We practise what we preach.
As an AI security company, our own security posture is non-negotiable. Here's how we protect your data, our platform, and your trust.
Certifications
Independently verified.
Our certifications are current, audited, and available for review.
SOC 2 Type II
Annual audit by an accredited third party
CertifiedISO 27001
Information security management system
CertifiedCyber Essentials Plus
UK government-backed cybersecurity certification
CertifiedGDPR Compliant
Full compliance with EU data protection regulation
CompliantInsured by Lloyd's of London for technology professional liability.
Security
How we protect your data.
Enterprise-grade security controls across infrastructure, application, and operations.
Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Customer data is isolated with tenant-level encryption keys.
Penetration Testing
Annual penetration tests conducted by accredited third-party firms. Summary reports available under NDA for enterprise customers.
Infrastructure
Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certified providers. Multi-region availability with UK/EU primary.
Vulnerability Management
Continuous vulnerability scanning, dependency monitoring, and patch management. Critical vulnerabilities addressed within 24 hours.
Business Continuity
Documented BCP and disaster recovery procedures. Regular testing and tabletop exercises. RPO and RTO targets defined per service tier.
Incident Response
Documented incident response plan with defined escalation paths. Customers notified within contractual SLA of any security incident.
Privacy
Privacy-first by design.
We built CultureAI with privacy as a first principle — not an afterthought.
No keylogging
We never capture keystrokes. Our sensor observes AI tool interactions, not general browsing or typing.
No screen scraping
We don't capture screenshots or screen recordings. Data classification happens on structured interaction data only.
Pre-trained models
Our classification models are pre-trained. We do not train on customer data. Your data never improves our models.
Data residency
UK/EU primary data residency. Customer data stays in the region you choose. No transatlantic transfers without explicit consent.
Minimal collection
We collect only what's necessary for the security and governance function. Data retention policies are configurable per customer.
Transparent processing
Full transparency about what we collect, why, and how long we keep it. Data processing agreements available for all customers.
Sub-processors
Who processes your data.
A complete list of third-party sub-processors and their purposes.
Provider
Purpose
Location
AWS (eu-west-2)
Primary cloud infrastructure and data storage
London, UK
Cloudflare
CDN and DDoS protection
Global (edge nodes)
SendGrid
Transactional email delivery
EU
Stripe
Payment processing
EU
Legal Documents
Download our standard agreements or contact us for bespoke terms.
Questions about our security posture?
We're happy to walk through our security practices, share pen test summaries under NDA, or discuss specific compliance requirements.