Security

Built for sensitive compliance data.

ICT third-party risk data includes contracts, audit reports and supplier detail. We state plainly what is available today and what is planned, and we do not claim certifications we do not hold.

Status labels

Available, Enterprise, Planned or Coming Soon.

Anything not marked Available is not in production today. We do not currently hold ISO 27001 or SOC 2 certification.

Infrastructure Security

  • EU data hosting

    Customer data is stored and processed in European Union regions.

    Available
  • Hardened cloud infrastructure

    Managed cloud services with restricted network access and least-privilege service accounts.

    Available
  • Independent infrastructure penetration test

    Annual third-party testing programme.

    Planned

Encryption

  • Encryption in transit

    TLS for all traffic between clients, services and storage.

    Available
  • Encryption at rest

    Database and object storage encrypted at rest.

    Available
  • Customer-managed keys

    Bring-your-own-key for encryption at rest.

    Planned

Tenant Isolation

  • Logical tenant isolation

    Every record is scoped to a workspace and enforced server-side.

    Available
  • Separate vendor portal scope

    Vendors only access the assessments and requests addressed to them.

    Available
  • Dedicated deployment

    Isolated environment for large institutions.

    Enterprise

Access Control

  • Role-based access control

    Admin, risk manager, analyst, auditor and read-only roles.

    Available
  • Multi-factor authentication

    MFA available for all workspace users.

    Available
  • SSO / SAML

    Federated sign-in with your identity provider.

    Enterprise
  • SCIM provisioning

    Automated user lifecycle management.

    Coming Soon

Auditability

  • Audit logs

    Who changed what, when, across providers, assessments, evidence, risks and the Register.

    Available
  • Field-level lineage

    Regulatory values trace to their source record and evidence.

    Available
  • Audit log export

    Scheduled export to your SIEM.

    Planned

Backups

  • Automated backups

    Regular encrypted backups of customer data.

    Available
  • Point-in-time recovery

    Restore to a specific point within the retention window.

    Available
  • Documented restore testing

    Periodic restore exercises with published results.

    Planned

Data Retention

  • Deletion on request

    An Organization Admin can export the whole workspace as JSON and permanently delete it — all records and all member accounts — from Settings › Data & retention.

    Available
  • Configurable retention policies

    Set retention per object type.

    Planned
  • Legal hold

    Preserve records beyond standard retention.

    Planned

AI Data Handling

  • No training on customer data

    Documents and responses are processed to produce findings for your workspace only.

    Available
  • Workspace AI controls

    An Organization Admin can switch model-assisted review off for the workspace; review then runs the rule-based pass only and no document or response text leaves the platform.

    Available
  • Human review required

    AI never changes compliance status without an explicit human decision.

    Available
  • EU-region model processing

    Model inference restricted to EU regions.

    Planned

Incident Management

  • Documented incident process

    Severity classification, triage targets, containment, recovery, customer notification windows and post-incident review.

    Available
  • Status page

    Public availability and incident communication.

    Coming Soon
  • Contractual notification commitments

    Notification timelines agreed in the customer contract.

    Enterprise

Compliance Roadmap

  • ISO 27001 certification

    Not certified today. Preparation is on our roadmap and we will publish the certificate when achieved.

    Planned
  • SOC 2 Type II

    Not audited today. Planned once the ISMS programme is complete.

    Planned
  • Security documentation pack

    Architecture, sub-processors and DPA available on request.

    Available

Have a security review to complete?

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.