CultureAI
Trust Centre

We practise what we preach.

As an AI security company, our own security posture is non-negotiable. Here's how we protect your data, our platform, and your trust.

Certifications

Independently verified.

Our certifications are current, audited, and available for review.

SOC 2 Type II

Annual audit by an accredited third party

Certified

ISO 27001

Information security management system

Certified

Cyber Essentials Plus

UK government-backed cybersecurity certification

Certified

GDPR Compliant

Full compliance with EU data protection regulation

Compliant

Insured by Lloyd's of London for technology professional liability.

Security

How we protect your data.

Enterprise-grade security controls across infrastructure, application, and operations.

Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Customer data is isolated with tenant-level encryption keys.

Penetration Testing

Annual penetration tests conducted by accredited third-party firms. Summary reports available under NDA for enterprise customers.

Infrastructure

Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certified providers. Multi-region availability with UK/EU primary.

Vulnerability Management

Continuous vulnerability scanning, dependency monitoring, and patch management. Critical vulnerabilities addressed within 24 hours.

Business Continuity

Documented BCP and disaster recovery procedures. Regular testing and tabletop exercises. RPO and RTO targets defined per service tier.

Incident Response

Documented incident response plan with defined escalation paths. Customers notified within contractual SLA of any security incident.

Privacy

Privacy-first by design.

We built CultureAI with privacy as a first principle — not an afterthought.

No keylogging

We never capture keystrokes. Our sensor observes AI tool interactions, not general browsing or typing.

No screen scraping

We don't capture screenshots or screen recordings. Data classification happens on structured interaction data only.

Pre-trained models

Our classification models are pre-trained. We do not train on customer data. Your data never improves our models.

Data residency

UK/EU primary data residency. Customer data stays in the region you choose. No transatlantic transfers without explicit consent.

Minimal collection

We collect only what's necessary for the security and governance function. Data retention policies are configurable per customer.

Transparent processing

Full transparency about what we collect, why, and how long we keep it. Data processing agreements available for all customers.

Sub-processors

Who processes your data.

A complete list of third-party sub-processors and their purposes.

Provider

Purpose

Location

AWS (eu-west-2)

Primary cloud infrastructure and data storage

London, UK

Cloudflare

CDN and DDoS protection

Global (edge nodes)

SendGrid

Transactional email delivery

EU

Stripe

Payment processing

EU

Legal Documents

Download our standard agreements or contact us for bespoke terms.

Questions about our security posture?

We're happy to walk through our security practices, share pen test summaries under NDA, or discuss specific compliance requirements.