UTC Overseas

Legal & Compliance

Security & Compliance

Last updated: Sep 24, 2026

Access control

Administrative access requires authenticated accounts with explicit roles stored separately from user data. Public self-registration is disabled.

Data protection

TLS encryption in transit, encryption at rest, row-level security on every database table, and IP anonymisation for analytics.

Change management & audit

Every create, update and delete on offices, country pages and enquiries is written to an immutable audit log with actor and timestamp.

Monitoring

Application errors and security-relevant events are logged centrally and reviewed in the admin console.

Privacy by design

Analytics run only after opt-in consent; consent decisions are recorded. Data subject requests are handled through a dedicated workflow.

Frameworks

Controls are designed in line with GDPR, SOC 2 / SOC 3 Trust Services Criteria and ISO/IEC 27001 Annex A. Formal certification is subject to independent audit.

--