Security
This page describes how we protect the systems and data we are responsible for. Each statement on it is confirmed by our Chief Technology Officer before it is published.
Last updated
Our controls
- Governance
- [TO CONFIRM: Who is accountable for security, and our information security management (ISO/IEC 27001 status exactly as in D5).]
- People
- [TO CONFIRM: Security training, confidentiality agreements, and removing access when people leave.]
- Infrastructure
- [TO CONFIRM: Cloud providers and regions, and network protection.]
- Encryption
- [TO CONFIRM: Encryption in transit (TLS 1.2 or higher) and at rest.]
- Access control
- [TO CONFIRM: Single sign-on, multi-factor authentication, least privilege and access reviews.]
- Zero trust and hardware attestation
- We verify every request rather than trusting its origin. In Prime Edge AI every device attests itself in hardware, no key ships in the app, and access tokens expire hourly and carry no identity.
- Logging and monitoring
- [TO CONFIRM: What we log, and how we monitor it.]
- Vulnerability management
- [TO CONFIRM: Patching, dependency scanning, and how often we run penetration tests.]
- Incident response
- [TO CONFIRM: How customers are told about an incident, and how quickly.]
- Business continuity and backups
- [TO CONFIRM: How we keep services running and data recoverable.]
- Secure development
- [TO CONFIRM: Code review, testing, and separation of environments.]
- AI-specific security
- [TO CONFIRM: Defences against prompt injection, controls on what AI components can reach, and output checks.]
Reporting and related pages
If you think you have found a security issue in anything we run, please tell us through our vulnerability disclosure policy.