ISO 27001 certified, UK data residency, and every regulatory framework you need — mapped, tracked, and exportable.
Information security management — independently audited every 12 months.
NCSC-approved. Re-assessed annually, with internal scans quarterly.
DPO appointed. Data stays in the UK. Full DPIA support for enterprise clients.
Standards Met for NHS and health-adjacent deployments.
Direct procurement for UK public sector. Pre-approved T&Cs and pricing.
In progress — attestation expected Q3 2026.
All data stored in AWS eu-west-2 (London). No transfers outside the UK, ever. Full right-to-erasure tooling.
Every file, database row, and backup encrypted with AWS KMS keys. TLS 1.3 in transit.
Okta, Azure AD, Google Workspace SAML. Passkeys and hardware key support. MFA mandatory for all admin accounts.
Annual CREST-accredited pen test. Continuous bug bounty. All critical findings published in our trust report.
RPO 15 minutes, RTO 4 hours. Multi-AZ replication. Monthly failover drills.
Live security posture at trust.cloud-safe.uk — status page, pen test summaries, and all certificates.
Join 400+ safety teams who trust CloudSafe to keep their buildings — and their people — on the right side of the law.