Skip to main content

Update: Golden thread, gateways, safety case & KBI on every plan — User manual

Security for Regulated Building Data

Security & Compliance

Your building safety data is some of the most sensitive information in construction. We take that seriously.

How We Protect Your Data

UK Data Centres

Primary database and file storage in Supabase London region

AES-256 Encryption

Industry-standard encryption for data at rest

TLS 1.2+ in Transit

Encrypted connections for all data in transit

GDPR-Aligned

Designed to support UK GDPR obligations (ICO ZC132889)

Dependency Scanning

Automated dependency and known-vulnerability alerts on application code — not a substitute for penetration testing

Immutable Audit Logs

Comprehensive audit trail of material platform actions

Role-Based Access

Granular permissions for every user

Two-Factor Auth

2FA available for all accounts

SSO/SAML

Enterprise single sign-on support

Service Availability

Availability commitments defined in enterprise agreements

Daily Backups

30-day retention with point-in-time recovery

Certifications & Compliance

In place today

ICO Registration

ZC132889

UK GDPR

Aligned operations

Certification roadmap

We are preparing Cyber Essentials (basic) for IASME submission and building an ISMS foundation toward ISO 27001. None of the items below are certified today — ask security@threadsovereign.co.uk for current status before procurement sign-off.

Cyber Essentials (basic)

Internal readiness pack prepared for IASME self-assessment submission — not yet certified. Do not treat as Cyber Essentials certified until a certificate is issued.

Cyber Essentials Plus

Planned after Cyber Essentials (basic). Certification has not commenced.

ISO 27001

ISMS foundation documentation in progress. Formal certification audit has not commenced.

SOC 2 Type II

Planned for enterprise buyers. Certification has not commenced.

Assurance programme

Threadsovereign publishes policies and technical controls in place today. The items below are part of our go-live assurance programme and are not yet complete — ask security@threadsovereign.co.uk for current status before procurement sign-off.

Independent penetration test

Not yet completed. OWASP Top 10 minimum scope with an external tester is planned.

Data Protection Impact Assessment (DPIA)

Not yet completed. Required for resident and PEEP special-category data processing. An internal draft exists; DPO/counsel sign-off is outstanding.

Legal review — Terms & DPA

Not yet completed. External counsel review for BSA-regulated building contexts is required.

Formal security review

Not yet scheduled. Covers environment variables, secrets handling, and auth configuration.

UK Data Residency

Customer building safety records are stored in UK data centres via Supabase (London region). The production application is hosted on Vercel with compute in UK/EU regions. Some supporting services — such as email, SMS, payments, and e-signatures — process limited personal data in the US or EU under standard contractual clauses. See our sub-processor list.

  • Primary database: Supabase (London, UK)
  • Encryption at rest and in transit
  • Daily backups with 30-day point-in-time recovery
  • Segregated staging and production environments

UK Data Centres

Supabase — London region

Security Questions?

Our security team can discuss your requirements and provide available security documentation. For assurance programme status, contact security@threadsovereign.co.uk.