Trust centre
This page consolidates the documentation your procurement, IT security or legal team typically asks for during vendor assessment. Most items are downloadable directly; the SIG-Lite and DPA are available on request to security@instantcheck.co.uk.
At a glance
| Hosting region | United Kingdom (London, AWS via Fly.io) |
|---|---|
| Data residency | All Worker Data stays in the UK at rest and in transit |
| Encryption at rest | AES-256 (volume-level) |
| Encryption in transit | TLS 1.2+ for all customer traffic; HSTS preload |
| Tenant isolation | Logical, per-company namespace; cross-tenant access blocked at auth layer |
| Backup frequency | Daily encrypted snapshots, 30-day retention |
| Disaster recovery RTO | 4 hours |
| Disaster recovery RPO | 24 hours |
| Penetration testing | Annual third-party penetration test; report available under NDA |
| ICO registration | ZB743659 |
| Cyber Essentials | In progress (2026) |
| ISO 27001 | On the roadmap (2027) |
Downloadable documents
- Security overview — controls, breach response, responsible disclosure
- Privacy policy — Article 13 / 14 notice content
- Data Processing Addendum — pre-signed processor terms ready to attach to your contract
- Terms of Service — including SLA and service credit table
- Accessibility statement — WCAG 2.2 AA conformance
- Cookie policy
- Service status page
On request (under NDA)
- SIG-Lite (Standardized Information Gathering) questionnaire response
- Annual penetration test report summary
- Vendor risk assessment template (we'll fill yours in too)
- Business continuity and disaster recovery plan
- Subprocessor list with named entities, locations and assurance status
- DPIA covering biometric (facial photograph) processing
Sub-processors
Listed in full in the Data Processing Addendum, section 5. Current core list:
- Fly.io — application and database hosting, UK (London) region
- Microsoft 365 — email and document collaboration, EU
- Formspree — demo request form receipt, US (EU-US Data Privacy Framework)
- Webshare — UK residential proxy for SIA register checks, UK exit nodes only
We give 30 days' notice of any change. Subscribe via contact to receive sub-processor change notifications.
Incident response
Confirmed personal data breaches affecting your tenant are notified to your registered contact within 24 hours of detection — well inside the 72-hour Article 33 window. Full incident detail and remediation steps follow within 72 hours. You remain the controller for any onward notification to data subjects and the ICO.
Status of in-progress incidents is published on our public status page.
Responsible disclosure
Security researchers: please email security@instantcheck.co.uk with reproduction steps and proof of concept. We acknowledge within 2 working days, fix in good faith, and credit researchers in the changelog where requested.
Procurement portal access
If your assessor uses Drata, Vanta, Conveyor, OneTrust, Whistic or similar, email security@instantcheck.co.uk with the platform name and we'll share our trust profile directly so you don't have to email a spreadsheet around.
Contact
- Security: security@instantcheck.co.uk
- Privacy / Data protection (DPO Mark Raybone): privacy@instantcheck.co.uk
- Procurement: support@instantcheck.co.uk