Skip to content
E-DOB

TRUST CENTRE

Everything your DPO, IT lead and procurement team will ask.

How we secure your data, where it's hosted, who processes it, and what our legal position is — in one place, in plain English.

Cloud

Data handling in five lines.

UK & EU data residency

All data stored in UK and EU regions. No transfers outside without your explicit consent. (Excluding media uploads, media is stored on a secure global CDN)

Encryption at rest and in transit

AES-256 for stored credentials and secrets; TLS 1.2+ for everything in transit.

Full audit trail

Every significant user action logged with user, IP and timestamp.

Private evidence storage

Uploaded files stored in private cloud storage; only accessible via short-lived signed URLs.

Sub-processor transparency

Our sub-processor list is public, versioned and available below.

SECURITY POSTURE

Where we are today, honestly.

E-DOB's security practices are informed by the ISO 27001:2022 framework and the UK's Cyber Essentials scheme. We're not currently certified against either — certification is on our roadmap and we're transparent with customers about that. What you get today is a platform built with security discipline throughout: multi-tenant isolation, encryption, strict Content Security Policy and HSTS, rate limiting, full audit logging, dedicated security event tracking, and mandatory 2FA for platform administrators.

If you'd like to walk your security team through any of this in detail, security@e-dob.uk goes straight to us.

Bring your DPO. We're ready.

Book a call with our team for a full security walkthrough.

We use cookies

We use essential cookies to make E-DOB work, and optional analytics cookies to help us understand how the site is used. You can accept everything, reject non-essential cookies, or manage your preferences.

Read our Cookie Policy →