Trust & compliance

You are about to give a security company access to everything.

So here is how we are set up, what we hold, and what happens when something goes wrong on our side. Ask for anything on this page that you cannot see and we will send it.

CERTIFIEDISO/IEC 27001:2022Certificate and scope statement available on request.
FILEDPatent applicationsTwo UK IPO applications filed — GB2516576.2, GB2611532.9. Both pending, not yet granted.
REGISTEREDUK GDPRDPA, subprocessor list and DPIA template available on request.

What we hold, and where

We try to hold as little as the job allows. Where a function can run on your side of the boundary, it does — that is why Guardian classifies on-device and why our agent sends findings rather than raw content.

Data residencyUK and EU regions. Chosen at contract, never moved without written notice.
EncryptionTLS 1.3 in transit, AES-256 at rest, customer-managed keys on Complete and Managed.
Staff accessJust-in-time, approved, time-boxed and logged. You can see the log of who accessed your tenant and why.
RetentionFindings and evidence for the contract term plus 30 days. Telemetry 13 months. Deletion on request, confirmed in writing.
SubprocessorsCurrent list available on request, with 30 days' notice before any addition. No model training on your data, by anyone, ever.
If we have an incident

Affected customers are contacted within 24 hours of confirmation, with what we know at that point rather than a polished statement a week later. A written post-incident review follows within ten working days and goes on our research page alongside everything else.

If you leave

Full export of your findings, evidence and logs in open formats, available for 30 days after termination, at no charge. Uninstall is a single command through your device management. We do not hold your compliance history hostage.

Security questionnaire to fill in?

Send it over. We keep completed responses for the common frameworks and turn most around in two working days.

Request documents