Security · Privacy · Compliance

Trust, built for the moments that matter most.

FirstHour is a crisis communication platform. This Trust Center sets out the controls that protect the service and the data our customers entrust to it.

EU-hostedData stored & processed in the EU
EncryptedIn transit and at rest
Human-approved AIReview before publication
Certified cloudISO 27001 / SOC 2 infrastructure

Overview

The controls below are in effect today. Planned work is listed separately under Roadmap. Detailed documentation is available to customers and prospects on request.

Last reviewed: July 2026

Compliance & certifications

ISO/IEC 27001

Inherited (Azure)

SOC 1 / 2 / 3

Inherited (Azure)

GDPR

Aligned

EU data residency

Enforced

Encryption

Enforced

SOC 2 Type II

In preparation

Security controls

Infrastructure & hosting3 controls
  • Enterprise cloud hosting

    The service runs on Microsoft Azure, built on ISO 27001 / SOC 2 certified infrastructure.

  • EU data residency

    All customer data is stored and processed within the European Union.

  • Infrastructure as code

    Environments are provisioned from version-controlled definitions for consistent, auditable configuration.

Data security & encryption3 controls
  • Encryption in transit and at rest

    Traffic is protected with TLS; stored data is encrypted at rest using AES-256.

  • Managed secrets vault

    Credentials and keys are held in a managed secrets vault, isolated per environment and never stored in source control.

  • Logical tenant isolation

    Every request is scoped to a single customer organisation, preventing cross-tenant data access.

Access control & authentication4 controls
  • Scoped authentication

    Access is token-based, with separate scopes so external reviewers never receive platform-level access.

  • Two-factor authentication

    One-time-password verification is enforced on external approval flows.

  • Strong credential storage

    Passwords are hashed with modern, industry-standard algorithms.

  • Least-privilege access

    Access to production systems is limited to those who require it.

Application security & development3 controls
  • Mandatory peer review

    All code changes are reviewed before they are merged.

  • Automated quality gates

    Every change passes automated checks and tests before deployment.

  • Controlled deployments

    Releases run through automated pipelines; no manual changes are made to production.

Business continuity2 controls
  • Automated backups

    Data is backed up automatically with point-in-time restore.

  • Resilient managed infrastructure

    The platform builds on redundant, managed cloud services.

AI governance

  • Inference within a controlled boundary

    AI processing runs within our cloud provider's boundary. Customer content is not sent directly to third-party model providers.

  • Human review before publication

    AI assists with drafting only. A person reviews and approves every statement before it is published.

  • Traceable and auditable

    AI activity is logged and traceable for review.

Privacy & GDPR

  • EU data residency

    Personal data is stored and processed within the European Union.

  • Governed sub-processors

    A limited set of sub-processors support the service, each bound by a data processing agreement. The current list is available on request.

  • Data minimisation

    We limit the personal data processed to what the service requires.

Roadmap

  • SOC 2 Type II

    Establishing the control framework ahead of a formal audit.

  • Independent penetration testing

    Scheduling regular third-party security testing.

  • Continuous vulnerability scanning

    Automated dependency, code and container scanning across the pipeline.

  • Published privacy documentation

    Privacy notice, customer DPA and data-subject-request process.

  • AI data-retention attestation

    Formal confirmation of no-training and limited-retention terms for AI processing.

Documents

Security overviewPlatform architecture and controls On request
Technical & Organisational Measures (TOMs)GDPR Article 32 measures Word · Download
Sub-processor listThird parties that support the service On request
Data processing agreement (DPA)Template available for customers On request

Contact

Security & compliance enquiries

For security questionnaires, documentation or a DPA, contact our security team.

security@firsthour.ai