Trust centre
How your data is protected — including what isn't finished yet
You're being asked to store employment records here, so this page states plainly what is in place, what is in progress, and who processes what. Anything not listed as done isn't done.
In place today
UK data residency
Application data and uploaded documents live in London (AWS eu-west-2, via Supabase), encrypted in transit (TLS) and at rest.
Tenant isolation
Every table carries the organisation id; queries are organisation-scoped server-side and Postgres row-level security policies back them up. Cross-tenant access is covered by automated tests against a live database.
Role-based access
A deny-by-default capability matrix (owner, admin, compliance manager, HR, finance, adviser, viewer) gates every write server-side. Finance can pay the bill but cannot touch a compliance record; advisers and viewers are read-only.
Audit trail
An append-only audit log records mutating actions — including audit-pack generation and downloads, right-to-work share-code reveals, team changes and setting changes.
Sensitive-data handling
Worker government identifiers (NINo, passport numbers, BRP) are deliberately not collected. Right-to-work share codes are masked in the interface and every reveal is permission-gated and logged. Signed download links expire after 5 minutes.
Uploads
File type and size are restricted, storage keys are randomised per organisation path, and access is only ever via short-lived signed URLs.
Data export and deletion
Owners can self-serve a full data export and account deletion from Settings → Data & privacy, with a 7-day grace period before permanent deletion.
In progress — stated honestly
Independent penetration test
Commissioned before broad paid launch; the summary will be published here.
MFA for privileged users
Multi-factor authentication for owners and admins is planned before real-data launch; single sign-on is on the roadmap for larger customers.
Professional review of compliance content
Checklists and event rules are mapped to published GOV.UK guidance with per-item sources; independent review by a qualified immigration professional is in progress and its status is shown in the product.
Company registration details
The operating company's registered details and ICO registration reference will be published on the legal pages before any payment is taken.
Subprocessors
The authoritative list lives in the privacy policy; DPA customers receive 30 days' notice of changes.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | London, UK |
| Vercel | Application hosting and delivery | EU/USA |
| Stripe | Payments, invoicing and VAT | EU/USA |
| Resend | Transactional email | EU/USA |
| PostHog | Product analytics (only with consent), EU cloud | EU |
| Sentry | Error monitoring | EU/USA |
| Anthropic | Optional AI drafting of report text (feature-gated per organisation) | USA |
Report a vulnerability
Email security@sponsorfort.com with steps to reproduce. We acknowledge within 2 working days, we won't pursue good-faith research, and we'll credit you if you'd like. If you believe customer data is at immediate risk, put “URGENT” in the subject line.
Related: Privacy policy · Data processing agreement · Account deletion