Security & Compliance
Your building safety data is some of the most sensitive information in construction. We take that seriously.
How We Protect Your Data
UK Data Centres
Primary database and file storage in Supabase London region
AES-256 Encryption
Industry-standard encryption for data at rest
TLS 1.2+ in Transit
Encrypted connections for all data in transit
GDPR-Aligned
Designed to support UK GDPR obligations (ICO ZC132889)
Dependency Scanning
Automated dependency and known-vulnerability alerts on application code — not a substitute for penetration testing
Immutable Audit Logs
Comprehensive audit trail of material platform actions
Role-Based Access
Granular permissions for every user
Two-Factor Auth
2FA available for all accounts
SSO/SAML
Enterprise single sign-on support
Service Availability
Availability commitments defined in enterprise agreements
Daily Backups
30-day retention with point-in-time recovery
Certifications & Compliance
In place today
ICO Registration
ZC132889
UK GDPR
Aligned operations
Certification roadmap
We are preparing Cyber Essentials (basic) for IASME submission and building an ISMS foundation toward ISO 27001. None of the items below are certified today — ask security@threadsovereign.co.uk for current status before procurement sign-off.
Cyber Essentials (basic)
Internal readiness pack prepared for IASME self-assessment submission — not yet certified. Do not treat as Cyber Essentials certified until a certificate is issued.
Cyber Essentials Plus
Planned after Cyber Essentials (basic). Certification has not commenced.
ISO 27001
ISMS foundation documentation in progress. Formal certification audit has not commenced.
SOC 2 Type II
Planned for enterprise buyers. Certification has not commenced.
Assurance programme
Threadsovereign publishes policies and technical controls in place today. The items below are part of our go-live assurance programme and are not yet complete — ask security@threadsovereign.co.uk for current status before procurement sign-off.
Independent penetration test
Not yet completed. OWASP Top 10 minimum scope with an external tester is planned.
Data Protection Impact Assessment (DPIA)
Not yet completed. Required for resident and PEEP special-category data processing. An internal draft exists; DPO/counsel sign-off is outstanding.
Legal review — Terms & DPA
Not yet completed. External counsel review for BSA-regulated building contexts is required.
Formal security review
Not yet scheduled. Covers environment variables, secrets handling, and auth configuration.
UK Data Residency
Customer building safety records are stored in UK data centres via Supabase (London region). The production application is hosted on Vercel with compute in UK/EU regions. Some supporting services — such as email, SMS, payments, and e-signatures — process limited personal data in the US or EU under standard contractual clauses. See our sub-processor list.
- Primary database: Supabase (London, UK)
- Encryption at rest and in transit
- Daily backups with 30-day point-in-time recovery
- Segregated staging and production environments
UK Data Centres
Supabase — London region
Security Questions?
Our security team can discuss your requirements and provide available security documentation. For assurance programme status, contact security@threadsovereign.co.uk.