Encryption
In transit (TLS) and at rest (AES-256).
Inherited controls
SOC 2 Type II and ISO 27001 on the infrastructure; PCI DSS Level 1 on payments — card data never touches our servers.
Secure access
Sign-in by single-use link —no passwords to steal or reuse—, encrypted sessions, and strong customer authentication (SCA).
Your data does not train models
The AI provider commits by contract not to use the data for training.
Minimisation and deletion
Atomic cascading deletion and automated retention policies that delete without being asked.
Zero reportable incidents
No reportable security incidents (Art. 33 GDPR) since the system went live; incident response within ≤72 h.
Responsible disclosure
A responsible disclosure programme with Safe Harbor and automated vulnerability management in continuous integration.