Skip to content
Security

Built to stand up to procurement, security review, and regulator scrutiny.

Vantage Point runs inside regulated firms, on regulated firms' data. Our own security posture matters as much as our features. Here is what we do, where we stand today, and who to contact.

SpecificationRev. 2026-04 · Public

What we do, and where we stand.

Four groups: data, access, standards, law. Each row is a fact you can hold us to; anything still to be published says so.

01

Data

Where customer data lives, how it is protected, and how long it stays.

Residency
Your own region: UK data in the UK, EU data in the EU, US data in the US. Data does not leave it. Transfers outside that region require documented basis + customer approval.
Encryption in transit
Current TLS for all traffic, customer and service-to-service.
Encryption at rest
Managed backing-store encryption. Backups equivalently encrypted.
Retention & deletion
Per customer contract. Portable export + scheduled deletion on termination.
02

Access

Who can see what, inside the platform and inside Vantage Point, and how that is proved.

Access model
Role-based, entity-scoped. Polymorphic ownership: entity, group, or org.
Single sign-on
SAML SSO on every tier. MFA & deprovisioning follow your IdP.
Production access
Named engineers only. Reviewed and logged. Customer data accessed only on explicit request or for incident response.
Audit trail
Every record change timestamped, attributed, retained, exportable for regulator review.
03

Standards

What we are certified to, what we are aligned with, and what we can hand a reviewer.

ISO/IEC 27001
Certified. Information-security management system in place; the controls shape access, change management, and logging.
ISO 31000
Aligned. Risk-management framework informs our own risk register and the platform’s.
ISO 37301
Aligned. Compliance-management-system structure informs how obligations and controls connect.
Certificate
ISO/IEC 27001, certified. Certifying body, certificate number and scope available on request from security@vantagepointgrc.com.
Questionnaires
SIG Lite, CAIQ, and bespoke due-diligence responses available under NDA.
04

Law

Who is responsible for the data, and under which law.

Controller
Vantage Point Limited, Jersey-registered.
Applicable law
UK GDPR and Data Protection (Jersey) Law 2018.
DPA
Standard Data Processing Agreement available on request.
Subprocessors
List maintained and provided under NDA. Changes notified in advance.
05 · ContactResponse SLA · 1 business day

Reporting and contact.

Security
security@vantagepointgrc.com

Vulnerability reports, suspected incidents, questions a sales rep can’t answer. Acknowledged within one business day.

Data protection
privacy@vantagepointgrc.com

Subject access requests, DPA amendments, data-processing questions.