Security Measures
Encryption at Rest
All data is encrypted using AES-256 encryption when stored in our databases and file systems.
Encryption in Transit
TLS 1.2+ encrypts all data transmitted between your browser and our servers.
Multi-Tenant Isolation
Complete logical separation ensures one organisation's data is never accessible to another.
Access Controls
Role-based access control (RBAC) ensures users only access data they're authorised to see.
UK Data Residency
All customer data is stored in UK-based AWS data centres (eu-west-2, London).
Audit Logging
Comprehensive audit trails track all access and modifications to sensitive data.
Regular Backups
Automated daily backups with point-in-time recovery (7-day retention).
Security Testing
Internal security testing and assessments, most recently completed July 2026.
Compliance Framework
Data Protection
- UK GDPR and Data Protection Act 2018 compliance
- Lawful basis documented for all processing activities
- Privacy by design and by default principles
- Data Protection Impact Assessments for high-risk processing
- Appointed Data Protection Officer
- Records of processing activities maintained
- Data subject rights facilitation within statutory timeframes
AI Governance
- Algorithmic Impact Assessments for AI features
- Bias detection and monitoring dashboards
- Human-in-the-loop for all hiring decisions
- Explainable AI recommendations
- Regular fairness audits across protected characteristics
- Compliance with upcoming EU AI Act requirements
- ICO AI and data protection guidance adherence
Employment Law
- Equality Act 2010 compliance in all AI processes
- Non-discrimination in automated screening
- Reasonable adjustments support for disabled candidates
- Age, gender, race, and other protected characteristic monitoring
- EHRC guidance on AI in recruitment followed
- Public Sector Equality Duty support for government clients
- Right to work verification integration
Information Security
- ISO 27001 aligned security management system
- Annual security risk assessments
- Incident response procedures and playbooks
- Business continuity and disaster recovery plans
- Security awareness training for all staff
- Vendor security assessments for third parties
- Regular vulnerability scanning and remediation
Public Sector Standards
We understand the unique requirements of UK government and public sector organisations. Our platform is designed to meet the stringent security and compliance standards required for public sector procurement.
G-Cloud Listing
We are preparing a listing on the UK Government Digital Marketplace to streamline procurement for public sector organisations. Not yet listed — on our roadmap.
SC Clearance Support
Our platform can be configured to support government clients with security-cleared staff requirements.
NCSC Guidance Alignment
We follow National Cyber Security Centre guidance for cloud security and secure development.
Cabinet Office Standards
Our data handling procedures align with Cabinet Office requirements for government suppliers.
Security Documentation
We're committed to transparency about our security practices. The following documentation is available to customers and prospective customers under NDA:
SOC 2 Report
Not yet available (roadmap)
Security Testing Summary
Internal — most recent July 2026
DPIA Template
For AI Features
DPA Template
Standard SCCs
Incident Response
We maintain a comprehensive incident response programme to ensure rapid and effective handling of any security events:
Maximum breach notification time (per GDPR)
We monitor our production environment and respond to security incidents as they arise. We don't yet operate a formal 24/7 SOC or a contracted incident response SLA — we'll tell you plainly if you ask.
Continuous Improvement
Security and compliance are not one-time achievements—they require ongoing commitment. Our programme includes:
- Quarterly security reviews
- Internal security testing
- Ongoing staff security training
- Regular compliance audits
- Vulnerability management programme
- Third-party vendor risk assessments
Questions About Our Security?
Our security team is happy to discuss our compliance posture and answer any questions about how we protect your data.