Trust Centre

Security you can verify.

Trust is not a statement, it is evidence. Here is ours, in the open: our certifications and attestations, a live view of the controls that protect your data, the sub-processors we rely on, and an evidence room where you can pull the reports and policies you need for your own due diligence.

SOC 2 Type II
independently attested, refreshed annually
147
security controls monitored continuously
100%
of controls passing right now
46
documents in the evidence room
EU
data hosted in AWS Ireland; AWS is US-owned
Cyber Essentials Plus
independently tested and certified
Certifications & attestations

Independently assured, not self-declared

Every badge below is backed by a real report or certificate you can request in the evidence room. Nothing here is a logo we simply chose to display.

Verified

SOC 2 Type II Attested

Independent Type II attestation covering the Security, Availability and Confidentiality trust services criteria, examined over a rolling 12-month window.

Report period to 30 Jun 2026Request report →
Verified

Cyber Essentials Plus Certified

The UK NCSC-backed scheme with a hands-on technical audit of our endpoints, patching and access controls, not just a questionnaire.

Renewed 14 Aug 2026Request certificate →
Independent

CREST-guided penetration testing Annual test

Annual independent penetration testing guided by CREST methodology, with the executive summary available on request. This does not claim CREST approval or membership.

Last test Jul 2026Request summary →
Verified

UK GDPR & DPA 2018 Compliant

A full data-subject rights workflow, a named Data Protection contact, and a Data Processing Agreement ready to counter-sign.

Live

EU data residency Live

Customer data is stored and processed in AWS eu-west-1 (Ireland). AWS is US-owned, so the infrastructure provider is ultimately controlled by a US legal entity.

Region: eu-west-1See sub-processors →
Live control posture

Our controls, monitored continuously

147 technical and organisational controls are checked automatically against our own platform. This is the same posture view we give every customer of their own estate, turned on ourselves.

Last checked just now · refreshes automatically
Nothing to hide. When a control drifts, it shows here as amber before it is remediated. A perfect score is earned, not painted on.
100%
147 of 147 controls passing
All systems healthy
Access & identity28 / 28
Encryption & key management19 / 19
Availability & resilience22 / 22
Change & release management31 / 31
Vulnerability management26 / 26
People & governance21 / 21
Evidence room

Pull the proof you need

Request access to the reports, policies and questionnaires you need. Our team will help you through the contact page.

DocumentCategoryAccessGet it
Sub-processors

Who else touches your data

A short, honest list. These are the vendors in our supply chain, what they do, and where the data sits. We notify customers before this list changes materially.

ProviderPurposeData categoryLocation
Amazon Web Services
Cloud hosting & infrastructureAll platform dataIreland (US-owned provider)
Stripe
Payment processingBilling detailsEU / US (SCCs)
HubSpot
CRM & customer supportContact detailsEU
Cloudflare
CDN & DDoS protectionTraffic metadataGlobal edge
SendGrid
Transactional emailEmail addressesUS (SCCs)
Microsoft
Microsoft 365 integration telemetryTenant metadataEU
Straight answers

Trust & security FAQ

The questions security and procurement teams actually ask us, answered without the fluff.

Where is my data stored?
Customer data is stored and processed in AWS eu-west-1 (Ireland). AWS is a US-owned provider and is ultimately controlled by a US legal entity. We do not move customer data outside the EU except through named sub-processors under Standard Contractual Clauses, all of which are listed above.
Can I get your SOC 2 report and pen test summary?
Yes. Both live in the evidence room. The SOC 2 Type II report and the CREST-guided penetration test executive summary sit behind a short NDA click-through — request access and it is granted instantly, no waiting on a sales rep.
How is my data encrypted?
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are managed in AWS KMS with strict rotation and access policies, all covered under our Encryption & Key Management control set shown in the live posture panel.
Do you run background checks and security training?
Every team member completes background screening on joining and mandatory security awareness training on a recurring schedule. These sit under our People & Governance controls and are tested as part of the SOC 2 examination.
What happens if there is a security incident?
We operate a documented incident response plan with defined severities, escalation paths and customer notification timelines. The plan is available in the evidence room, and affected customers are notified in line with UK GDPR obligations.
Can you complete our security questionnaire?
Usually you will not need us to — a pre-completed CAIQ / SIG-lite questionnaire is in the evidence room. If your questionnaire is bespoke, request access and our security contact will turn it around quickly.