Legal
Security Policy
Overview
-
We take the protection of customer data extremely seriously. This policy outlines the technical and organisational measures we have implemented to protect customer data against unauthorised access, alteration or disclosure.
-
Unless otherwise specified, our application services operate on Google Cloud Platform.
-
If you become aware of a critical security incident that you believe has not already been brought to our attention, please contact us immediately on +44 20 3868 7559.
Security Team
- Our security team consists of individuals with strong security backgrounds and industry experience in developing highly available, secure and scalable web applications.
Incident Response
-
Our security team follows a formal procedure when responding to security events.
-
In the event of a critical issue, our security team follows an incident response process designed to investigate the issue, contain any exploitation, mitigate the associated risks and remedy the vulnerability.
-
We will notify affected customers of any critical security incident without undue delay and, in any event, within 36 hours of discovering the incident.
-
Security incidents are documented. Following an incident, affected customers will be provided with a post-incident report containing a root cause analysis, details of the incident and any lessons learned.
-
If an incident is sufficiently serious that it cannot be handled by our internal security team alone, we have arrangements in place with external cybersecurity companies that are familiar with our application and able to provide additional assistance. External contractors will not be given access to the personal data we store on behalf of our customers.
Infrastructure
-
We do not directly manage cloud infrastructure or maintain physical servers.
-
Our cloud infrastructure is managed, scaled and maintained by Google Cloud Platform. All cloud infrastructure, including our compute engines, storage buckets and networking rules, is hosted within Google Cloud Platform’s London data centre.
-
Further information about how Google protects the security of its data centres is available at: https://www.google.com/about/datacenters/data-security/
-
Our web application is served through a content delivery network (CDN) and is protected against common attacks, including Distributed Denial of Service (DDoS) attacks.
Data
-
Customer data is stored in multi-tenant data stores. We do not maintain a separate data store for each customer.
-
We implement strict security controls to prevent one customer from accessing another customer’s data, including through the use of security rules. These rules allow us to configure the platform to support a high volume of database transactions while maintaining security and functionality.
-
When deploying new code to production, we test these security rules in a sandbox environment to ensure that they operate as expected.
-
We perform and regularly test data backups to protect against data loss in the event of a failure.
-
Backups are retained for 31 days and deleted at the end of that period.
Data Access
-
Access to data is granted only to individuals who can demonstrate that they are the owner of the data or have the necessary authority to access it.
-
Authority to access an individual’s data is controlled through the relevant workspace permissions.
Data Deletion
-
Individuals have the right to delete their data from our systems where they do not have an active legal agreement with the relevant workspace.
-
Where a deletion request is made on behalf of an individual, an authorised person should process the request directly through the CRM or API.
-
Logs of data deletion events may be accessed by subscribing to the Notification API.
Data Transfer
-
All data stored within our databases is encrypted using the 256-bit Advanced Encryption Standard. The encryption keys are themselves encrypted using a regularly rotated set of master keys.
-
All data is transmitted using TLS 1.2 to ensure secure data transfer between customers and our databases.
-
Certification standards: ISO 27001, ISO 27017 and ISO 27018.
-
Evaluation standards: SOC 1, SOC 2 and SOC 3.
Penetration Testing
-
We make reasonable efforts to engage independent penetration testers to conduct security assessments of our application. Copies of the resulting reports may be made available upon reasonable request.
-
Testing is conducted across the web application and its infrastructure to identify security vulnerabilities that could pose a risk to the application, its data or its users.
Application Monitoring
-
Comprehensive audit logs are maintained through detailed logging and internal integrations with Cloud Access Transparency and Cloud Audit Logs.
-
Performance and availability are monitored through application logs and resource health reports. These measures allow us to track changes over time and notify the relevant teams when necessary.
Customer Responsibilities
-
Customers are responsible for:
-
complying with the terms of their services agreement and all applicable laws;
-
promptly notifying us if any user credentials have been compromised or if they suspect any activity that could adversely affect the security of their account; and
-
refraining from conducting penetration tests or other security assessment activities without our prior express written consent.
Subprocessors
-
We use the following subprocessors:
-
Simunix - identity verification services;
-
Yoti - identity verification services;
-
ClickSend - user communication services;
-
Mailjet - user communication services;
-
Google Cloud Platform - cloud services;
-
Amazon Web Services (AWS) - cloud services; and
-
Microsoft Azure - cloud services.
