Enterprise-ready by design and default
A note from the team
We are not SOC 2 or ISO 27001 certified today. We would rather earn trust with honest architecture than a badge we do not have. We publish a public trust roadmap of everything we have deliberately parked, so procurement teams can see exactly where we are — and where we plan to get to.
Security
Encryption, authentication, MFA, session policy, audit trail, tenant isolation.
Read morePrivacy
UK GDPR-aligned. ICO-registered controller. Self-serve rights at /data-privacy.
Read moreAI
Approval-first AI. Human commit required for every state change and external message.
Read moreSub-processors
Every third party that touches customer data, kept current.
Read moreManaged Postgres
Row Level Security on every business table, with explicit GRANTs per migration.
EU hosting
Managed Postgres, static hosting and edge functions. Primary region confirmed on request.
Approval-first AI
AI never edits data or communicates externally without an explicit human commit.
Public status
Live health checks at /api-status. Release history at /changelog.
Enterprise Readiness Pack
18 documents. Viewable online, downloadable as PDF, versioned.
Working through procurement?
Ask for a DPA, sub-processor list, penetration test summary (under NDA), or a completed security questionnaire. We turn most requests around in a few working days.
