Security Overview
Cyber Horizon Intelligence Ltd
Version 1.0 · Effective 31 August 2026 · Classification: Public
This overview summarises how we protect the confidentiality, integrity, and availability of the data entrusted to us. It is a public summary, and is not the internal Security Overview held in our ISMS, which is classified Confidential and released under NDA on request along with our detailed security policies and documentation. We continuously mature our security programme; where a control is being established rather than fully operational, we say so.
Data Protection
- Encryption of data in transit (TLS) and at rest (AES-256), provided by our managed infrastructure.
- Encrypted, managed backups with point-in-time recovery.
- Logical tenant isolation — Tenant isolation is enforced structurally: the organisation is resolved from the verified session, a tenant guard scopes every organisation-scoped query and stamps writes, and at the database layer row-level security is enabled on every table with no grants to the anonymous or authenticated roles — so there is no path to the data that bypasses the guard. Automated isolation tests run on every deploy.
Access Control
- Multi-factor authentication (MFA) is available to every user on every plan; single sign-on (SSO) via SAML 2.0 / OIDC is available on the Scale and Enterprise plans. We enforce MFA on our own platform-administrator accounts; whether MFA is mandatory for your users is a policy you set for your organisation.
- Role-based access control (RBAC) on a least-privilege basis.
- Access reviews and prompt revocation on role change or offboarding.
Hosting & Data Residency
Customer Data is stored in the European Union by default (Supabase, eu-west-1). Per-organisation regional residency in the United States, the United Kingdom and APAC is available on request; a dedicated regional project is provisioned before data is loaded. No managed region is currently available in the Middle East. Some processing takes place outside the EU — application hosting and serverless compute, identity management, AI features, transactional email, malware scanning of uploaded files, and encrypted off-site backups. Every sub-processor, the service it provides, the region in which it processes Customer Data and the transfer mechanism relied on are listed in Annex 3 of the DPA. Where processing takes place outside the UK or EEA, CHI applies the transfer safeguards set out in the DPA.
Application & Operational Security
- Secure development practices, peer code review, and separated development, staging, and production environments.
- Dependency and vulnerability scanning in our build pipeline; timely patching.
- Automated application and error monitoring with alerting.
- A documented incident-response process covering identification, containment, eradication, recovery, and post-incident review.
Compliance
- UK GDPR and EU GDPR compliance for personal data, backed by our Data Processing Agreement.
- ISO 27001 — controls aligned, certification targeted Q3 2027 (not yet certified).
- A limited set of vetted sub-processors, each bound by appropriate data-protection obligations.
Reporting & More Information
To report a suspected vulnerability, see our Vulnerability Disclosure Policy. For our security posture and to request detailed documentation, visit the Trust Centre or contact security@cyberhorizon.co.
- Version
- 1.0
- Effective
- 31 August 2026
- Last reviewed
- 31 August 2026
- Next review
- 31 August 2027
- Classification
- Public