Trust Center

    Security and privacy, by design.

    We hold ourselves to the same standards your regulator holds you to — independently audited, continuously monitored.

    Independently certified to international standards

    ISO/IEC 27001 — Information Security ManagementISO 9001 — Quality ManagementISO 22301 — Business Continuity Management

    ISO/IEC 27001

    Information security management system certified by an accredited body.

    ISO 9001

    Quality management system ensuring consistent service delivery and continuous improvement.

    ISO 22301

    Business continuity management — resilience, recovery, and operational continuity.

    GDPR & CCPA

    Lawful processing, DPIAs on request, EU SCCs, and DSAR support out of the box.

    Regional data residency

    Choose where customer data is stored: EU, UK, US, MENA, or APAC.

    Single sign-on & MFA

    SAML 2.0 / OIDC, enforced MFA, role-based access, and SCIM provisioning.

    AI & Governance

    AI that augments your team — never replaces your judgement.

    Our AI capabilities are built around a strict human-in-the-loop model, full audit traceability, and alignment with the EU AI Act. No automated decision affects a customer without a documented human review.

    Model usage & data

    We use frontier and EU-hosted LLMs for drafting, summarisation, and rule generation. Customer data is never used to train third-party models. PII is redacted before any external inference call.

    Human-in-the-loop

    Every AI suggestion — rule, alert disposition, narrative — requires explicit human approval. MLRO four-eyes workflows are enforced for activation, with full attribution.

    Audit trails

    Every prompt, model version, input, output, citation and human decision is logged immutably for the full retention period. Regulators and auditors get reproducible evidence on demand.

    EU AI Act alignment

    Mapped to high-risk system obligations: risk management, data governance, transparency, human oversight, accuracy and cybersecurity. DPIAs and FRIAs available on request.

    Architecture

    Encrypted in transit and at rest.

    TLS 1.3 for all traffic. AES-256 envelope encryption with customer-managed keys (BYOK) available on enterprise plans. Tenants are logically isolated; data never leaves your chosen region.

    Privacy

    Your data, your control.

    Granular retention policies, on-demand DSAR exports, and signed DPAs. We never use your data to train models, and we never sell it.