Security & Trust

The security summary your IT team asked for.

A short, plain-English summary of how we host, secure, segregate and audit our products. Anything more detailed - policies, penetration-test summaries, data-flow diagrams - is provided under NDA on request.


/ 01

Encryption

TLS in transit, at-rest encryption for stored data, and key management aligned with industry practice.

/ 02

Access control

MFA, role-based access control with named permissions, and lifecycle management (activate, deactivate, retain history).

/ 03

Data segregation

Access segregated by organisation, team and user. Customer data is not used to train shared models and is not shared across tenants.

/ 04

Testing & monitoring

Independent third-party penetration testing on a regular cadence, application-level monitoring, and a web application firewall in front of user-facing services.

/ 05

UK hosting

Services are hosted on UK infrastructure. Region-locked with data residency configurable per customer where required.

/ 06

Audit history

Every action - who did what, when and from where - is written to an immutable audit trail across ScoreCoach, InsolVatrack and Partner Connect.

Certifications

Certifications will be listed here as and when they are formally held or in-progress. We do not claim certifications we have not been awarded. For your current requirements, please reach out via the contact form.

Due diligence

Point your IT-security team here first.

Have your team send us their questionnaire. We normally return a completed response within one working week, and can arrange a structured technical session with our engineering team on request.