1.Certifications and frameworks
Safe Space Technology Limited holds ISO 27001 and ISO 9001 certification, and is pursuing SOC 2 Type II certification.
The platform is mapped to healthcare-sector frameworks used by NHS and independent-sector procurement teams:
- NHS Data Security and Protection Toolkit (DSPT) — the annual self-assessment required for organisations that handle NHS patient data or systems.
- NHS Digital Technology Assessment Criteria (DTAC) — the NHS's standard evaluation framework for new digital products before deployment.
If you are running a procurement exercise and need certificate detail, DSPT evidence, DTAC submissions, or scope confirmation, ask us and we will provide it directly. We would rather answer that question properly than summarise it here.
2.Where your data lives
Safe Workplace runs on Amazon Web Services, and you choose the region. For most UK customers that means UK or EU hosting; for organisations with an international footprint it means data can sit where their own obligations require.
Region choice matters more than a blanket residency claim. A UK-only guarantee reads as a limitation to an organisation with an EU arm, and as an irrelevance to one without.
3.Encryption
Customer data is encrypted in transit and at rest. Traffic to and from the platform runs over TLS; stored data and backups are encrypted at rest using AES-256 via our hosting provider's encryption facilities.
4.Who can see your data
Access follows two principles, worth stating plainly because they are what security questionnaires are really asking about.
- Least privilege. People see what their role requires and nothing more. Case visibility is scoped by role, not granted by default.
- Tenant isolation. Your data is logically separated from every other customer's. One organisation cannot see another's records.
Users authenticate via SSO or magic-link email, so there are no long-lived passwords to manage or leak. SSO federates to your identity provider so joiners, movers and leavers reflect your existing HR/IT process.
Safe Workplace staff do not browse customer data. Access by our team happens only where it is necessary to deliver or support the service, and it is logged.
5.Anonymity and speak-up
This is the part that matters most in employee relations, and the honest answer is that it is your decision, not ours.
Anonymity is configurable per reporting channel. You decide whether a channel accepts anonymous reports, requires identification, or offers the reporter the choice. Different channels in the same organisation can be set differently — an anonymous whistleblowing line alongside a named grievance process, for example.
We are deliberately not making a blanket "everything is anonymous" claim. It would not be true of every configuration, and a promise that does not survive contact with the settings is worse than no promise at all. If anonymity is critical to your use case, raise it during implementation and we will configure for it explicitly.
6.Backups and recovery
These are contractual commitments, not aspirations. Under our customer terms we:
- create a back-up copy of customer data at least daily;
- retain each copy securely for a minimum of 30 days; and
- use all reasonable endeavours to restore from a back-up within one business day of a written request.
In practice we go further: point-in-time recovery lets us restore the database to any specific minute within the last 30 days. If you need a restore to a moment rather than a day, we can do that.
7.Sub-processors
We use a small number of sub-processors — hosting, transactional email, monitoring and our AI provider. Every sub-processor is named in our customer terms and data processing agreement, so you know exactly who is involved before you sign rather than afterwards.
Each has been vetted for data security and holds recognised security credentials. We do not add a sub-processor without notice, and you have the right to object to a change.
8.Testing and responsible disclosure
We run quarterly penetration testing. Findings are triaged and tracked to closure — the same discipline we ask our customers to apply to audit findings.
If you believe you have found a security issue, please email security@safework.place rather than testing further. We will acknowledge it and keep you updated, and we do not pursue researchers who report in good faith.
9.If something goes wrong
Our customer terms commit us to notifying you of any personal data breach affecting your data without undue delay and no later than 72 hours after we become aware of it — matching the UK GDPR standard.
Enterprise customers who need a tighter notification window can specify a shorter period on the Sales Order. In a regulated setting where you may have a duty of candour obligation running in parallel, we can commit to as little as 24 hours where the operational risk profile makes sense.
10.AI and your data
The clearest way to say it: your data is not used to train anyone's AI model, and it never leaves AWS.
Our AI features run on Anthropic's Claude models via Amazon Bedrock. Bedrock is a fully managed AWS service: prompts and completions stay inside your chosen AWS region, are not shared with Anthropic, and are not used to train any model. AWS's own commitment is explicit — customer data submitted to Bedrock is not used to improve base models, and it is not passed on to third-party model providers.
Three further points, because "we don't train on your data" is only part of what you should be asking:
- AI assists; it does not decide. Outcome decisions, credibility judgements and case outcomes stay with a named person. That is also what the CQC expects — see how the regulator views AI.
- Outputs are cited. Where the platform summarises or drafts, it points back at the source records, so a human can verify rather than trust.
- It can be turned off. AI features are configurable. If your organisation would rather not use them, they can be disabled.
11.Questions
Security questionnaires, certification detail (ISO 27001, ISO 9001, SOC 2 Type II status), DSPT evidence, DTAC submissions and procurement packs: email hello@safework.place and we will answer properly. If we cannot evidence something, we will tell you so rather than write around it.
Related: Privacy Policy · Terms of Use · Acceptable Use Policy
