Skip to content
E-DOB

SECURITY & COMPLIANCE

Security software should be Secure!

E-DOB's security practices are informed by the ISO 27001:2022 information security framework and the UK's Cyber Essentials scheme. We're not currently certified against either — we're a small, security-focused engineering team that treats those frameworks as a checklist for building the product, and we're transparent with prospective customers about where we are on that journey. What you get today is a platform built with security discipline at its core, documented in a Trust Centre your DPO can actually read.

evidance-firewall

Isolation, encryption, and nothing cached that shouldn't be.

Every company is fully isolated — data never crosses tenant boundaries. Credentials and OAuth tokens are stored encrypted (AES-256). A strict Content Security Policy, HSTS and hardened headers protect every page, and media is only ever served through short-lived signed URLs from private storage. Our application is hosted by AWS in the EEA and Cloudflare Object Storage.

Secure-cloud

Every action has a name and a timestamp attached.

All significant user actions are audit-logged with user, IP address and user agent. A dedicated security event log tracks authentication failures and suspicious activity. Rate limiting guards logins, 2FA, share links and AI endpoints. Two-factor authentication is available to all accounts — and mandatory for platform administrators.

log

Documentation your procurement team will ask for.

Our security practices are informed by the ISO 27001:2022 framework and the Cyber Essentials scheme's five themes — we're not certified against either yet, and we say so plainly rather than imply otherwise. The Trust Centre holds our terms, privacy policy, acceptable use policy and sub-processor list, versioned, with acceptance tracked.

Documents

Everything included

  • Informed by ISO 27001:2022 — used as our security framework; certification is on our roadmap, not yet in place
  • Informed by Cyber Essentials — treated as a checklist across all five themes, not a claimed certification
  • Encrypted credentials — AES-256 for every stored secret and token
  • Strict CSP & HSTS — hardened headers on every page
  • Rate limiting — logins, 2FA, share links and AI endpoints protected
  • Audit logging — every significant action, with user, IP and timestamp
  • Security event log — authentication failures and suspicious activity tracked
  • Path traversal protection — every file path input validated
  • Two-factor authentication — available to all, mandatory for platform admins
  • UK/EU data residency — with a versioned, public Trust Centre

Frequently asked questions

In UK/EU regions on AWS and Cloudflare infrastructure, with UK data residency.
No. We use ISO 27001:2022 as the framework our security practices follow, but we're not currently certified against it. Certification is on our roadmap. Our Trust Centre sets out exactly what controls we operate today, and we're happy to walk your security team through any of them.
Card details go straight to Stripe and never touch E-DOB's servers — PCI DSS SAQ A scope.

Bring your DPO. We're ready.

Start your 14-day free trial today. No card required.

No card required

We use cookies

We use essential cookies to make E-DOB work, and optional analytics cookies to help us understand how the site is used. You can accept everything, reject non-essential cookies, or manage your preferences.

Read our Cookie Policy →