Security that doesn't
wait to be asked

Every night, we scan our code, dependencies and cloud for new threats. Critical fixes are raised the same night.

Every night

Automated threat sweep

Same night

Critical advisories triaged and fixed

ISO/IEC 27001 certified

Certified security management

Independent pen tested

Web, API and cloud tested annually

Found and fixed
before you asked

  1. Reads the latest threat intelligence.

    Checks vendor alerts, vulnerability databases and CISA’s list of actively exploited flaws.

  2. Matches them to what we actually run.

    Checks advisories against exact versions in our code, containers and customer cloud images.

  3. Reviews recent code changes.

    Looks for access control gaps, injection and unsafe network calls before release.

  4. Cross-checks our scanners and controls.

    Combines code, cloud and compliance findings so nothing goes unowned.

  5. Opens a fix, then checks it landed.

    Logs evidence, severity, deadlines and draft fixes; verifies rollout everywhere next night.

The complete workspace for modern Loss Control.

Technical controls

Identity and access

  • Project-scoped role-based access
  • Multi factor authentication
  • Account lockout after failed logins
  • Org-wide password & login policy
  • Login, access & admin audit logs

Application

  • Enforced CSP & security headers
  • XSS, SSRF & injection protection
  • No-root privileges
  • Dependency patches within SLAs
  • Hardened CI, pinned dependencies

Infrastructure

  • Per-customer cloud/on-prem hosting
  • Reviewed infrastructure as code
  • Destructive change approval
  • Unique signing keys per deployment
  • Anti malware on every host

Data

  • TLS/HSTS & at-rest encryption
  • Never used to train models
  • Regional hosting; EU routing rollout
  • Configurable retention and deletion
  • Data isolated per deployment

AI you can put in
front of a security team

AI features are held to the same bar as the rest of the platform, and tested for the ways AI systems fail

  • Model guardrails

    Model input & output guardrails required by and built with a global insurer’s security team

  • Bounded access

    AI agents can only reach public web hosts, never your internal network

  • Independent testing

    Dedicated AI red team test by an independent firm

  • Responsible AI

    Working towards ISO/IEC 42001 (AI management), with a gap assessment underway and a written Responsible AI policy

  • Model choice

    Choose OpenAI, Anthropic or Google to suit your team’s needs. All are contractually barred from training on your data.

Security you can
verify for yourself

Independent audits, regular testing and clear documentation for your team to review.

Request documentation

Certification & compliance

  • ISO/IEC 27001

    Certified information security management practices.

  • GDPR

    Personal data protection in line with GDPR requirements.

Testing & exercises

  • Internal penetration tests

    Internal penetration tests conducted every quarter to assess security.

  • External penetration test

    Annual external penetration testing across our web, API and cloud.

  • AI red team test

    Dedicated testing by an independent firm to assess how our AI systems fail.

  • Disaster recovery test

    Recovery testing with measured recovery time and recovery point.

  • Incident response exercise

    Incident response exercises covering the GDPR 72 hour notification path.

In-progress

  • SOC 2 Type I

    Our SOC 2 Type I audit is underway as part of our assurance programme.

  • ISO/IEC 42001

    A gap assessment is underway as we work towards ISO/IEC 42001.

Security, without
the ambiguity

No. Your data is strictly isolated and is never used to train, retrain, or fine-tune public or shared AI models. All inspection evidence, property records, and underwriting guidelines remain exclusively yours.

Let’s talk about your requirements.