Trust Centre
Procurement, in one sitting.
Everything your security, privacy and procurement reviewers need to clear DECID:R — our posture, sub-processors, the artefacts available under NDA, and a single contact path. We tell you what's in place, what's in progress, and what's on the roadmap. No marketing fluff.
At-a-glance facts
- Hosting region
- UK / EU
- Customer data residency
- UK / EU
- Encryption in transit
- TLS 1.2+
- Encryption at rest
- AES-256 (managed)
- Default report retention
- 12 months
- Backup retention
- 7 days
- Sev-1 ack target
- 1 hour
- Sub-processor notice
- 30 days
- Standards alignment
- UK GDPR · DPA 2018 · WCAG 2.2 AA
Where we stand on each control
Honest, status-tagged. Anything labelled In progress or Roadmap isn't hidden — you can ask about timelines via the request form below.
Data protection & privacy
How exercise data, account data and personal data are handled.
UK GDPR & DPA 2018 aligned
In placeLawful basis documented per processing activity. Data subject rights handled via privacy@ inbox within 30 days.
Data minimisation by default
In placeWe collect work email, name and organisation. Exercise content is the team's own decisions — no end-customer PII is required to run a session.
Demo accounts are air-gapped
In placeDemo seats are blocked at the database from writing exercise results, so trial data never mixes with production analytics.
Data residency: UK / EU
In placeApplication and database hosted in EU regions. Backups stay in-region.
Standard DPA template
In progressPre-signed Data Processing Agreement available on request below; a self-serve PDF is being added to this page.
Customer-managed retention windows
RoadmapPer-tenant override of the default 12-month retention for session reports.
Security & access
Authentication, authorisation and platform hardening.
Encryption in transit & at rest
In placeTLS 1.2+ for every request. Database storage encrypted at rest by the managed platform.
Row-level access control
In placeDatabase-enforced row-level security on every customer-facing table. Roles separated: admin, partner, customer, demo, participant.
Single sign-on (Google)
In placeGoogle OAuth available alongside email + password. Sessions are short-lived JWTs with rotating refresh tokens.
Least-privilege service roles
In placeApplication code uses the public anon key; privileged operations run inside scoped server functions, not the browser.
Cyber Essentials certified (Culture Gem Ltd)
In placeDECID:R is delivered by Culture Gem Ltd, which holds a current UK Cyber Essentials certificate. Verify on the IASME registry: https://registry.blockmarktech.com/certificates/e1c92501-ee16-43e7-a0c7-ddeca6bdb43c/
SAML / OIDC SSO for enterprise
In progressAvailable on request for annual customers; self-serve configuration coming.
SOC 2 Type II
RoadmapInternal control mapping in progress; external audit planned.
Resilience & operations
What happens when things go wrong, and how quickly we recover.
Daily backups
In placeAutomated daily database backups retained for 7 days; point-in-time recovery available within that window.
Incident response runbook
In placeDefined severity levels, on-call rota and customer-comms template. Sev-1 acknowledgement target: 1 hour.
Status visibility
In placeLive status surface for the customer-facing app; major incidents communicated by email to account owners.
Published RTO / RPO targets
In progressTargets being formalised in the standard security overview document.
Public status page
RoadmapExternal status.decidr.live page for uptime history and live incidents.
Sub-processors & supply chain
The third parties involved in delivering the service.
Managed Postgres + storage
In placeEU region, encryption at rest. Used for customer accounts, session reports and exercise results.
Edge runtime & CDN
In placeApplication served via global edge for latency, with EU-pinned data plane.
Transactional email
In placeUsed for account verification, magic links and report-ready notifications. No marketing.
Payments
In placeCard processing handled by a PCI-DSS Level 1 provider; we never see or store card data.
Sub-processor change notice
In progress30-day notice before adding or removing a sub-processor; subscribe via the request form below.
AI & content safety
How generative AI is (and isn't) used in the platform.
No customer data trains models
In placeCustomer exercise data is never used to train or fine-tune any third-party model.
AI is augmentation, not authority
In placeScenario branches, scoring rules and the decision framework are human-authored. AI is used for summarisation and language polish only.
Prompt-injection guardrails
In placeUser-supplied free text is scoped and never trusted as system instruction. Server functions validate all inputs before any model call.
Customer opt-out for AI features
RoadmapPer-tenant toggle to disable AI-assisted summarisation in debriefs.
Accessibility & inclusion
We treat accessibility as a security control: an exclusionary product is a broken control.
WCAG 2.2 AA target
In placeComponents designed against WCAG 2.2 AA; accessibility widget on every page (contrast, motion, dyslexic-friendly font, larger hit areas).
Keyboard-first navigation
In placeAll flows are keyboard-operable; skip-to-content link on every page; focus trapping in dialogs.
Independent VPAT
In progressExternal audit and Voluntary Product Accessibility Template scheduled.
Public policies
These are publicly accessible — no NDA required.
Privacy notice →
What we collect, why, and your rights.
Terms of service →
How the service is provided.
Acceptable use →
What the platform may and may not be used for.
Demo licence →
Terms for the free 3-day demo seat.
Refund policy →
Refund window and conditions.
Risk model →
How decisions are scored and why.
NDA-gated artefacts
Request the procurement pack
Pen-test summaries, SOC readiness status, the pre-signed DPA, and any specific questionnaire help — all under a mutual NDA. We typically respond within one working day.
Direct contacts
Security
security@decidr.liveVulnerability disclosure, incident notifications.
Privacy
privacy@decidr.liveData subject requests, DPA queries.
Procurement
hello@decidr.liveAnything else — we'll route it.
