SECURITY & COMPLIANCE
Security software should be Secure!
E-DOB's security practices are informed by the ISO 27001:2022 information security framework and the UK's Cyber Essentials scheme. We're not currently certified against either — we're a small, security-focused engineering team that treats those frameworks as a checklist for building the product, and we're transparent with prospective customers about where we are on that journey. What you get today is a platform built with security discipline at its core, documented in a Trust Centre your DPO can actually read.
Isolation, encryption, and nothing cached that shouldn't be.
Every company is fully isolated — data never crosses tenant boundaries. Credentials and OAuth tokens are stored encrypted (AES-256). A strict Content Security Policy, HSTS and hardened headers protect every page, and media is only ever served through short-lived signed URLs from private storage. Our application is hosted by AWS in the EEA and Cloudflare Object Storage.
Every action has a name and a timestamp attached.
All significant user actions are audit-logged with user, IP address and user agent. A dedicated security event log tracks authentication failures and suspicious activity. Rate limiting guards logins, 2FA, share links and AI endpoints. Two-factor authentication is available to all accounts — and mandatory for platform administrators.
Documentation your procurement team will ask for.
Our security practices are informed by the ISO 27001:2022 framework and the Cyber Essentials scheme's five themes — we're not certified against either yet, and we say so plainly rather than imply otherwise. The Trust Centre holds our terms, privacy policy, acceptable use policy and sub-processor list, versioned, with acceptance tracked.
Everything included
- Informed by ISO 27001:2022 — used as our security framework; certification is on our roadmap, not yet in place
- Informed by Cyber Essentials — treated as a checklist across all five themes, not a claimed certification
- Encrypted credentials — AES-256 for every stored secret and token
- Strict CSP & HSTS — hardened headers on every page
- Rate limiting — logins, 2FA, share links and AI endpoints protected
- Audit logging — every significant action, with user, IP and timestamp
- Security event log — authentication failures and suspicious activity tracked
- Path traversal protection — every file path input validated
- Two-factor authentication — available to all, mandatory for platform admins
- UK/EU data residency — with a versioned, public Trust Centre
Frequently asked questions
Related features
User management
Named user groups with granular permissions replace blunt admin/user roles — controlling closing rights, edit rights, AI access, and visibility of departments, locations and incident types.
Learn moreEvidence management
CCTV exports, photos, documents and statements — uploaded to the report they belong to, scanned for malware, stored encrypted, and playable in the browser.
Learn moreSecure sharing
When an external agency needs an incident, send a password-protected, time-limited link — no E-DOB account required on their end, full control retained on yours.
Learn moreBring your DPO. We're ready.
Start your 14-day free trial today. No card required.
No card required