure Key Vault is central to piqlConnect’s security strategy for managing sensitive keys, secrets, and certificates. Azure Key Vault stores cryptographic keys and secrets in a secure, isolated vault backed by Hardware Security Modules (HSMs). All secrets in Key Vault are encrypted at rest All secrets in Key Vault are encrypted at rest using a robust encryption hierarchy with all keys in that hierarchy are protected by modules that are FIPS 140-2 compliant.
This means that even if someone could access the raw stored data, it would be unintelligible without the proper keys. In fact, Key Vault is designed so that even Microsoft cannot see or extract your keys; keys are safeguarded by industry-standard algorithms and HSMs, and cryptographic operations occur within the HSM.
Data in transit to and from the Key Vault is equally secure. Key Vault enforces TLS (Transport Layer Security) for all communications, ensuring that when piqlConnect services retrieve a secret or key, the communication is encrypted and protected from eavesdropping or tampering. Azure uses Perfect Forward Secrecy and strong 2048-bit RSA encryption for these TLS connections, which provides confidentiality and integrity for data in motion.
Azure Key Vault also supports strong authentication and fine-grained authorisation. Access to keys and secrets is controlled via Azure Active Directory identities and Key Vault access policies or role-based access control (RBAC). Only authorised applications and personnel (as defined by piqlConnect’s tenant administrators) can access specific secrets or perform key operations.
Every access or key usage can be logged and audited: Key Vault provides auditing functionality that logs who accessed which secret or key and when. In near real time.
Key Vault generates usage logs for key operations, allowing security teams to monitor and review cryptographic operations and detect any unauthorized access attempts
By using Azure Key Vault, piqlConnect ensures that secret credentials (such as database connection strings, API keys) and encryption keys for archived data are heavily protected. Keys are stored securely (in Norway-based HSMs), used only within controlled environments, and never exposed in plain text. This mitigates the risk of data breaches and supports compliance requirements for strong encryption key management.
Secure Database Storage: Azure Database for MySQL
piqlConnect relies on Azure Database for MySQL as its managed database service, benefiting from Azure’s built-in security for relational data. All data stored in the MySQL database is encrypted at rest by default. Azure Database for MySQL uses Azure Storage encryption under the hood, employing AES 256-bit encryption in a FIPS 140-2 validated cryptographic module to protect data at rest. This includes the primary database files, temporary files created during query processing, and all backups. (For example, automatic backups of the MySQL server are encrypted using AES-256 as well.
Data in transit to the MySQL database is protected via SSL/TLS. By default, Azure Database for MySQL enforces TLS 1.2 for all incoming connections, requiring encrypted connections between the application (piqlConnect’s services) and the database. Older, less secure TLS versions (1.0 and 1.1) are refused, ensuring modern cryptographic protocols protect data flowing over the network. This prevents attackers from snooping on or altering queries and data results as they travel between the application and the database.
Azure Database for MySQL also offers strong network security and identity features. Azure Database for MySQL supports Microsoft Entra ID (Azure AD) authentication for the database, allowing piqlConnect to manage database user identities and roles through Azure AD instead of static credentials. With Entra ID authentication, database access can be tied to centrally managed Azure AD accounts and groups, enabling uniform password policy, possible multi-factor authentication, and easy user provisioning or revocation. This integration eliminates the need to embed database passwords and helps enforce enterprise-wide identity standards.
From an authorization and auditing perspective, the MySQL engine has its own user permissions and roles, and Azure augments this with platform monitoring. Administrators can enforce the principle of least privilege in the database (so that, for example, the piqlConnect application user only has the minimal rights needed). Azure Database for MySQL provides auditing capabilities – logging access to the database and queries. These audit logs can record events like successful and failed logins or data access, which are important for compliance and forensic analysis.
In summary, piqlConnect’s use of Azure Database for MySQL means that archived data in structured form is stored on an encrypted, monitored database service with strict access controls, fulfilling both security best practices and GDPR’s requirements for protecting personal data.
