Security and data
Your data stays in your tenancy.
The records a request touches are among the most sensitive you hold. Health, vulnerability, safeguarding, disputes, children. The system is built so those records do not leave your control to be processed.
Where it runs
In your own Microsoft Azure environment, behind a private endpoint, in a UK region. You hold the subscription. You hold the keys. We deploy into it and support it.
What leaves and what does not
Tenant and staff records, documents, messages and the redaction decisions made on them stay inside your tenancy. The only data that leaves is operational metadata: counts, hashes, version and licence checks, error reports with no content in them. We will walk your information security lead through exactly what crosses the boundary and why.
Who sees what
Officers see the records a case needs and nothing else. Reviewers see what officers decided. The DPO sees everything on the case and signs off release. Every view, decision and release is logged with a name and a time. The log cannot be edited.
Assurance
Cyber Essentials Plus. UK GDPR data processing agreement on our standard terms or yours. Penetration test reports available under NDA. Data protection impact assessment template provided for your own DPIA.
Retention
Case records are retained for the period you set, aligned to your retention schedule and to the limitation periods that apply to disputes. Deletion is logged.