TRUST CENTER

    Security & Compliance

    A complete view of how Safeheld protects client data and maintains compliance across every layer of the platform.

    CERTIFICATIONS

    Compliance status

    GDPR

    Compliant

    UK Data Protection Act 2018

    Compliant

    SECURITY

    Infrastructure Controls

    Encryption

    • AES-256 encryption at rest
    • TLS 1.3 encryption in transit
    • End-to-end encryption for sensitive data fields
    • Hardware security modules for key management

    Infrastructure

    • European Union data centres
    • Isolated tenant environments
    • No shared data between clients
    • Automated backups with point-in-time recovery

    Access Controls

    • Role-based access control (RBAC)
    • Multi-factor authentication enforced
    • IP allowlisting available
    • Session management and timeout policies
    • Principle of least privilege

    Monitoring & Testing

    • 24/7 infrastructure monitoring
    • Regular penetration testing by independent firms
    • Vulnerability scanning and patch management
    • Incident response procedures documented and tested

    DATA GOVERNANCE

    How We Handle Data

    Data Minimisation

    We collect only the data necessary to perform verification. No extraneous data retention.

    Data Processing Agreements

    DPAs available for all clients. Sub-processor lists maintained and updated proactively.

    Right to Erasure

    Full support for data subject access requests and right to erasure under GDPR.

    Data Residency

    Client data is hosted in European Union data centres. We do not transfer data outside that jurisdiction without appropriate safeguards and explicit contractual agreement.

    Responsible Disclosure

    Security researchers can report vulnerabilities to our security team. We acknowledge all reports within 48 hours and work collaboratively on responsible resolution.

    The system of record for client funds and reserves