Secure Archive Storage: Blob Storage
Many digital archives involve large files or objects (documents, images, etc.), and piqlConnect leverages Azure Blob Storage to store this unstructured data securely. Azure Blob Storage is engineered with a defense-in-depth approach to data protection.
Data at rest: Data at rest on Azure Blob Storage is automatically encrypted using Microsoft’s Service-Side Encryption (SSE). In practice, this means that whenever piqlConnect writes a file or object to Blob Storage, Azure will transparently encrypt the data using 256-bit AES encryption, and decrypt it when read, with no action needed by the application. The encryption process is FIPS 140-2 compliant, one of the strongest encryption standards available. Crucially, this storage encryption is enabled for all Azure storage accounts by default and cannot be turned off, ensuring that all blobs (including block blobs, append blobs, page blobs, and their metadata) are always stored in an encrypted form
Whether piqlConnect archives are in a “hot” tier for active use (Online) or an “archive” tier (Frozen Cloud) for long-term retention, the data remains encrypted in Azure’s Norwegian datacenters. Customers thus get encryption-at-rest by default, helping meet compliance requirements for safeguarding data on disk.
Data in transit: For data in transit, Azure Blob Storage uses secure protocols to protect data as it moves between piqlConnect’s application and the storage service. All connections to Azure Blob endpoints are encrypted using HTTPS/TLS. In fact, communication between a client application and Azure Storage is encrypted with TLS to ensure privacy and integrity. piqlConnect enforces “secure transfer required” on its storage accounts, meaning any attempt to connect over an unencrypted channel will be rejected. This guarantees that files uploaded or downloaded – such as digital records being archived or retrieved – cannot be intercepted or read by unauthorized parties on the network.
Azure Blob Storage also provides robust mechanisms for authentication and authorization. Every storage account has unique access keys and supports Shared Access Signatures (SAS) for delegated, time-bound permissions, but the recommended method for an enterprise solution like piqlConnect is to use Azure AD integration.
For auditability, Azure provides storage analytics and logging. piqlConnect can enable logging on blob storage to record operations such as read, write, or delete along with the caller identity (when using Azure AD auth). These logs can be fed to Azure Monitor or external systems to generate an audit trail of who accessed or modified any archive item – critical for monitoring and compliance verification.
Finally, Azure Blob Storage offers features supporting governance, such as immutable storage (Write-Once-Read-Many retention policies) and soft delete, which piqlConnect can use to prevent tampering or accidental deletion of archived records. Combined with its geo-redundancy options, Azure Blob gives piqlConnect a secure and resilient foundation for file storage.
Payment Processing Security: Stripe
While Azure secures the application and data storage, piqlConnect also handles payment transactions (for example, subscription billing for the service) through Stripe, a leading online payment processor. Stripe is an external service (not hosted on Azure) but is a critical part of the overall security and compliance architecture, especially regarding sensitive financial data.
piqlConnect chose Stripe for payments because of its strong security design and compliance with industry standards. Stripe is certified as a PCI DSS Level 1 Service Provider, the highest level of certification in the payment card industry, which means it meets all requirements for securely handling and processing credit card data. In practice, Stripe’s systems are audited annually by independent assessors to ensure they maintain strict controls over cardholder data. This relieves piqlConnect (and its Clients) from the heavy burden of directly processing or storing credit card details, which in turn reduces the scope of compliance they must manage.
Data at rest within Stripe’s infrastructure is heavily protected. All credit card numbers are encrypted at rest with AES-256 on Stripe’s servers. Stripe takes a layered approach: decryption keys are stored on separate machines and the primary card data storage is segregated from the rest of Stripe’s systems. Stripe internally tokenizes card numbers (PANs), meaning piqlConnect never sees the actual card number – only a token or the last 4 digits for reference – and Stripe’s own servers cannot retrieve plaintext PANs except through tightly controlled processes. Even within Stripe, the systems that store and decrypt card data run in a separate, isolated environment with minimal access (managed by a special team), adding an extra layer of protection.
