Security & Privacy

Enterprise-grade security, built in from day one.

EstatesAI is designed for organisations that take data seriously — NHS trusts, local authorities, FM contractors holding sensitive client estate data. Your data stays in the UK, encrypted, isolated, and auditable.

UK Data ResidencyAES-256 EncryptionFull Audit Logging
Core Protections

Six layers of protection

From the data centre to your browser, every layer is hardened by design.

UK Data Residency

All customer data is hosted exclusively in the United Kingdom. Your estate data never leaves UK jurisdiction — full stop.

Encryption Everywhere

Data encrypted in transit (TLS 1.2+) and at rest (AES-256). Your asset registers, compliance records, and user data are protected at every layer.

Access Control

Role-based access control with least-privilege principles. Eight distinct roles mean each user sees only what their job requires.

Full Audit Trail

Every user action — login, upload, edit, export — is logged with timestamp and IP. Full traceability for internal governance and external audits.

Multi-Tenant Isolation

Your organisation's data is strictly isolated. No data is shared between organisations. Logical separation enforced at every data access layer.

Backup & Recovery

Automated daily backups with point-in-time recovery. Backup integrity tested quarterly. Recovery time objective under 4 hours.

Data Residency

Your data stays in the United Kingdom.

EstatesAI is hosted entirely within the United Kingdom. We chose a UK data centre specifically to support NHS, public sector, and local authority customers who require data to remain in UK jurisdiction.

  • All databases and file storage in the UK
  • No cross-border transfers of personal data without appropriate safeguards
  • UK GDPR and DPA 2018 compliant as data processor
  • Data Processing Agreement available on request
Where Your Data Lives
Primary RegionUnited Kingdom
Data at RestAES-256 encrypted
Data in TransitTLS 1.2 minimum
BackupsUK-only, daily
Personal Data TransferUK jurisdiction only*

* AI enrichment sends only non-personal asset data (asset names, building types, technical parameters). Personal data is never transmitted outside the UK.

Compliance

Frameworks & certifications

Built for the regulatory environment your organisation operates in.

UK GDPR & DPA 2018

Compliant

Privacy by design, data minimisation, lawful basis documented for all processing activities.

ICO Registration

Registered

Registered with the Information Commissioner's Office as required by UK law.

NHS DSPT Controls

Aligned

Controls aligned to the NHS Data Security and Protection Toolkit standards for healthcare customers.

Cyber Essentials

In Progress

Cyber Essentials certification in progress — required for public sector and NHS contracts.

Transparency

Sub-processors

We use a small number of carefully vetted sub-processors. All are subject to data processing agreements. We notify customers of any changes with 14 days' notice.

ProviderPurposeLocation
Microsoft AzureCloud hosting & data storageUnited Kingdom
AnthropicAI enrichment (non-personal data only)United States
PostmarkTransactional email deliveryUS / EU

AI enrichment sends only non-personal asset data to our AI provider — asset names, building types, disciplines, and technical parameters. Personal data (names, email addresses, IP addresses) is never transmitted to AI systems.

Need a Data Processing Agreement?

Our DPA is available for review. Enterprise customers can request a countersigned copy.

Start Your Pilot

See your estate's intelligence in 15 minutes.

Start a 3-month pilot. Full platform, fixed low price, no annual commitment. Upload your asset register today.