Skip to main content

Trust Center.

Who we trust with your data, how we handle it, and our honest compliance roadmap. Dated targets, not fuzzy promises — if a target slips, the next revision of this page will explain why.

Subprocessors.

We rely on a small set of named vendors. Every vendor touching your data is listed below, with what they do and where the data sits. Future vendors are flagged with the milestone that brings them online.

VendorServiceData categoryLocationStatus
ResendOutbound email deliveryContact form submissions, auto-repliesUK / EU (via AWS SES upstream)Active
HostingerVPS + storageAll platform data (database, uploads, logs)UK (London / Manchester)Active
AnthropicAI engineTicket content, KB articlesUSPlanned (M5)
StripeBillingPayment metadataUS / EUPlanned (M7)
TwilioVoice / SMS channelCall recordings, SMS contentUS / UKPlanned (M4)

How we handle your data.

Data location

UK VPS hosted at Hostinger (London and Manchester datacentres). No cross-region replication in M1. A full disaster-recovery plan arrives with the M8 launch hardening phase.

Transit encryption

TLS 1.3 from client to nginx at the edge. nginx talks to the app over loopback only — no internet-reachable port other than 443.

At-rest encryption

Full-disk encryption on the VPS. Database files and uploaded attachments both sit on the encrypted volume.

Deletion policy

Thirty-day soft-delete, then purge. The policy becomes enforceable from Phase 6 (when the database ships) and applies to accounts, tickets, and uploaded files alike.

Our compliance roadmap.

  1. UK-GDPR + EU-GDPR

    Aligned today.

  2. SOC 2 Type I

    Targeted for M8 launch.

  3. ISO 27001

    Post-launch roadmap.

  4. SAML SSO + SCIM

    Post-launch — M8+ for the enterprise tier.

We publish dated targets instead of fuzzy roadmaps. If a target slips, the next revision of this page will explain why.