Trust & security
What we hold, where it sits, and what we can prove.
Stated plainly, including the things that are still in progress. A product about evidence should not be vague about its own.
Data
- Customer data held in a United Kingdom region
- Encrypted in transit and at rest
- Tenant isolation enforced at the database layer
- Evidence objects held under retention locks and cannot be altered
- Full export with a verifiable manifest, on request or self-service
Integrity
- Append-only audit log, hash chained per customer
- Signed checkpoints published to separate immutable storage
- Scheduled verification of the chain, with the result visible to you
- Our own staff access to your data is written into the same log
- Time-boxed, logged read-only access available for regulators
Certification
Where we are, without rounding up.
| Item | Status |
|---|---|
| ICO registration | Held |
| Cyber Essentials | Held |
| Cyber Essentials Plus | In progress |
| Independent penetration test | Scheduled |
| ISO 27001 | Implementation under way |
| Independent review of the audit layer | Planned |
Update this table as things change, and never let it run ahead of reality. Procurement teams check.
Continuity
Golden thread information has to survive changes of ownership, changes of managing agent, and the failure of any supplier, including us. Source code and data escrow are part of the standard agreement, the export schema is open, and you can take a complete, verifiable copy of your records at any time without asking.
Security questions, or want our DPA and sub-processor list? Get in touch.