Built to be trusted.
Enterprise-grade security for the data behind every supplier decision.

The controls behind every supplier decision.
AES-256 at rest. TLS 1.3 in transit.
Role-based access, audit logs, and SSO.
Stored and processed in the European Union. Your supplier data never leaves EU borders.
A custom Data Processing Agreement is available on request.
Every search, export, and permission change is logged and available for review.
Compliant by design, with a signed DPA and EU-only processing.
Independently audited, EU hosted.
EU hosted
Your data stays in the EU. GDPR compliant by design.
ISO 27001
Independently certified information security management.
SOC 2 Type II
Audited controls, verified over time.
The questions your security team will ask.
Do you use our data to train AI models?
No. Your supplier data, searches, and documents never train any model, ours or anyone else’s. They are processed to answer your question and nothing more.
Who are your subprocessors?
A current subprocessor list is available on request and forms part of the DPA. We notify customers before adding a new one.
How often is the platform penetration tested?
Annually, by an independent third party, alongside continuous automated scanning. Summary reports are available under NDA.
What happens if there is a breach?
You are notified without undue delay, and within 72 hours. That is GDPR Article 33. You get what happened, what was affected, and what we have done.
How long do you keep our data, and can we get it back?
For the life of the contract. On termination you can export everything, and we delete it on request within 30 days.
Can we run our own security review?
Yes. Send us your questionnaire. We complete customer security assessments as standard. We can sign your NDA and DPA before the review starts.
Bring it to your security team.
We will complete your questionnaire, sign your DPA, and answer anything this page did not.
Talk to us