Security posture · architecture · sub-processors · roadmap

Built for buyers who read
the security review.

We sell to CISOs. Our own security posture is the first thing they assess. Below is the same architecture, sub-processor and compliance roadmap document we hand over during procurement — but public.

UK GDPR EU GDPR · SCC + UK IDTA TLS 1.3 · HSTS preload AES-256-GCM at rest RFC 3161 notarisation SOC 2 Type II — 2027 ISO 27001 — 2027
Architecture

Defence in depth, from SDK to storage.

At the customer perimeter

  • PII redaction at the SDK boundary, before any network transmission
  • SHA-256 hash of raw payload generated locally — enables verification without storing raw data
  • Local disk buffer for offline / air-gapped operation
  • Async, batched, encrypted transport — never blocks the agent

In transit

  • TLS 1.3 minimum, with mandatory HSTS preload
  • API key Bearer authentication, SHA-256 hashed on the server
  • Rate-limited and size-capped at the edge before reaching app code

At rest

  • AES-256-GCM encryption at the storage layer
  • Customer-held signing keys (Professional tier and above) — shipping Q4 2026
  • UK data residency by default; EU and US optional
  • Hash-chain integrity verifiable independently against any read-only copy
Sub-processors

Who handles what.

Sub-processor Purpose Region
Supabase Inc.Managed database hot store and authenticationUK / EU
Amazon Web ServicesLong-term encrypted cold archiveeu-west-2 (London)
Vercel Inc.Edge CDN and serverless function runtimeUK edge presence
FreeTSA / Sectigo TSARFC 3161 timestamping (optional)EU
StripeBillingUK / EU

Any change to this list is notified at least 30 days in advance per our standard DPA, and customers may object in writing.

Compliance roadmap

Certifications and where we are with each.

In place

UK GDPR / DPA 2018

Full compliance. Standard DPA available pre-contract.

In place

EU GDPR

Article 28 sub-processor terms, SCC + UK IDTA available for international transfers.

Planned

SOC 2 Type II

Targeted for 2027 once first paid customers are live. We will publish the engaged auditor and audit window when booked.

Planned

ISO 27001:2022

Targeted alongside SOC 2 in 2027. ISMS scope drafted; we will publish the certification body and audit dates when engaged.

Planned

UK Cyber Essentials

Targeted via the VantagePoint Networks parent organisation.

Planned

NHS DSPT

For UK healthcare customers. Submission targeted Q4 2026.

Vulnerability disclosure.

We take coordinated disclosure seriously. Email info@vpnetworks.co.uk with details of any suspected vulnerability. We acknowledge within one working day and aim for a coordinated disclosure within 90 days.

For the curious, our /.well-known/security.txt is the machine-readable canonical version.