# Trust & Security — Data Residency, Encryption & Audit | G&

> How G& protects geotechnical data: hosting and data residency, encryption in transit and at rest, backup and recovery targets, audit logging, access model, sub-processor categories, and current ISO 27001 / SOC 2 status.

## Summary

- **Hosting model** — Managed cloud, single-tenant database per customer estate
- **Encryption** — TLS 1.2+ in transit · AES-256 at rest
- **Audit log** — Append-only, every create / edit / approve / export
- **Certification** — ISO 27001 aligned · not yet certified

## Controls

| Code | Area | Status | Detail |
| --- | --- | --- | --- |
| TS-01 | Data residency | In place | Each customer estate is provisioned in one nominated hosting region and stays there; data is not replicated to other regions for convenience. Region is fixed at provisioning and recorded in the agreement. Additional regions for jurisdictions with in-country data requirements are assessed per contract. |
| TS-02 | Encryption | In place | All traffic between clients, field devices and the platform runs over TLS 1.2 or higher. Data at rest — database, file attachments, field photographs, scanned log sheets and generated deliverables — is encrypted with AES-256 using managed keys. Credentials are stored as salted hashes, never in recoverable form. |
| TS-03 | Backups and recovery | Target | Continuous point-in-time recovery over a rolling window, plus daily snapshots retained on a defined schedule. Recovery-point objective (RPO) and recovery-time objective (RTO) are stated as service targets in the agreement rather than open-ended promises, and restore drills are run against a non-production copy. Ask for the current target figures for your deployment tier. |
| TS-04 | Audit logging | In place | Every record creation, edit, validation override, approval, signature and export is written to an append-only audit log with actor, timestamp, previous value and governing standard version. Log entries cannot be edited or deleted by platform users, including administrators. Retention period is set per customer and stated in the agreement. |
| TS-05 | Access model | In place | Role-based access at project and area level: field, laboratory, engineering, approver and read-only viewer. Approval and export rights are separated from data-entry rights so no single account can enter and certify the same value. Access is enforced server-side by row-level policies, not by hiding controls in the interface. |
| TS-06 | Authentication | In place | Email and password with breach-list screening, plus Google sign-in. Enterprise SAML single sign-on and directory-driven provisioning are available on request for organisations that require them. Sessions expire and can be revoked centrally. |
| TS-07 | Data ownership and exit | In place | Your data remains yours. A full export in AGS 4.1 plus Excel is available at any time, at no charge, without a support request or exit fee. On termination the estate is exported and then deleted on a defined schedule. |
| TS-08 | Environment separation | In place | Production, staging and development are separate environments. Production data is not copied into development; test datasets are anonymised. Administrative access to production is limited to named personnel and logged. |

## Sub-processor categories

| Category | Purpose | Scope |
| --- | --- | --- |
| Cloud hosting and managed database | Runs the application, database, object storage and backups | All customer data, within the nominated hosting region |
| Transactional email delivery | Account, notification and approval-request emails | Recipient name and email address, message subject and body |
| AI inference provider | Handwriting transcription of field sheets and the site assistant | Only content submitted to those features; not used to train third-party models |

## Certifications and conformance

### ISO/IEC 27001 — Not certified

G& is not ISO 27001 certified today. The platform's controls — access control, cryptography, logging and monitoring, backup, supplier management, change control — are built to align with the Annex A control set, and the control mapping is available for review under NDA. Any future certification will be published here with the certificate number and scope, not before.

### SOC 2 Type II — Not certified

No SOC 2 report has been issued. Where a tender requires third-party assurance, G& answers security questionnaires directly and will support a customer-led or independent assessment of the deployment.

### AGS 4.1 data standard — In place

Not a security certification, but a governed conformance point: exports are validated against the AGS 4.1 dictionary before release, and the standard version that produced each value is stored with it.
