Skip to content

Trust centre

How your data is protected — including what isn't finished yet

You're being asked to store employment records here, so this page states plainly what is in place, what is in progress, and who processes what. Anything not listed as done isn't done.

In place today

  • UK data residency

    Application data and uploaded documents live in London (AWS eu-west-2, via Supabase), encrypted in transit (TLS) and at rest.

  • Tenant isolation

    Every table carries the organisation id; queries are organisation-scoped server-side and Postgres row-level security policies back them up. Cross-tenant access is covered by automated tests against a live database.

  • Role-based access

    A deny-by-default capability matrix (owner, admin, compliance manager, HR, finance, adviser, viewer) gates every write server-side. Finance can pay the bill but cannot touch a compliance record; advisers and viewers are read-only.

  • Audit trail

    An append-only audit log records mutating actions — including audit-pack generation and downloads, right-to-work share-code reveals, team changes and setting changes.

  • Sensitive-data handling

    Worker government identifiers (NINo, passport numbers, BRP) are deliberately not collected. Right-to-work share codes are masked in the interface and every reveal is permission-gated and logged. Signed download links expire after 5 minutes.

  • Uploads

    File type and size are restricted, storage keys are randomised per organisation path, and access is only ever via short-lived signed URLs.

  • Data export and deletion

    Owners can self-serve a full data export and account deletion from Settings → Data & privacy, with a 7-day grace period before permanent deletion.

In progress — stated honestly

  • Independent penetration test

    Commissioned before broad paid launch; the summary will be published here.

  • MFA for privileged users

    Multi-factor authentication for owners and admins is planned before real-data launch; single sign-on is on the roadmap for larger customers.

  • Professional review of compliance content

    Checklists and event rules are mapped to published GOV.UK guidance with per-item sources; independent review by a qualified immigration professional is in progress and its status is shown in the product.

  • Company registration details

    The operating company's registered details and ICO registration reference will be published on the legal pages before any payment is taken.

Subprocessors

The authoritative list lives in the privacy policy; DPA customers receive 30 days' notice of changes.

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageLondon, UK
VercelApplication hosting and deliveryEU/USA
StripePayments, invoicing and VATEU/USA
ResendTransactional emailEU/USA
PostHogProduct analytics (only with consent), EU cloudEU
SentryError monitoringEU/USA
AnthropicOptional AI drafting of report text (feature-gated per organisation)USA

Report a vulnerability

Email security@sponsorfort.com with steps to reproduce. We acknowledge within 2 working days, we won't pursue good-faith research, and we'll credit you if you'd like. If you believe customer data is at immediate risk, put “URGENT” in the subject line.

Related: Privacy policy · Data processing agreement · Account deletion