Security

Built to be examined

You are buying a system whose whole purpose is to stand up to scrutiny. It would be a poor advertisement if the platform holding your evidence could not survive the same questions.

Where your data sits, and how it is looked after, follows the regulation that applies to you. For United Kingdom clients the platform runs in Amazon Web Services' London region, so your data stays in the United Kingdom. If your obligations point somewhere else, raise it early and we will work through it with you.

What follows is the summary. The architecture overview and the API specification go to prospective clients on request, and we answer assurance questionnaires directly and in writing.


Your data cannot reach another organisation

Your data is separated from every other organisation's twice over, by two independent mechanisms. The first sits in the software. The second sits in the database itself, which will not hand over another organisation's records no matter what the software asks it for.

That second layer is the one that matters. It means a mistake in the software cannot expose another organisation's register, because the database refuses regardless. Both layers are tested automatically on every change we make.


A record nobody can quietly edit

Every change writes an entry: who, what changed, from what to what, when, the role held at the time and the line of defence. Names and roles are captured at the moment of the change, so the trail still reads correctly years later.

The record only ever grows. Nothing in the system can edit an entry or remove one, and that holds for administrators and for us as well as for your users. Entries are chained to one another, so an entry altered after the fact no longer fits and a check reports where. An auditor gets evidence rather than a log we assure them is complete.


Segregation of duties, enforced rather than asserted

These refusals are a security control as much as a governance one, and the platform enforces them where a browser cannot argue with them.

  • Whoever submitted a breaching value cannot write its response, and nor can the author of the original submission.
  • Whoever compiled a committee pack cannot approve any step of it, and no one person clears two steps of the same pack.
  • Whoever requests closure of a remediation action cannot approve it.
  • Nobody grants themselves a role, deactivates their own account or resets their own second factor. Nobody, at any level, edits or deletes an audit entry.

The data we hold is deliberately narrow

PureTrace is designed to run on business data rather than personal data. What it holds about your people is their working identity: name, work email address, role and the record of what they did in the system.

Your data is used to run your platform and for nothing else. It never trains anything, and no model makes a risk judgement anywhere in the system.