
Legal & Compliance
Security & Compliance
Last updated: Sep 24, 2026
Access control
Administrative access requires authenticated accounts with explicit roles stored separately from user data. Public self-registration is disabled.
Data protection
TLS encryption in transit, encryption at rest, row-level security on every database table, and IP anonymisation for analytics.
Change management & audit
Every create, update and delete on offices, country pages and enquiries is written to an immutable audit log with actor and timestamp.
Monitoring
Application errors and security-relevant events are logged centrally and reviewed in the admin console.
Privacy by design
Analytics run only after opt-in consent; consent decisions are recorded. Data subject requests are handled through a dedicated workflow.
Frameworks
Controls are designed in line with GDPR, SOC 2 / SOC 3 Trust Services Criteria and ISO/IEC 27001 Annex A. Formal certification is subject to independent audit.