Security and Data Protection

Built for people whose job is information security. The platform is designed and run by a PECB certified ISO 27001 and ISO 42001 Lead Auditor and Lead Implementer.

Data Residency

All programme data and uploaded evidence files are stored in the EU West region. A small number of named sub processors listed in our privacy policy operate outside the EEA under standard contractual clauses.

Authentication

Sign in with Google, or with email and password. OAuth tokens are handled by our authentication provider. Customers signing in with Google inherit their Google account's multi factor policy, and multi factor authentication for email and password sign in is not currently offered.

Encryption

All data is encrypted with TLS in transit and encrypted at rest. Evidence files are stored in a private storage bucket with row-level security.

GDPR

Auditara is built to UK GDPR requirements. We publish a privacy policy and an Article 28 data processing agreement. We do not sell data, and we do not use your data to train models. Full privacy policy available at /privacy.

AI Assistance

Optional, off by default, and consent logged per workspace. Runs entirely server side against EU hosted models (Mistral AI, France) with zero data retention. AI can draft a complete document, section by section, from your own intake answers, the section guidance in the template, the control references the document maps to, and content you have already typed. It never reads or sends uploaded evidence files. Nothing is scored by AI. Every output lands as an unreviewed draft, is labelled as one, and a document cannot be approved while any section is still unreviewed, so a person always confirms the text. Connected tools such as GitHub, AWS, Microsoft Entra, and Google Cloud are read only, and any scheduled reading of them is opt in per workspace.

Policy version 2026-08-ai-v3, effective 4 August 2026.

Questions? Contact us at hello@auditara.io