Security & Trust
The security summary your IT team asked for.
A short, plain-English summary of how we host, secure, segregate and audit our products. Anything more detailed - policies, penetration-test summaries, data-flow diagrams - is provided under NDA on request.
/ 01
Encryption
TLS in transit, at-rest encryption for stored data, and key management aligned with industry practice.
/ 02
Access control
MFA, role-based access control with named permissions, and lifecycle management (activate, deactivate, retain history).
/ 03
Data segregation
Access segregated by organisation, team and user. Customer data is not used to train shared models and is not shared across tenants.
/ 04
Testing & monitoring
Independent third-party penetration testing on a regular cadence, application-level monitoring, and a web application firewall in front of user-facing services.
/ 05
UK hosting
Services are hosted on UK infrastructure. Region-locked with data residency configurable per customer where required.
/ 06
Audit history
Every action - who did what, when and from where - is written to an immutable audit trail across ScoreCoach, InsolVatrack and Partner Connect.
Certifications
Certifications will be listed here as and when they are formally held or in-progress. We do not claim certifications we have not been awarded. For your current requirements, please reach out via the contact form.
Due diligence
Point your IT-security team here first.
Have your team send us their questionnaire. We normally return a completed response within one working week, and can arrange a structured technical session with our engineering team on request.