Built for sensitive compliance data.
ICT third-party risk data includes contracts, audit reports and supplier detail. We state plainly what is available today and what is planned, and we do not claim certifications we do not hold.
Status labels
Available, Enterprise, Planned or Coming Soon.
Anything not marked Available is not in production today. We do not currently hold ISO 27001 or SOC 2 certification.
Infrastructure Security
- Available
EU data hosting
Customer data is stored and processed in European Union regions.
- Available
Hardened cloud infrastructure
Managed cloud services with restricted network access and least-privilege service accounts.
- Planned
Independent infrastructure penetration test
Annual third-party testing programme.
Encryption
- Available
Encryption in transit
TLS for all traffic between clients, services and storage.
- Available
Encryption at rest
Database and object storage encrypted at rest.
- Planned
Customer-managed keys
Bring-your-own-key for encryption at rest.
Tenant Isolation
- Available
Logical tenant isolation
Every record is scoped to a workspace and enforced server-side.
- Available
Separate vendor portal scope
Vendors only access the assessments and requests addressed to them.
- Enterprise
Dedicated deployment
Isolated environment for large institutions.
Access Control
- Available
Role-based access control
Admin, risk manager, analyst, auditor and read-only roles.
- Available
Multi-factor authentication
MFA available for all workspace users.
- Enterprise
SSO / SAML
Federated sign-in with your identity provider.
- Coming Soon
SCIM provisioning
Automated user lifecycle management.
Auditability
- Available
Audit logs
Who changed what, when, across providers, assessments, evidence, risks and the Register.
- Available
Field-level lineage
Regulatory values trace to their source record and evidence.
- Planned
Audit log export
Scheduled export to your SIEM.
Backups
- Available
Automated backups
Regular encrypted backups of customer data.
- Available
Point-in-time recovery
Restore to a specific point within the retention window.
- Planned
Documented restore testing
Periodic restore exercises with published results.
Data Retention
- Available
Deletion on request
An Organization Admin can export the whole workspace as JSON and permanently delete it — all records and all member accounts — from Settings › Data & retention.
- Planned
Configurable retention policies
Set retention per object type.
- Planned
Legal hold
Preserve records beyond standard retention.
AI Data Handling
- Available
No training on customer data
Documents and responses are processed to produce findings for your workspace only.
- Available
Workspace AI controls
An Organization Admin can switch model-assisted review off for the workspace; review then runs the rule-based pass only and no document or response text leaves the platform.
- Available
Human review required
AI never changes compliance status without an explicit human decision.
- Planned
EU-region model processing
Model inference restricted to EU regions.
Incident Management
- Available
Severity classification, triage targets, containment, recovery, customer notification windows and post-incident review.
- Coming Soon
Status page
Public availability and incident communication.
- Enterprise
Contractual notification commitments
Notification timelines agreed in the customer contract.
Compliance Roadmap
- Planned
ISO 27001 certification
Not certified today. Preparation is on our roadmap and we will publish the certificate when achieved.
- Planned
SOC 2 Type II
Not audited today. Planned once the ISMS programme is complete.
- Available
Security documentation pack
Architecture, sub-processors and DPA available on request.
Have a security review to complete?
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.