Trust

How we protect your documents

Facts about where your documents go and what touches them. Short, verifiable, no seals.

01

Where processing happens

Every stage of processing, including AI inference, runs within the EU (Ireland). Your documents remain strictly within that environment.

02

Before anything reads your files

Every upload passes a malware scan in an isolated stage before any other component touches it.

03

Encryption, in transit and at rest

Every connection uses TLS 1.3 to secure data on the move. At rest, your data is encrypted with AES-256 using customer-managed keys, backed by a documented and periodically tested key management lifecycle. Looking ahead, our architecture integrates an active Post-Quantum Cryptography initiative, proactively preparing our cryptographic lifecycles and infrastructure to support quantum-safe standards.

04

Tenant isolation and ephemeral compute

Tenants are isolated end-to-end via verified tokens, with all processing jobs running in ephemeral, sandboxed compute environments.

05

Access controls

Access is strictly governed by the principle of least privilege, ensuring operators only have the permissions necessary for their specific roles. Privileged access is tightly controlled, monitored, and restricted to verified personnel, requiring multi-factor authentication and continuous logging for every session.

06

Standards, ours and our suppliers'

Our information security management system at INKASEC is strictly aligned with ISO 27001:2022, ISO 27017:2015, and ISO 27018:2019, covering core security, cloud controls, and PII protection. Furthermore, our infrastructure partners hold comprehensive, independent certifications that are transparently verifiable through their respective compliance programmes.

07

Logging, monitoring and alerting

Access and processing events are logged to tamper-evident storage. Logs are monitored continuously, with automated alerting on anomalous access or failed controls, and reviewed by a person.

08

Incident management

We maintain a formal incident response plan that ensures rapid containment, thorough investigation, and structured recovery for all security events. This framework includes a dedicated playbook for ransomware mitigation, focusing on isolated backup restoration, swift service restoration, and transparent customer notifications.

09

Business continuity and disaster recovery

Operational resilience is built directly into our architecture through continuous data replication and automated failover capabilities. Our disaster recovery frameworks are subject to periodic, structured testing to validate our recovery point and recovery time objectives under simulated failure scenarios.

10

Application security

Applications are secured by design through strict testing criteria and continuous automated checks. We run comprehensive code testing on every release, utilising integrated SAST and DAST tools to detect and eliminate security vulnerabilities before they hit production.

11

Who operates this

A named UK operating company, INKASEC Ltd. The people behind it are entirely reachable; our contact page is not decorative, and our security experience is real.

12

Retention, deletion and destruction

Documents are kept only as long as needed to deliver your response, though you can choose to retain them longer to support your future requirements. When data is removed, destruction utilises cryptographic erasure with FIPS 140-3 validated modules, strictly in line with NIST SP 800-88.

13

GDPR and UK data protection law

Processing complies with the UK GDPR and the Data Protection Act 2018, and with the EU GDPR where it applies. We act as your processor, under the DPA you accept before anything is processed.

What we do not claim

We do not claim this makes you or us immune to anything. It describes how the service is built and run today.