Threatwhere is relied upon in hostile environments where the confidentiality and integrity of information cannot be compromised. We protect the data you entrust to us to the same standard as the intelligence we deliver.
UK & EU
Data residency
HTTPS & WSS
Production public endpoints
UK & EU
Processed in region
Never sold
Never used to train AI
The same standard of protection we apply to the intelligence we deliver — applied to the data you entrust to us.
Threatwhere's production web and mobile applications connect to our backend services and realtime endpoints over HTTPS and WSS.
Internal access to customer data is restricted to operational need.
Administrative and operational actions in your organisation are recorded, available to your administrators and exportable.
All customer data is stored within the United Kingdom and European Union. Any limited processing outside the region is governed by our Data Processing Agreement.
The complete sub-processor list and the protections that apply are set out in our Data Processing Agreement, available to every customer on request.
Request a DPAYou own your data. We never sell it, and we do not use your operational data to train AI models. We collect only what the platform needs to function, and we honour data subject rights in line with EU GDPR and UK GDPR.
A Data Processing Agreement is available to every customer on request.
When you use Threatwhere's AI capabilities, your questions, the context drawn from your own data, and the responses you receive are treated as your confidential data, held in the UK and EU and available only to your authorised users.
We do not use your AI interactions to train AI models.
Engineered to stay available when it matters most.
Enterprise-grade denial-of-service mitigation protects the platform at the network edge.
The platform is monitored continuously, with automatic failover if a component fails.
Stored data is backed by point-in-time recovery, so it can be restored to any moment.
Deployments are engineered to be zero-downtime — the intelligence you depend on stays available.
Our security programme is built around the controls and principles that underpin SOC 2 and ISO 27001, and our privacy practices align with EU and UK GDPR.
Built around the controls and principles that underpin SOC 2.
Information security aligned to ISO 27001 standards and principles.
Privacy practices aligned with both EU GDPR and UK GDPR.
Clear answers to the questions our customers' security, risk, and procurement teams ask most.
For a Data Processing Agreement, security documentation, or to complete a security questionnaire, contact our security team and we will provide everything your risk and compliance teams need.