Security & compliance

The most secure place for your risk data might be your own.

Polestead is built to run where you decide — up to and including fully air-gapped. When the platform lives inside your walls, there is no third-party attack surface to inherit and no foreign jurisdiction to answer to.

How we secure it.

Deploy where you decide

On-premises, air-gapped, single-tenant EU cloud, or managed single-tenant SaaS. You choose the boundary your data lives inside.

Encryption everywhere

Data encrypted in transit (TLS) and at rest. Secrets are managed, rotated, and never written to logs.

Isolation by default

Row-level security in the database and single-tenant instances for the managed and EU-cloud models — no co-mingled customer data.

Least privilege & SSO

Role-based access control, SSO/SAML for managed deployments, and scoped API entitlements. Access is granted narrowly and reviewed.

AI that can't leak to us

Inference runs on your keys or not at all. Your data never trains our models — structurally, because it never reaches our infrastructure.

Secure development

Code review, dependency and secret scanning in CI, and periodic third-party penetration testing of the managed service.

Framework alignment — stated honestly.

Polestead is new. Rather than borrow badges, we publish where each framework actually stands. Because you can self-host, your own auditors can inspect the deployment directly.

Framework
Status
Notes
SOC 2 Type II
In progress
Controls designed to the Trust Services Criteria; observation window underway.
ISO/IEC 27001
Aligned · roadmap
ISMS built to 27001 structure; certification planned.
GDPR
Supported
DPA available; self-host keeps personal data in your environment.
DORA · NIS2
Supported by CIIC
Incident clocks and regulator-ready reporting; dataset carries last-verified dates.
Subprocessors
Published
Managed-service list in our Trust Center; none used for self-hosted data.

Status labels reflect Polestead's position as of the last-updated date and will change as certifications complete. We will never display a badge we haven't earned.

Found something? Tell us.

We run a responsible-disclosure programme. Report suspected vulnerabilities to security@polestead.com — we acknowledge promptly, keep you updated, and will not pursue good-faith research that follows the policy. Please don't access data that isn't yours or degrade the service while testing.

Security contacts
Vulnerabilitiessecurity@polestead.com
FAQ

Security questions.

Are you SOC 2 or ISO 27001 certified?+

We're new. Controls are designed to SOC 2 and ISO 27001 criteria and certification is on the roadmap — we publish honest status, not borrowed badges. Self-hosting lets your own auditors inspect the deployment directly.

How does self-hosting change my posture?+

Your register, assessments, and incident records never leave your environment — no third-party attack surface to inherit, no cross-border compulsion question.

Does my data reach an AI provider?+

Only if you enable AI with your own keys, in which case the call goes to your provider under your terms. Zero-AI runs with no external inference. We never train on your data.

How do I report a vulnerability?+

Email security@polestead.com. We run a responsible-disclosure programme, acknowledge promptly, and protect good-faith researchers who follow the policy.