Skip to content

Security & privacy FAQs

The questions we get asked in due diligence, answered the way we answer them in the room. The full specification is on the security page.

2 min readUpdated 16 August 2026

Does Vantage Point hold security certifications?

Yes. Vantage Point is ISO/IEC 27001 certified (information security management), and is built and run in alignment with ISO 31000 (risk management) and ISO 37301 (compliance management systems), whose structure informs how obligations and controls connect in the product. Certificate details are on the security page; due-diligence questionnaires (SIG Lite, CAIQ, bespoke) are available under NDA.

Where is customer data hosted?

Microsoft Azure, in the customer’s own region: UK data in the UK, EU data in the EU, US data in the US, and it stays there. Transfers outside that region require a documented basis and the customer’s approval.

How is data encrypted?

Current TLS for all traffic, customer-facing and service-to-service. Managed encryption of the backing stores at rest, with backups encrypted equivalently.

Who at Vantage Point can see customer data?

Named engineers only, with access reviewed and logged. Customer data is accessed only on the customer’s explicit request or for incident response.

How do we control access within the platform?

Access is role-based and entity-scoped: a user sees the entities they are scoped to and nothing else, with ownership at entity, group or organisation level. Client-board access is per entity where you run a book.

Do you support single sign-on and multi-factor authentication?

SAML single sign-on is on every tier: Microsoft Entra ID or any SAML identity provider. MFA, session policy and deprovisioning follow your identity provider.

Is there an audit trail?

Every record change is timestamped, attributed and retained, and it is exportable for regulator review. The trail is part of the platform, not a log we keep on the side.

Who owns the data, and how do we get it back?

You do. Every register and report exports to Excel in one click at any time. On termination, data is exported to you on request and deleted on the schedule set in the contract.

What is the applicable data-protection law, and who is the controller?

Vantage Point Limited, Jersey-registered, is the controller for this website and our contact with you, and the processor for data in the service. The Data Protection (Jersey) Law 2018 applies, and the UK and EU GDPR where they apply. A standard data processing agreement is available on request.

Which sub-processors do you use?

The list is maintained and provided under NDA, and changes are notified in advance. On this website: Microsoft Azure (hosting, and the forms), Azure Communication Services (transactional email, including what the forms send us) and Google Analytics (only with your consent).

How do we report a security concern?

Email security@vantagepointgrc.com. Vulnerability reports, suspected incidents and questions a sales rep cannot answer are acknowledged within one business day.

Questions: security@vantagepointgrc.com for security,privacy@vantagepointgrc.com for data protection.