GDPR & UK GDPR
In placeWe process personal data under the UK GDPR and the Data Protection Act 2018. Where we handle data on your behalf, we act as your processor under a Data Processing Agreement.
Trust Centre
Equate reconciles supplier invoices against booking records, so we handle commercial and financial data. This page answers what a vendor assessment usually asks. The evidence behind it is available on request under NDA.
We process personal data under the UK GDPR and the Data Protection Act 2018. Where we handle data on your behalf, we act as your processor under a Data Processing Agreement.
Customer data is hosted and processed in the UK or EU, and stays in the region agreed at onboarding.
Each customer's data is isolated by Postgres Row-Level Security, enforced at the database layer rather than in application code.
Access to production data is limited to authorised staff on a least-privilege basis, and is audit-logged.
AES-256 at rest and TLS 1.2+ in transit, across the database, storage and application tiers.
Every connection is served over HTTPS. Certificates are issued and renewed automatically.
The production database is backed up automatically and encrypted, with point-in-time recovery.
Core infrastructure runs on managed platforms with redundancy across availability zones. Recovery targets are being finalised.
The application runs on a global edge network with automatic scaling. We monitor availability and latency continuously.
Availability, support response times and incident communication are agreed in the commercial contract.
SAML 2.0 and OIDC single sign-on is on our roadmap for enterprise deployments. Ask us about availability.
Dependency and code scanning runs on every change, and the application has been penetration tested by an independent security firm.
All code is peer-reviewed before merge and ships through an automated pipeline with checks. Production is separated from development.
Equate is Cyber Essentials certified across the whole organisation. Our infrastructure providers hold SOC 2 Type 2 and ISO 27001, evidenced on request.
What we hold today, and what we’re working towards.
Certified July 2026
Application penetration test completed August 2026. Audit report available under NDA.
Certification of a formal information security management system (ISMS).
Independent attestation of our own security and availability controls.
Our named sub-processor list, with purpose, region and certifications, is available on request under NDA.
Our DPA, sub-processor list, provider attestations and a completed security questionnaire, released under NDA.