Your business data — and your own customers' or tenants' information — is exactly the kind of data that has to be looked after properly. This page explains, in plain terms, the measures we take to protect it. We follow a defence-in-depth approach: several independent layers of protection, so no single failure exposes your data.
Your data is hosted in the United Kingdom by Fasthosts, whose data centres are certified to ISO/IEC 27001 — the international standard for information-security management. Keeping data in the UK also means it stays within UK data-protection law.
In transit: every connection to our apps is protected with HTTPS/TLS encryption, so information moving between your device and our servers can't be read along the way. If anyone tries to reach the app over an unencrypted (http) address, they're immediately redirected to the secure (https) version, and their browser is told to use the secure connection every time after that — so data is never sent unprotected.
At rest: our backups are encrypted with AES-256 (the same class of encryption used by banks and governments), and the key that unlocks them is held only by us — a backup copy on its own is useless to anyone else.
Our apps are built so that each customer's information is isolated. Every record is tied to the account that owns it, and the system only ever returns your own data to you. One customer can never see, or reach, another customer's information — and that separation is preserved in our backups too.
Your data is backed up automatically every hour, with a full daily server image, using Acronis Cyber Protect. Backups are encrypted, stored off-site from the live server, and retained so we can recover from an earlier point if ever needed. Database backups are taken cleanly and consistently, so a restore brings everything back intact.
Our application code has been through an in-depth security review, including adversarial (red-team-style) verification, and is hardened against common web-application attacks. Every change to the live system is reviewed and logged before it goes out, so nothing reaches your data unchecked.
Card payments are handled by Stripe, a global PCI-DSS-certified payment provider. We never see or store your full card details.
We handle personal data in line with the UK GDPR and the Data Protection Act 2018, and we're registered with the Information Commissioner's Office (ICO) under reference ZC188926. When you use our apps to store information about your own clients or tenants, you remain in control of that data and we act as your data processor. Full details are in our Privacy Policy.
Security isn't a one-off task — it's something we maintain. We review our protections regularly and strengthen them as new threats emerge and best practice moves on. Your data is protected by multiple independent safeguards working together, and we treat it with the same care we'd expect for our own.
If you have any questions about security or data protection, email us at info@azurydigital.co.uk.