Data Security & Privacy

The Protection Behind Every Threatwhere Account

Threatwhere is relied upon in hostile environments where the confidentiality and integrity of information cannot be compromised. We protect the data you entrust to us to the same standard as the intelligence we deliver.

UK & EU

Data residency

HTTPS & WSS

Production public endpoints

UK & EU

Processed in region

Never sold

Never used to train AI

How Your Data Is Protected

The same standard of protection we apply to the intelligence we deliver — applied to the data you entrust to us.

Encrypted Connections to Our Endpoints

Threatwhere's production web and mobile applications connect to our backend services and realtime endpoints over HTTPS and WSS.

Controlled, Least-Privilege Access

Internal access to customer data is restricted to operational need.

Audit Logging

Administrative and operational actions in your organisation are recorded, available to your administrators and exportable.

DATA RESIDENCY

Stored Within the UK and EU

All customer data is stored within the United Kingdom and European Union. Any limited processing outside the region is governed by our Data Processing Agreement.

Region & Sub-Processors

The complete sub-processor list and the protections that apply are set out in our Data Processing Agreement, available to every customer on request.

Request a DPA
OWNERSHIP & RIGHTS

Yours, and Only Yours

You own your data. We never sell it, and we do not use your operational data to train AI models. We collect only what the platform needs to function, and we honour data subject rights in line with EU GDPR and UK GDPR.

A Data Processing Agreement is available to every customer on request.

Access
Correction
Export
Erasure

Your AI Interactions Are Private

When you use Threatwhere's AI capabilities, your questions, the context drawn from your own data, and the responses you receive are treated as your confidential data, held in the UK and EU and available only to your authorised users.

We do not use your AI interactions to train AI models.

Resilient by Design

Engineered to stay available when it matters most.

DDoS Mitigation

Enterprise-grade denial-of-service mitigation protects the platform at the network edge.

Continuous Monitoring

The platform is monitored continuously, with automatic failover if a component fails.

Point-in-Time Recovery

Stored data is backed by point-in-time recovery, so it can be restored to any moment.

Zero-Downtime Deployments

Deployments are engineered to be zero-downtime — the intelligence you depend on stays available.

Built to Recognised Standards

Our security programme is built around the controls and principles that underpin SOC 2 and ISO 27001, and our privacy practices align with EU and UK GDPR.

SOC 2

Built around the controls and principles that underpin SOC 2.

ISO 27001

Information security aligned to ISO 27001 standards and principles.

EU & UK GDPR

Privacy practices aligned with both EU GDPR and UK GDPR.

FAQ

Answers for Your Risk & Procurement Teams

Clear answers to the questions our customers' security, risk, and procurement teams ask most.

Data storage & residency

Encryption & resilience

Access & accountability

Threatwhere AI & privacy

Ownership, rights & data lifecycle

Compliance & assurance

Talk to Our Security Team

For a Data Processing Agreement, security documentation, or to complete a security questionnaire, contact our security team and we will provide everything your risk and compliance teams need.