TRUST CENTER
Security & Compliance
A complete view of how Safeheld protects client data and maintains compliance across every layer of the platform.
CERTIFICATIONS
Compliance status
GDPR
Compliant
UK Data Protection Act 2018
Compliant
SECURITY
Infrastructure Controls
Encryption
- ●AES-256 encryption at rest
- ●TLS 1.3 encryption in transit
- ●End-to-end encryption for sensitive data fields
- ●Hardware security modules for key management
Infrastructure
- ●European Union data centres
- ●Isolated tenant environments
- ●No shared data between clients
- ●Automated backups with point-in-time recovery
Access Controls
- ●Role-based access control (RBAC)
- ●Multi-factor authentication enforced
- ●IP allowlisting available
- ●Session management and timeout policies
- ●Principle of least privilege
Monitoring & Testing
- ●24/7 infrastructure monitoring
- ●Regular penetration testing by independent firms
- ●Vulnerability scanning and patch management
- ●Incident response procedures documented and tested
DATA GOVERNANCE
How We Handle Data
Data Minimisation
We collect only the data necessary to perform verification. No extraneous data retention.
Data Processing Agreements
DPAs available for all clients. Sub-processor lists maintained and updated proactively.
Right to Erasure
Full support for data subject access requests and right to erasure under GDPR.
Data Residency
Client data is hosted in European Union data centres. We do not transfer data outside that jurisdiction without appropriate safeguards and explicit contractual agreement.
Responsible Disclosure
Security researchers can report vulnerabilities to our security team. We acknowledge all reports within 48 hours and work collaboratively on responsible resolution.