Built to stand up to procurement, security review, and regulator scrutiny.
Vantage Point runs inside regulated firms, on regulated firms' data. Our own security posture matters as much as our features. Here is what we do, where we stand today, and who to contact.
What we do, and where we stand.
Four groups: data, access, standards, law. Each row is a fact you can hold us to; anything still to be published says so.
Data
Where customer data lives, how it is protected, and how long it stays.
- Residency
- Your own region: UK data in the UK, EU data in the EU, US data in the US. Data does not leave it. Transfers outside that region require documented basis + customer approval.
- Encryption in transit
- Current TLS for all traffic, customer and service-to-service.
- Encryption at rest
- Managed backing-store encryption. Backups equivalently encrypted.
- Retention & deletion
- Per customer contract. Portable export + scheduled deletion on termination.
Access
Who can see what, inside the platform and inside Vantage Point, and how that is proved.
- Access model
- Role-based, entity-scoped. Polymorphic ownership: entity, group, or org.
- Single sign-on
- SAML SSO on every tier. MFA & deprovisioning follow your IdP.
- Production access
- Named engineers only. Reviewed and logged. Customer data accessed only on explicit request or for incident response.
- Audit trail
- Every record change timestamped, attributed, retained, exportable for regulator review.
Standards
What we are certified to, what we are aligned with, and what we can hand a reviewer.
- ISO/IEC 27001
- Certified. Information-security management system in place; the controls shape access, change management, and logging.
- ISO 31000
- Aligned. Risk-management framework informs our own risk register and the platform’s.
- ISO 37301
- Aligned. Compliance-management-system structure informs how obligations and controls connect.
- Certificate
- ISO/IEC 27001, certified. Certifying body, certificate number and scope available on request from security@vantagepointgrc.com.
- Questionnaires
- SIG Lite, CAIQ, and bespoke due-diligence responses available under NDA.
Law
Who is responsible for the data, and under which law.
- Controller
- Vantage Point Limited, Jersey-registered.
- Applicable law
- UK GDPR and Data Protection (Jersey) Law 2018.
- DPA
- Standard Data Processing Agreement available on request.
- Subprocessors
- List maintained and provided under NDA. Changes notified in advance.
Reporting and contact.
- Security
- security@vantagepointgrc.com
Vulnerability reports, suspected incidents, questions a sales rep can’t answer. Acknowledged within one business day.
- Data protection
- privacy@vantagepointgrc.com
Subject access requests, DPA amendments, data-processing questions.
The documentation behind the summary.
- HubSecurity & privacy hub: the documentation set your due diligence needs
- DocsInfrastructure and development security: hosting, encryption, backups, release process
- DocsGDPR and data protection compliance: roles, the DPA, transfers, data-subject rights
- DocsSub-processors and the DPA: how to obtain the list and the agreement
- DocsVulnerability disclosure: how to report, scope, what we commit to
- DocsSecurity & privacy FAQs: the questions procurement, CISOs and DPOs ask
- ModuleAudit trail: every compliance record change timestamped, attributed, exportable