Security & Compliance

Trust Centre

We are committed to transparency and maintaining the highest standards of data integrity.

Security & Compliance Certifcations

RedactXpert has the following security and compliance certifications: ISO 27001, ISO 9001, Cyber Essentials, Cyber Essentials Plus.

The solution is hosted on Microsoft Azure which holds several security and compliance certifications, including ISO 27017, ISO 27018 and UK Police-Assured Secure Facilities (PASF).

RedactXpert is hosted in the UK, where all data is stored and processed.

ISO 27001

ISO 9001

The solution is hosted on Microsoft Azure which holds several security and compliance certifications, including:

Security Controls

Category
Control Title
Description
Access Controls
Application level RBAC
Users within the RedactXpert application are assigned roles that define their access to features, ensuring least-privilege access to tenant data and operations.
Access Controls
Tenant level data access controls
Tenant boundaries within the application ensure users can only interact with resources belonging to their own organisation. Tenant context is validated on all operations.
Access Controls
Just-in-time platform access
Elevated privileges require JIT activation via PIM to minimise standing administrative permissions
Access Controls
Approval process for privileged platform roles
Requests for privileged roles must be approved by designated approvers before access is granted, ensuring strict segregation of duties.
Access Controls
Use of password-less credentials
Interactions between platform components are performed with password-less managed service accounts.
AI Security
Customer data is never used for AI model training
Customer data uploaded to the solution is never used to train AI models.
AI Security
Opt-out of AI logging
Sensitive data is not stored on AI services, other than for the purposes of processing. In particular, configuration options are used to explicitly opt-out of logging data processed by AI when detecting personally identifiable information (PII).
Application Security
Web-application firewall
WAF implemented to inspect and block malicious traffic, using OWASP 3.2 and Bot Protection.
Application Security
Code review processes
All code changes must be reviewed and approved via pull requests, preventing unauthorised code changes.
Application Security
SAST tooling
Static analysis security testing (SAST) is run during CI to detect insecure coding practices and vulnerabilities before code is deployed.
Application Security
Secure credential management (use of key vault)
All secrets (keys, certificates, connection strings) are stored in Azure Key Vault and never committed to code or stored on developer machines. Access to secrets is tightly controlled and audited.
Application Security
CI/CD Pipelines
Automated pipelines are used for code build, testing, validation, and deployment to ensure consistent, repeatable, and secure development processes.
Application Security
Production deployment approvals
All deployments to the production environment must have an approval from specified team members to protect the integrity, security, and availability of the production environment.
Business Continuity & Disaster Recovery
Immutable backups
Immutable, isolated backups protect against ransomware by ensuring data cannot be modified, encrypted, or deleted by attackers, even with elevated privileges.
Business Continuity & Disaster Recovery
Business Continuity & Disaster Recovery Plan
RedactXpert has a documented Business Continuity & Disaster Recovery Plan that outlines mechanisms in place to protect against disruption to the service, and how to respond in the event of many disaster scenarios.
Compliance
ISO 27001 Compliance
RedactXpert is certified for ISO 27001 via Simpson Associates.
Compliance
Cyber Essentials Plus Compliance
RedactXpert is certified for Cyber Essentials Plus via Simpson Associates.
Compliance
UK Police-Assured Secure Facilities (PASF)
RedactXpert is built on Microsoft Azure. The NPIRMT completed a comprehensive security assessment of the physical infrastructure of Microsoft Azure datacenters in the UK, and concluded that they're in compliance with NPIRMT requirements. The NPIRMT audits one Azure datacenter each year, annually cycling through the four Microsoft datacenters in the UK.

