Overview
The controls below are in effect today. Planned work is listed separately under Roadmap. Detailed documentation is available to customers and prospects on request.
Compliance & certifications
ISO/IEC 27001
SOC 1 / 2 / 3
GDPR
EU data residency
Encryption
SOC 2 Type II
Security controls
Infrastructure & hosting3 controls
Enterprise cloud hosting
The service runs on Microsoft Azure, built on ISO 27001 / SOC 2 certified infrastructure.
EU data residency
All customer data is stored and processed within the European Union.
Infrastructure as code
Environments are provisioned from version-controlled definitions for consistent, auditable configuration.
Data security & encryption3 controls
Encryption in transit and at rest
Traffic is protected with TLS; stored data is encrypted at rest using AES-256.
Managed secrets vault
Credentials and keys are held in a managed secrets vault, isolated per environment and never stored in source control.
Logical tenant isolation
Every request is scoped to a single customer organisation, preventing cross-tenant data access.
Access control & authentication4 controls
Scoped authentication
Access is token-based, with separate scopes so external reviewers never receive platform-level access.
Two-factor authentication
One-time-password verification is enforced on external approval flows.
Strong credential storage
Passwords are hashed with modern, industry-standard algorithms.
Least-privilege access
Access to production systems is limited to those who require it.
Application security & development3 controls
Mandatory peer review
All code changes are reviewed before they are merged.
Automated quality gates
Every change passes automated checks and tests before deployment.
Controlled deployments
Releases run through automated pipelines; no manual changes are made to production.
Business continuity2 controls
Automated backups
Data is backed up automatically with point-in-time restore.
Resilient managed infrastructure
The platform builds on redundant, managed cloud services.
AI governance
Inference within a controlled boundary
AI processing runs within our cloud provider's boundary. Customer content is not sent directly to third-party model providers.
Human review before publication
AI assists with drafting only. A person reviews and approves every statement before it is published.
Traceable and auditable
AI activity is logged and traceable for review.
Privacy & GDPR
EU data residency
Personal data is stored and processed within the European Union.
Governed sub-processors
A limited set of sub-processors support the service, each bound by a data processing agreement. The current list is available on request.
Data minimisation
We limit the personal data processed to what the service requires.
Roadmap
SOC 2 Type II
Establishing the control framework ahead of a formal audit.
Independent penetration testing
Scheduling regular third-party security testing.
Continuous vulnerability scanning
Automated dependency, code and container scanning across the pipeline.
Published privacy documentation
Privacy notice, customer DPA and data-subject-request process.
AI data-retention attestation
Formal confirmation of no-training and limited-retention terms for AI processing.
Documents
Contact
Security & compliance enquiries
For security questionnaires, documentation or a DPA, contact our security team.