We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
A system of record for regulatory obligations is only as trustworthy as its own security. We build for UK and EU data residency, least-privilege access, and tamper-evident evidence from the ground up, not as an afterthought.
Customer data is processed and stored in the UK or EU, including the model endpoints used for retrieval and analysis.
Transport encryption everywhere, encryption at rest for stored data, with managed keys.
Role-scoped access, short-lived credentials, and audit logging on the systems that hold customer data.
The cryptographic spine records governance actions as a verifiable, tamper-evident chain, so a produced record can be trusted.
A short, reviewed set of subprocessors, chosen for regional processing and available to customers on request.
Regular backups and tested recovery, so the record survives failure without losing its chain of custody.
We're building the assurance posture a regulated buyer expects, owned by our CTO. Where a certification is in progress rather than complete, we say so plainly.
Information security management. In certification now.
AI management systems, the standard a governance vendor should be able to meet itself. In certification now.
Planned to follow the ISO certifications.
The UK security baseline, relevant to public-sector and critical-infrastructure procurement.
Our customers are regulated enterprises, many with strict residency and transfer requirements. The platform is architected so that customer content, and the AI processing applied to it, stays within the UK or EU.
As a UK-domiciled vendor hosting in the UK or EU, we carry materially lower exposure to the US CLOUD Act than US-headquartered alternatives, because the Act follows provider control, not data location.
If you believe you've found a vulnerability, report it to us before disclosing it publicly. We'll acknowledge your report, keep you updated while we investigate, and we won't pursue action against research conducted in good faith under a coordinated-disclosure approach.