The fundamentals

UK hosted, encrypted everywhere, isolated by design.

UK data residency

All customer data, documents and backups are hosted in AWS data centres in London (eu-west-2). Your ISMS never leaves the UK for storage.

AWS facilities hold ISO 27001, SOC 2 and equivalent certifications.

Encryption in transit and at rest

TLS 1.2 or higher for every connection. AES-256 encryption at rest across databases, document storage and backups. No exceptions, no legacy endpoints.

Isolated tenancy

Every customer has an isolated database schema and isolated, tenant-namespaced document storage. Your data is structurally separated from other customers', not just filtered by a query.

Access control

Authentication is handled by Auth0, with single sign-on and multi-factor authentication. Inside your workspace, your administrators control who sees and edits what.

Our own administrative access to production is restricted, MFA-protected and logged.

Backups that restore

Automated backups with point-in-time recovery for every customer database. Restores are tested on a schedule, because a backup you have never restored is a hope, not a control.

Documents handled properly

Documents live in isolated object storage, never in the database, and are served only through short-lived signed URLs. Storage is never publicly accessible.

We use our own product

ISOvault runs its ISMS on ISOvault.

Our risk register, asset register, supplier reviews and policies are managed in the same product you are evaluating, and we are working toward Cyber Essentials certification for ISOvault itself. When we make a security decision, we feel it as a customer first. Our supply chain is deliberately short, and every provider in it is published in our sub-processor register.