Security you can verify.
Trust is not a statement, it is evidence. Here is ours, in the open: our certifications and attestations, a live view of the controls that protect your data, the sub-processors we rely on, and an evidence room where you can pull the reports and policies you need for your own due diligence.
Independently assured, not self-declared
Every badge below is backed by a real report or certificate you can request in the evidence room. Nothing here is a logo we simply chose to display.
SOC 2 Type II Attested
Independent Type II attestation covering the Security, Availability and Confidentiality trust services criteria, examined over a rolling 12-month window.
Cyber Essentials Plus Certified
The UK NCSC-backed scheme with a hands-on technical audit of our endpoints, patching and access controls, not just a questionnaire.
CREST-guided penetration testing Annual test
Annual independent penetration testing guided by CREST methodology, with the executive summary available on request. This does not claim CREST approval or membership.
UK GDPR & DPA 2018 Compliant
A full data-subject rights workflow, a named Data Protection contact, and a Data Processing Agreement ready to counter-sign.
EU data residency Live
Customer data is stored and processed in AWS eu-west-1 (Ireland). AWS is US-owned, so the infrastructure provider is ultimately controlled by a US legal entity.
Our controls, monitored continuously
147 technical and organisational controls are checked automatically against our own platform. This is the same posture view we give every customer of their own estate, turned on ourselves.
Pull the proof you need
Request access to the reports, policies and questionnaires you need. Our team will help you through the contact page.
| Document | Category | Access | Get it |
|---|
Who else touches your data
A short, honest list. These are the vendors in our supply chain, what they do, and where the data sits. We notify customers before this list changes materially.
| Provider | Purpose | Data category | Location |
|---|---|---|---|
Amazon Web Services | Cloud hosting & infrastructure | All platform data | Ireland (US-owned provider) |
Stripe | Payment processing | Billing details | EU / US (SCCs) |
HubSpot | CRM & customer support | Contact details | EU |
Cloudflare | CDN & DDoS protection | Traffic metadata | Global edge |
SendGrid | Transactional email | Email addresses | US (SCCs) |
Microsoft | Microsoft 365 integration telemetry | Tenant metadata | EU |
Trust & security FAQ
The questions security and procurement teams actually ask us, answered without the fluff.
Where is my data stored?
Can I get your SOC 2 report and pen test summary?
How is my data encrypted?
Do you run background checks and security training?
What happens if there is a security incident?
Can you complete our security questionnaire?
Request access
You are requesting this document. Tell us who you are and accept a short NDA — access is granted instantly.