Bank-Level Security

Security & Data Protection

We understand that you're entrusting us with sensitive financial data. Security isn't an afterthought—it's built into everything we do.

ICO Registered
UK GDPR Compliant
Data Protection Officer Appointed

Our Data Protection Framework

We've implemented a comprehensive GDPR compliance framework to protect your data and your clients' data.

Data Protection Impact Assessment

We've conducted a thorough DPIA to identify and minimise the data protection risks of our processing activities. This is reviewed regularly as our platform evolves.

Data Processing Register

We maintain a comprehensive record of all processing activities, including the purposes, data categories, retention periods, and security measures for each type of processing.

Privacy Policy

Our privacy policy clearly explains what data we collect, how we use it, who we share it with, and your rights. It's written in plain English, not legal jargon.

Data Subject Rights

We have documented procedures for handling data subject requests including access, rectification, erasure, and portability. We respond within the statutory timeframes.

How We Protect Your Data

We implement comprehensive technical measures to protect personal data against unauthorised access, loss, or destruction.

Encryption at Rest

All data is encrypted using AES-256 encryption when stored.

Encryption in Transit

All data transmissions are protected using TLS 1.3 encryption.

Multi-Factor Authentication

MFA is mandatory for all user accounts accessing the platform.

Role-Based Access

Access controls based on the principle of least privilege.

Intrusion Detection

Continuous security monitoring and intrusion detection systems.

Automated Backups

Regular automated backups with disaster recovery procedures.

Audit Logging

Comprehensive logging of all access and changes for audit trails.

Penetration Testing

Regular security testing and vulnerability assessments.

UK Data Residency

Your data never leaves the UK. We use AWS infrastructure based in the London region (eu-west-2), ensuring your sensitive financial data remains within UK jurisdiction at all times.

All data stored in UK-based data centres
No international data transfers
Subject to UK GDPR and data protection law
AWS SOC 2 and ISO 27001 certified infrastructure

AWS London (eu-west-2)

All data processing and storage occurs exclusively within UK borders

Our Security Practices

Technical measures are only part of the picture. We've also implemented robust organisational practices.

1

Staff Training

All team members receive regular training on data protection, security awareness, and our internal policies. This ensures everyone understands their responsibilities when handling sensitive data.

2

Information Security Policies

We maintain comprehensive policies covering information security, acceptable use, access management, and incident response. These are reviewed and updated regularly.

3

Data Breach Response

We have documented procedures for identifying, containing, and reporting data breaches. In the event of a breach, we'll notify affected parties within the statutory timeframes.

4

Supplier Due Diligence

We carefully assess the security practices of any third-party suppliers before engaging them, and maintain Data Processing Agreements where required.

Insurance Coverage

We carry appropriate insurance to provide additional protection and peace of mind.

Professional Indemnity Insurance

We carry professional indemnity insurance to protect against claims arising from professional advice, errors, or omissions in our service.

Cyber Liability Insurance

We carry cyber liability insurance covering data breaches, cyber attacks, and related costs including notification and remediation expenses.

Have Questions About Our Security?

We're happy to discuss our security practices in more detail or answer any questions about how we protect your data.

Get in Touch