For data in transit, Stripe ensures that all communication is secure. Any interaction with Stripe’s API or dashboard is encrypted using HTTPS/TLS, and Stripe enforces a minimum of TLS 1.2 for connections. In fact, Stripe uses mutual TLS (mTLS) for server-to-server communications, adding client-authentication to the TLS process for enhanced security. This means that when piqlConnect’s backend communicates with Stripe (e.g., to create a charge or subscription), both ends authenticate each other and negotiate a secure channel, protecting the payment data in transit. Stripe also uses HSTS (HTTP Strict Transport Security) and is on major browsers’ HSTS preload lists, ensuring browsers only connect to Stripe over secure channels.
Additionally, piqlConnect’s integration with Stripe is implemented in a way that no sensitive payment data ever touches piqlConnect’s servers. Using Stripe’s checkout or payment tokenization solutions, card details provided by a user go directly to Stripe’s infrastructure over an encrypted connection, and piqlConnect receives only a secure token or reference. This design follows Stripe’s recommended low-risk integration pattern, where payment information is transmitted directly to Stripe without passing through the Piql’s servers By doing so, piqlConnect significantly reduces its exposure to card data and simplifies PCI compliance obligations – Stripe handles the most sensitive aspects and provides the necessary certifications.
Stripe also supports robust authentication, authorisation, and auditing for the management of payment operations. piqlConnect uses Stripe’s API keys (which can be made restricted to limit their capabilities) to perform transactions. These keys are securely stored (in Key Vault) and are never exposed in client-side code. Stripe provides a security history log that tracks important account events (logins, changes, key usage), and it employs anomaly detection to flag unusual account access patterns. All of these measures mean that not only is card data secure within Stripe, but the processes around using Stripe in piqlConnect are also secure and trackable.
From a GDPR perspective, Stripe acts as a data processor for payment data and has its own GDPR and privacy compliance measures. Stripe participates in and complies with European and international data transfer frameworks and offers a Data Processing Addendum to its users, ensuring that personal data (like a payer’s details) is handled lawfully. Their adherence to privacy frameworks and use of strong encryption and access controls supports piqlConnect’s overall compliance stance when handling users’ personal and financial data.
Use of Norwegian Data Centres: Data Sovereignty and GDPR Compliance
Locating piqlConnect in Azure’s Norway East and Norway West data centres means that all customer data is stored and processed within Norway’s borders, under European data protection regulations. This setup allows organisations to use cloud services while complying with local laws and regulations, a benefit noted when Microsoft opened its Norwegian Azure regions.
Importantly for GDPR, Microsoft operates as a data processor (sub-processor of Piql) with robust privacy and security commitments. Microsoft contractually commits to meet all GDPR requirements in every Azure region, and all Azure services can be used in a GDPR-compliant manner. Client data in piqlConnect stays within the EU/EEA boundary, avoiding unwarranted cross-border transfers. Additionally, Azure’s compliance certifications (such as ISO/IEC 27018 for cloud privacy and ISO/IEC 27701 for privacy information management) and standard contractual clauses provide assurance that using Azure helps fulfill GDPR obligations.
In short, hosting piqlConnect in Azure’s Norwegian data centres gives European customers confidence that their archived data remains under European jurisdiction and is handled according to GDPR’s strict standards.
Sources:
- Microsoft Azure Documentation – Data Residency, GDPR and Security Compliance datacentrereview.com
- Azure Key Vault – Security Features and Encryption learn.microsoft.com
- Azure Database for MySQL – Security, Encryption and Networking learn.microsoft.com
- Azure Storage (Blob & Files) – Encryption at Rest and in Transit, AD Integration learn.microsoft.com
- Stripe Security Documentation – Payment Data Protection and Compliance docs.stripe.com