Security & Compliance

Enterprise-grade security and comprehensive compliance for organisations that demand the highest standards. Built for government and regulated industries.

Certifications & Standards

ISO 27001 Aligned

Aligned

Our security practices align with ISO 27001 international standards for information security management systems.

UK GDPR Compliant

Compliant

Full compliance with UK General Data Protection Regulation and Data Protection Act 2018.

Cyber Essentials Plus Ready

In Progress

Working towards Cyber Essentials Plus certification, the UK government-backed security scheme.

Equality Act 2010 Compliant

Compliant

Our AI systems are designed to prevent discrimination and promote equal opportunities.

Security Measures

Encryption at Rest

All data is encrypted using AES-256 encryption when stored in our databases and file systems.

Encryption in Transit

TLS 1.2+ encrypts all data transmitted between your browser and our servers.

Multi-Tenant Isolation

Complete logical separation ensures one organisation's data is never accessible to another.

Access Controls

Role-based access control (RBAC) ensures users only access data they're authorised to see.

UK Data Residency

All customer data is stored in UK-based AWS data centres (eu-west-2, London).

Audit Logging

Comprehensive audit trails track all access and modifications to sensitive data.

Regular Backups

Automated daily backups with point-in-time recovery (7-day retention).

Security Testing

Internal security testing and assessments, most recently completed July 2026.

Compliance Framework

Data Protection

  • UK GDPR and Data Protection Act 2018 compliance
  • Lawful basis documented for all processing activities
  • Privacy by design and by default principles
  • Data Protection Impact Assessments for high-risk processing
  • Appointed Data Protection Officer
  • Records of processing activities maintained
  • Data subject rights facilitation within statutory timeframes

AI Governance

  • Algorithmic Impact Assessments for AI features
  • Bias detection and monitoring dashboards
  • Human-in-the-loop for all hiring decisions
  • Explainable AI recommendations
  • Regular fairness audits across protected characteristics
  • Compliance with upcoming EU AI Act requirements
  • ICO AI and data protection guidance adherence

Employment Law

  • Equality Act 2010 compliance in all AI processes
  • Non-discrimination in automated screening
  • Reasonable adjustments support for disabled candidates
  • Age, gender, race, and other protected characteristic monitoring
  • EHRC guidance on AI in recruitment followed
  • Public Sector Equality Duty support for government clients
  • Right to work verification integration

Information Security

  • ISO 27001 aligned security management system
  • Annual security risk assessments
  • Incident response procedures and playbooks
  • Business continuity and disaster recovery plans
  • Security awareness training for all staff
  • Vendor security assessments for third parties
  • Regular vulnerability scanning and remediation

Public Sector Standards

We understand the unique requirements of UK government and public sector organisations. Our platform is designed to meet the stringent security and compliance standards required for public sector procurement.

G-Cloud Listing

Roadmap

We are preparing a listing on the UK Government Digital Marketplace to streamline procurement for public sector organisations. Not yet listed — on our roadmap.

SC Clearance Support

Supported

Our platform can be configured to support government clients with security-cleared staff requirements.

NCSC Guidance Alignment

Aligned

We follow National Cyber Security Centre guidance for cloud security and secure development.

Cabinet Office Standards

Aligned

Our data handling procedures align with Cabinet Office requirements for government suppliers.

Security Documentation

We're committed to transparency about our security practices. The following documentation is available to customers and prospective customers under NDA:

SOC 2 Report

Not yet available (roadmap)

Security Testing Summary

Internal — most recent July 2026

DPIA Template

For AI Features

DPA Template

Standard SCCs

Request Security Documentation

Incident Response

We maintain a comprehensive incident response programme to ensure rapid and effective handling of any security events:

72hrs

Maximum breach notification time (per GDPR)

We monitor our production environment and respond to security incidents as they arise. We don't yet operate a formal 24/7 SOC or a contracted incident response SLA — we'll tell you plainly if you ask.

Continuous Improvement

Security and compliance are not one-time achievements—they require ongoing commitment. Our programme includes:

  • Quarterly security reviews
  • Internal security testing
  • Ongoing staff security training
  • Regular compliance audits
  • Vulnerability management programme
  • Third-party vendor risk assessments

Questions About Our Security?

Our security team is happy to discuss our compliance posture and answer any questions about how we protect your data.