Trust & security

Security is foundational, not a later feature

This product is a data processor: it holds your data protection records, which can themselves contain personal data. The baseline below is built in from day one.

Data residency (EU)

The application and database are hosted in the EU, and your stored records stay in-region. The one exception is AI drafting, where the inputs are processed by Anthropic in the US under appropriate safeguards (see Controlled AI data handling).

Encryption

All traffic is encrypted in transit with TLS. The database is encrypted at rest. Card details are never stored by us; payments are handled by Stripe.

Tenant isolation

Every record belongs to your organisation and is scoped to it at the data-access layer. There is no global data path; a cross-tenant data leak is treated as the worst-case bug and designed against.

Authentication & access

Sign-in is handled by a reputable managed authentication provider with multi-factor authentication available. Sessions are secure and expiring; least privilege is applied to administrative tooling.

Audit logging

Significant actions (authentication events, data changes, and every AI call) are recorded in an append-only audit log, because a compliance product should be able to show its own working.

Controlled AI data handling

AI assistance runs server-side only; the API key is never exposed to the browser. Inputs are sent to Anthropic's API and processed in the US under Standard Contractual Clauses and the UK Addendum. They are not used to train models, and Anthropic retains them for up to 30 days for safety before deleting them. Every call is logged.

Secrets management

All secrets are injected from a secrets manager or environment at deploy time and are never committed to source control or shipped to the browser.

Sub-processors & your DPA

We use a small set of sub-processors to run the service, listed in full in our Privacy Notice. Our Data Processing Agreement is published and applies to every customer automatically, no signature needed. It covers the Article 28 essentials: documented instructions, confidentiality, security measures, sub-processor changes with notice, breach notification, and deletion at the end of the contract.