How Redactics is built, where data lives, who can see it and what happens to it at the end. Certifications are listed with their real status, including those still in progress or planned.
Runs entirely on Microsoft Azure. No self-hosted servers, no other cloud providers in the processing path.
UK and EU processing options
Choose a UK or EU Azure region at onboarding. Storage, processing and model calls stay within it.
Encryption
TLS 1.2 or higher for every connection. Azure Storage encryption at rest with customer-managed key options on Enterprise.
Role-based access
Case-level permissions, reviewer and administrator roles, and single sign-on with Microsoft Entra ID.
Customer data segregation
Storage partitioned by customer and by request. No shared indexes, no cross-customer linking.
Audit logging
Append-only event log for every case: views, decisions, changes and exports, attributed and timestamped.
Retention controls
Retention periods per case type, set by you. Cases close with their evidence intact until the period ends.
Secure deletion
Deletion on request or at the end of retention, with a deletion certificate recorded in the audit log.
Human-controlled disclosure
Redactics suggests. Your reviewers decide. Nothing is disclosed without a named person's approval.
Subprocessor transparency
A published list of subprocessors, with region and purpose, and notice before any change.
Security overview
Available
How Redactics is designed, operated and monitored to protect the personal data it processes on your behalf.
Redactics is a multi-tenant platform built on Microsoft Azure. Every customer has a separate storage partition, separate encryption scope and separate access policy.
The processing pipeline runs in Azure Functions with no persistent compute. