Security & compliance

Evidence written as the work happens — not assembled afterwards.

UK buyers and the FCA are both exacting, and the ICO has become markedly less patient. Consent is checked against one ledger before anything sends, and every consequential action leaves a record you can produce on request.

The rules you actually live under

Built for UK retail, not translated into it.

The maximum PECR penalty rose from £500,000 to £17.5m under the Data Use and Access Act 2025, and ICO guidance is explicit that consent records must be clear, unambiguous and retrievable. From one place — not from twenty suppliers who each keep their own version and disagree.

UK GDPR + DPA 2018

A lawful basis, purpose limitation and full data-subject rights on every record — with an immutable trail showing what was done and when.

PECR + TPS

Marketing consent checked against one ledger before anything sends, and screening against the Telephone Preference Service before any proactive call.

FCA · Consumer Duty

Fair-value and good-outcome evidence on regulated motor finance, with disclosure logged per deal — the lesson every group took from the redress scheme.

ICO accountability

Records of processing, DPIAs and consent records that are actually retrievable — from one place, rather than from twenty suppliers who each keep their own version.

For your IT director

8 questions, answered straight.

Where does our data live?

On managed infrastructure in your group's own dedicated node — a separate database and network boundary, not a shared table with everyone else's customers in it. Row-level security and tenant scoping apply on every request.

Where is it hosted — and does it leave the UK?

Data residency is set per engagement and written into the DPA, so it is a contractual commitment rather than a promise on a website. If your group requires UK or EU residency, that is agreed before anything is connected — not discovered afterwards.

Is it encrypted?

In transit and at rest, with field-level encryption on the most sensitive records. Transport security and headers are verified against the live deployment rather than asserted in a policy document.

Who can see it internally?

Access is role-scoped, and administrative surfaces are guarded at the page rather than merely hidden from a menu. Sensitive records are logged whenever they are viewed — who looked, when, and why.

What is your audit trail?

Every consequential action writes an immutable evidence record as it happens. The trail is a by-product of operating the platform, not a report someone assembles the week before an audit.

Do you train AI on our data?

No. Models are used to reason and to write. Your customer data is not a training corpus and is not shared with other dealers. Where signals travel between nodes — fraud patterns, for instance — they travel as patterns, never as customer records.

What happens if we leave?

You take your data with you. Export on demand, with real tooling rather than a support ticket and a ninety-day wait. That is deliberate: if the door is open, the only thing keeping you is whether the product works.

Are you SOC 2 certified?

No — and we are not going to tell you otherwise. We are engineered to the SOC 2 Trust Services Criteria and pursuing certification. We keep a control matrix marking every control implemented, policy-backed, partial or an open gap, and we will share it with your team with the gaps still showing. That document is the reason to believe everything above it.

Isolation, in practice

Your group's own node is the security answer, not a feature.

A dedicated database and network boundary per group means one group's incident cannot reach another group's data — or another group's uptime.

Bring your security team

We'll bring the gaps too.

Book a security session and we will walk your team through the control matrix — implemented, policy-backed, partial and open — before anything is signed.