Compliance & Security
Housing data is sensitive — it covers people's homes, finances, and wellbeing. We treat security and regulatory compliance as foundational, not optional.
Our Security Principles
Every system we build and every dataset we handle is governed by four core principles.
Data Protection
All personal and housing data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We maintain a lawful basis for every category of data we handle.
Encryption
Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Database connections are secured with SSL, and all secrets are managed through environment-level vaults — never stored in code.
Access Control
Role-based access control (RBAC) ensures users only see the data relevant to their role. All authentication events and data access are logged for audit purposes, with session management enforced via JWT tokens.
Regulatory Alignment
Our solutions are designed to support compliance with the Decent Homes Standard, Awaab's Law, Tenant Satisfaction Measures (TSMs), and expectations set by the Regulator of Social Housing.
Regulatory Compliance
Our solutions are designed to help housing providers meet current and emerging regulatory requirements — not just report on them, but stay ahead of them.
Decent Homes Standard
Our analytics track stock condition data against the Decent Homes criteria, flagging properties that are approaching or breaching the standard so teams can prioritise remediation works before inspection.
Awaab's Law
Damp and mould case monitoring is built into our platform. We help housing providers meet the prescribed timescales for investigation, response, and remediation — with automated alerts when deadlines approach.
Tenant Satisfaction Measures (TSMs)
Our reporting modules align with the TSM framework, enabling providers to track, benchmark, and report on the measures required by the Regulator of Social Housing with minimal manual effort.
Housing Regulator Expectations
From consumer standards to governance and financial viability, our data tools give leadership teams visibility over the metrics that regulators assess — supporting proactive compliance rather than reactive scrambling.
Data Handling
Transparency about what data we process, how we store it, and what rights data subjects retain.
- We process property condition data, tenancy records, repair histories, arrears data, and tenant contact information — only as required to deliver the contracted service.
- All data is stored in encrypted PostgreSQL databases hosted on Azure infrastructure within UK or EEA data centres.
- Data retention periods are agreed with each client during onboarding. Default retention is aligned with the client’s own policies or 7 years, whichever is shorter.
- Tenants and data subjects retain their right to access, rectification, and deletion under UK GDPR. We support clients in fulfilling Subject Access Requests (SARs) promptly.
- We do not sell, share, or use client data for any purpose beyond the agreed scope of work. Data is never used to train third-party models without explicit written consent.
Vendor Assessment Support
We understand that procurement teams need to assess vendors thoroughly before onboarding. We are happy to support your due diligence process and can provide the following on request:
- Completed security questionnaires and pre-qualification documents
- Data Protection Impact Assessments (DPIAs) for our core platform
- Architecture and infrastructure diagrams showing data flow and hosting
- Evidence of encryption standards, access controls, and incident response procedures
- Details of sub-processors and third-party services used in delivery
- References and case study material from existing housing sector clients
Questions About Security?
If you have questions about our security practices, data handling, or need documentation for a vendor assessment, we're happy to help.