https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-uk-pasf
Data Security
Tenant data storage isolation
Tenant data for organisations is isolated in unique storage accounts and databases. Enterprise tenants are further isolated with individual database servers.
Data Security
Tenant network isolation
Tenant data for organisations is isolated in per tenant virtual networks
Data Security
Access restrictions to customer data
RedactXpert staff cannot access customer-uploaded data (documents or PII). Access is blocked by design, policy, and technical enforcement.
Encryption
TLS communication
All services communicate using TLS encryption in transit.
Encryption
Sensitive column encryption
Database columns containing PII or other sensitive information are encrypted at the database level and protected with per-tenant RedactXpert managed key pairs.
Encryption
Storage account file encryption
Storage containing uploaded documents uses encryption-at-rest.
Encryption
Secret encryption
Secret configuration values are encrypted at rest and protected from unauthorised access.
Infrastructure Security
Azure cloud configuration review
A review of Azure cloud configuration is performed annually to identify any security vulnerabilities or areas for increased security in the platform.
Infrastructure Security
Private network restrictions
All resources in the solution (except access to the application itself) are protected by a private virtual network. Public access is disabled to resources and only communication internally between resources on the network is allowed.
Infrastructure Security
Environment segregation
Development, test, and production environments are kept separate via distinct subscriptions, credentials, networks, and deployment pipelines.
Infrastructure Security
DDoS Protection
DDoS protection is used to detect and mitigate malicious high-volume traffic to prevent service disruption and ensure system availability.
Operational Security
Staff Vetting
All staff with access to the RedactXpert application and platform are vetted in line with the customer (and internal) vetting requirements.
Operational Security
Access Reviews
Periodic verification of user permissions to ensure access remains appropriate to job roles and to promptly remove excessive or outdated privileges.
Operational Security
Joiners Movers Leavers Process
Formal onboarding, role-change, and off-boarding procedures to provision access securely, adjust permissions as responsibilities change, and revoke access immediately when individuals leave the organisation.
Vulnerability Management
Penetration testing
Annual penetration testing of the application is performed by a 3rd party to identify security vulnerabilities.
Vulnerability Management
Automated dependency scanning
Dependencies are scanned for security vulnerabilities and licence issues automatically as part of CI/CD and via scheduled scans.
Vulnerability Management
SIEM Monitoring
Centralised logging and real-time analysis of security events to detect, and respond to suspicious or unauthorised activity across systems and user accounts.
Access Controls [5]
AI Security [2]
Application Security [6]
Business Continuity & Disaster Recovery [2]
Compliance [3]
Data Security [3]
Encryption [4]
Infrastructure Security [4]
Operational Security [3]
Vulnerability Management [3]
Supplier
Location
Data Access Level
Microsoft
Global company however all servers in use are located within the UK
Data is processed within Microsoft Azure as the cloud hosting provider; however, everything is encrypted at rest and in transit. Microsoft Products and Services Data Protection Addendum (DPA) can be found here. Services are provisioned, and data is stored in UK data centres only. Microsoft is a global organisation with global sub-processors for support and service operations; however, they will not access customer data without authorisation. Details here.

Microsoft also act as Identity Provider.
Cloud Service Provider
Global organization withheadquarters in Switzerland and our main point of contact being their UK office
No access to data within the RedactXpert platform.
Library Provider
Global organisation with head office in the USA.
Data processing is done via an SDK which is installed locally within the application, and so currently runs in the UK only. No data is sent to any external platforms.
DNS Provider
Global organisation with head office in the USA.
DNS provider only. No access to data within the RedactXpert platform.
ITSM Tool Provider
Company is based in Australia; however, the UK region is used for our tenant.
ITSM tool for support and service desk operations. Access to user contact details for the purposes of providing support services, as well as any information uploaded in tickets. No access to data within the RedactXpert platform (unless explicitly included in a support ticket).

Policies/Documents

  • Business Continuity & Disaster Recovery (BCDR) Plan
  • Data Protection Policy
  • Support Access Policy
  • Security Management Plan
  • Responsible Disclosure Policy
  • Information Security Policy
  • Privacy Policy
  • Cookie Policy
  • Terms & Conditions
  • Data Processing Agreement
  • Data Retention Policy
  • Support Policy
  • Change & Release Management Policy
  • Accessibility Statement
  • Responsible AI Statement
Document
Status
Public/Gated
Business Continuity & Disaster Recovery (BCDR) Plan
In Review
Gated
Data Protection Policy
In Review
Gated
Support Access Policy
In Review
Gated
Security Management Plan
In Review
Gated
Responsible Disclosure Policy
Draft
Gated
Information Security Policy
In Review
Gated
Privacy Policy
In Review
Public
Cookie Policy
Draft
Public
Terms & Conditions
In Review
Public
Data Processing Agreement
In Review
Public
Data Retention Policy
Draft
Public
Support Policy
In Review
Public
Change & Release Management Policy
In Review
Gated
Accessibility Statement
Draft
Public
Responsible AI Statement
In Review
Public

Supplier Register

Supplier
Location
Data Access Level
Microsoft
Global company however all servers in use are located within the UK
Data is processed within Microsoft Azure as the cloud hosting provider; however, everything is encrypted at rest and in transit. Microsoft Products and Services Data Protection Addendum (DPA) can be found here: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Services are provisioned, and data is stored in UK data centres only. Microsoft is a global organisation with global sub-processors for support and service operations; however, they will not access customer data without authorisation. Details here:
https://azure.microsoft.com/en-us/explore/global-infrastructure/data-residency#more-information

Microsoft also act as Identity Provider
Cloud Service Provider
Global organization with headquarters in Switzerland and our main point of contact being their UK office
No access to data within the RedactXpert platform.
Library Provider
Global organisation with head office in the USA
Data processing is done via an SDK which is installed locally within the application, and so currently runs in the UK only. No data is sent to any external platforms.
DNS Provider
Global organisation with head office in the USA
DNS provider only. No access to data within the RedactXpert platform.
ITSM Tool Provider
Company is based in Australia; however, the UK region is used for our tenant
ITSM tool for support and service desk operations. Access to user contact details for the purposes of providing support services, as well as any information uploaded in tickets. No access to data within the RedactXpert platform (unless explicitly included in a support ticket).

Ready to Transform Your Security?

Get your 14-day free trial today.