Skip to main content

    Security · data protection

    Your firm's records are stored in the UK, and stay yours.

    You are handing a compliance platform your firm's most sensitive records. Here is exactly how we hold them: where they live, who can reach them, and what we will never do with them.

    UK · London · eu-west-2UK GDPR · Article 28TLS in transit · encrypted at rest

    What we do today

    Six protections, live now.

    Written for procurement: the controls that are in place today, the sub-processors that see your data, and where the limits are. It prints clean.

    01 · Residency

    UK data residency

    Firm data is stored in the United Kingdom (London, eu-west-2), and stored data stays there. When the AI does work, only the context it needs leaves the UK, and only to the sub-processors named in section 06, under the terms set out there.

    02 · Encryption

    Encryption and circuit breakers

    Data is encrypted in transit (TLS) and at rest. Each specialist runs behind a circuit breaker that halts it if it behaves unexpectedly, with per-firm spend ceilings on specialist AI work and a daily ceiling on assistant usage.

    03 · Access

    Role-based access, per-firm isolation

    Every table holding your firm's data is isolated per firm, enforced in the database rather than in application code, so a query made for one firm cannot return another firm's rows. Access within your firm is role-based. Administrative access to the platform itself is held only by named RegForge staff accounts.

    04 · Auditability

    Append-only trail, reversible actions

    Every action writes an append-only audit record: the inputs, the reasoning, and the Handbook references cited. Audit records can never be deleted. Low-risk automated actions are reversible within 24 hours.

    Four meeting actions overdue: 2 with Hana, 1 with Oliver, 1 unassigned. The 6 March audit committee minutes are still empty 47 days on. I've drafted placeholder minutes from the agenda for the chair to review, and three follow-up emails offering complete / extend / cancel. None are decisions for me to take.
    Bryn · Board Secretary · Keeps the record. Chases the action.
    05 · Processing

    DPA · UK GDPR Article 28

    We act as your processor under a written data-processing agreement. Your firm remains the controller; the data, and the decisions taken on it, stay yours.

    06 · Sub-processors

    Your data never trains a model

    When the AI does work, only the context it needs is sent to our AI sub-processors: Anthropic (Claude, for drafting and document reading) and OpenAI (for search embeddings), both processing in the United States under written data-processing terms and UK transfer safeguards. Neither trains on your data. We do not train our own models on your data either, unless you explicitly opt in to anonymised product improvement. The AI reads your context to do the work in the moment; it does not learn from it for anyone else.

    For our current sub-processor list, ask us and we will share it.

    Certifications

    We would rather be accurate than impressive.

    The protections above are facts you can verify, not badges. For formal attestations, SOC 2, ISO 27001 and independent penetration-test reports, ask us for our current status and we will share where each one stands.

    We will not claim a certificate we do not hold, and we will not dress a roadmap up as a control. When something lands, it will say so here, with a date.

    Built to be inspected,
    not just trusted.

    Questions about data residency, the DPA, or our sub-processors? Bring them to the founder. Twenty minutes, ex-FCA, no slides.

    Talk to us for 20 minutes