Legal
Security
Last updated: 8 July 2026
Security is core to what PilotVantage does — we're a compliance platform, so we hold ourselves to the practices we help our customers implement. This page summarises how we protect your data. For contractual data-protection terms, see our Data Processing Agreement.
Hosting & data residency
- Customer data is hosted in the United Kingdom on infrastructure provided by DigitalOcean, LLC (London, United Kingdom (DigitalOcean LON1)).
- Each customer organisation's data is logically isolated in its own database schema (multi-tenant isolation), so one customer cannot access another's data.
- Encrypted backups are taken regularly and retained on a rolling cycle to support recovery.
Encryption
- In transit: all traffic is served over HTTPS/TLS.
- At rest: data is stored on encrypted infrastructure; passwords are stored only as salted hashes and are never recoverable in plain text.
- Payment card data is handled directly by Stripe (PCI-DSS Level 1) and never touches our servers.
Access control & authentication
- Two-factor authentication (2FA) is supported for all users and enforced for administrator and platform accounts.
- Role-based access control lets you scope what each user can see and do; access to data follows least-privilege principles.
- Account protection: automatic lockout after repeated failed logins helps defend against brute-force attacks.
- Internal administrative access to production is restricted to authorised personnel on a need-to-know basis.
Operational security
- Audit logging records key actions across the platform for accountability and investigation.
- Production servers are protected by a firewall, rate limiting and intrusion-prevention (fail2ban) at the network edge.
- We apply security patches to our operating systems and dependencies on an ongoing basis.
- Maintenance is performed with care to preserve availability, with a maintenance page shown during brief deploys.
Data protection & privacy
- We process personal data in line with the UK GDPR and the Data Protection Act 2018 — see our Privacy Policy.
- We act as your data processor for the data you enter into the platform, under our DPA, and maintain a published list of sub-processors.
- You can export your organisation's data, and we delete or anonymise it after account closure in line with our stated retention periods.
Frameworks
PilotVantage is built around the controls it helps customers manage, and our internal practices are aligned with ISO 27001. We'll update this page as our certification and assurance posture matures. If you need a security questionnaire completed or supporting documentation for your vendor assessment, we're happy to help — contact us below.
Report a vulnerability
If you believe you've found a security vulnerability, please email security@pilotvantage.com with details so we can investigate. Please act in good faith, avoid accessing or modifying other users' data, and give us a reasonable time to respond before any public disclosure.
Contact
Security enquiries: security@pilotvantage.com
Privacy enquiries: privacy@pilotvantage.com