Security & Trust

We sell compliance software.
We had better be compliant.

Your compliance programme is only as trustworthy as the platform holding it. These are the controls protecting your data, how the application defends the common attack classes, and how to reach us if you find something.

AES-256
Encryption at rest
TLS 1.2+
Enforced in transit
SAML
2.0 SSO, any IdP
99.9%
Uptime target, not an SLA

Controls inside the platform

Identity & access

Role-based access control with permissions defined centrally, SAML 2.0 single sign-on against any conforming identity provider — with guided setup for Okta, Azure AD, Google Workspace and OneLogin — and TOTP two-factor authentication.

Tenant separation

Your data is logically separated from every other customer's and access is authorised on the server for each request. Records outside your organisation are never returned — not returned and hidden, not filtered in the browser.

Field-level audit logging

Changes recorded with actor, timestamp and before/after values. The trail is what makes an audit defensible rather than anecdotal.

Encryption

TLS for everything in transit, AES-256 at rest. No plaintext compliance data and no exceptions made for convenience.

Connector credentials

The keys you give us to read your cloud, identity and endpoint platforms are the highest-value secrets we hold, so they get their own scheme: a separate encryption key per organisation, itself wrapped twice — once to a hardware-held key and once to an offline recovery key. Encryption fails closed rather than degrading, and the whole path is re-verified hourly.

Revocation that takes effect now

Deactivating someone applies immediately: privileged operations re-check the account against its live status rather than trusting a token until it expires. Repeated failed sign-ins escalate from a timed lockout to a standing one.

Availability

The platform runs on a dedicated physical server — single-tenant hardware, not a virtual slice of a shared host, and no other customer of the hosting provider runs on it. A Cloudflare edge network with DDoS protection sits in front. Encrypted backups are taken regularly and restore-tested, not merely configured — current operating practice rather than a contracted recovery objective.

AI data handling

Generation draws only on your own organisation's records, under the same access rules as everything else. Output is always a draft for human review — nothing is filed or signed off automatically, and your data is not used to train models.

How the platform defends the common attack classes

These are properties of how the application is built, not the result of a point-in-time test. Implementation detail is available to prospective customers under NDA.

Injection & scripting

Untrusted input never reaches a query or a rendered page as executable content, and a strict Content Security Policy is enforced in the browser as a second line.

Authentication & access

Every endpoint requires authentication and re-checks what the caller is entitled to reach. Nothing is trusted because the interface chose not to display it.

Data exposure

Credentials and secrets stay out of API responses and application logs, and error pages do not leak internal detail to the caller.

Components & transport

Third-party dependencies are pinned and scanned against published vulnerability advisories, and HTTPS is enforced end to end.

Responsible disclosure

Found something? Tell us.

If you believe you have found a security vulnerability in GRCxAI, email us with enough detail to reproduce it. We will acknowledge, investigate and keep you updated through to resolution.

  • We will not pursue legal action against good-faith research that respects user privacy and avoids service degradation.
  • Do not access or modify data belonging to others while testing.
  • Report to [email protected] — we read every one.
Report a vulnerability

Security questions before you buy?
Ask the hard ones.

We will walk your team through the architecture, the controls and the audit trail.