We are a cyber-security firm, so we hold ourselves to the standards we set for our clients. This statement summarises how we protect the data you entrust to us.
Last updated: 20 June 2026
Your data is encrypted in transit and at rest, isolated per client tenant, and we only make outbound connections, we never open inbound access into your environment. We align to ISO 27001:2022 and the NIST Cybersecurity Framework, and we’re working toward formal ISO 27001 certification. The full detail is below.
Security is built into how we design, build, and run our website, client portal, and platform, not bolted on afterwards. We align our practices to recognised frameworks including ISO 27001:2022 and the NIST Cybersecurity Framework, and we are actively working toward formal ISO 27001 certification.
Traffic to our services is protected with TLS. Data stored in our platform is encrypted at rest using industry-standard algorithms managed through AWS.
Each client's data is logically separated within the platform. Access controls are scoped per tenant so one customer cannot reach another customer's data.
Access to systems and data follows the principle of least privilege. Permissions are granted only where needed for a role and reviewed regularly.
MFA is enforced for our team's access to administrative and production systems, reducing the risk from compromised credentials.
Our infrastructure runs on Amazon Web Services in the London region (eu-west-2), benefiting from AWS's physical and platform security controls.
We log access to our systems and monitor for anomalous activity, with security logs retained for a proportionate period to support investigation.
We follow secure-by-design practices: code is version-controlled and peer-reviewed, dependencies are scanned, and secrets are kept out of source control. Our public website ships with a strict Content Security Policy and hardening headers.
Our practitioners hold recognised industry certifications (including CISSP, CCSP, and ISO 27001 Lead Implementer & Auditor). We operate under our own information-security policies on every engagement, sign mutual NDAs and data processing agreements, and carry professional indemnity insurance.
How we handle personal data, our processors, retention periods, and your rights under UK GDPR are described in our Privacy Policy.
If you believe you have found a security issue in our website or platform, we want to hear from you. Please email security@penthropic.ai with the details. We will acknowledge your report and work with you to resolve it responsibly. Please do not test against our systems without prior written permission.