Security and privacy at Vantage Point.
Regulated firms put their compliance function in Vantage Point. Everything your due diligence needs to see is here: how the service is built and run, where data lives, how we meet data-protection law, and who to ask.
Certified where it counts. Aligned everywhere else.
A compliance platform has to hold itself to the discipline it sells. Certificate details are on the security page.
- ISO/IEC 27001 certified: information security management, with the controls shaping access, change management and logging.
- Aligned with ISO 31000 and ISO 37301: the risk and compliance-management structures inform our own registers and the platform’s.
- Customer data hosted in the customer's own region (UK in the UK, EU in the EU, US in the US), and it stays there.
- Role-based, entity-scoped access with SAML single sign-on on every tier.
- Every record change timestamped, attributed, retained and exportable for regulator review.
- A standard data processing agreement, sub-processor list and due-diligence questionnaires available under NDA.
An experienced team.
Vantage Point’s founders have spent years running infrastructure and security for other firms. We built and run SystemLabs, a Jersey managed service provider, and we run Vantage Point’s estate the way we would run a client’s.
Steve Quinn, CEO
Steve co-founded SystemLabs in Jersey in 2018 and still runs it: a managed service provider responsible for the infrastructure, security and cloud estates of firms across the island. Keeping other people’s systems secure, patched and recoverable has been the day job for years.
He leads Vantage Point’s strategy and direction, and the security posture described on these pages is his to answer for. The estate Vantage Point runs on is run the way SystemLabs runs a client’s.
Jamie McDonald, CTO
Jamie co-founded SystemLabs with Steve and leads its engineering: the team, the architecture and the delivery discipline behind the platform SystemLabs runs its own operations on.
At Vantage Point he owns the product’s architecture and engineering, so secure development, code review and the release gates are part of how the product is built rather than a layer added afterwards.
Ask the people who run it.
Questionnaires, the data processing agreement, penetration-test summaries and the sub-processor list are available under NDA. Anything your due diligence still needs, ask us directly and you will hear back within one business day.