Trust centre
What we actually have in place.
Below is every security and privacy control we run, each marked with its real status. Where something is still being built, it says so. You should be able to take this page to your security team without a follow-up call to find out which of it is aspirational.
11 of 14 controls in place. Evidence for any control marked In place is available on request during procurement.
Infrastructure
Where the software runs and how that environment is protected.
- In place
Hosted on managed cloud infrastructure
AWS and Azure regions, no self-managed hardware in the serving path.
- In place
TLS on all traffic in transit
- In place
Encryption at rest
- In place
DDoS protection and web application firewall
Cloudflare, with a tuned managed WAF ruleset.
- In place
Independent penetration testing
Performed by an independent external assessor. Findings are confidential.
Data and privacy
How customer data is separated, processed, and handed back.
- In place
Tenant data isolation
Per-tenant separation across the multi-tenant products.
- In place
Role-based access control
- In progress
Data processing agreement available
Available on request during procurement.
- In place
Cookie and tracking consent
- In progress
GDPR alignment
Reviewing our processing basis and retention policy with counsel.
Operations
How we build, monitor, and respond when something breaks.
- In place
Secure development lifecycle
Code review and dependency scanning before release.
- In progress
Security training for engineering staff
- In place
24/7 incident response
Round-the-clock on-call rotation for production incidents.
- In place
Uptime SLA
A formal SLA is in place, provided directly to contracted customers.
Need something not listed?
Security questionnaires, a DPA, architecture detail, or a specific control your policy requires — ask and we will tell you plainly whether we have it today.

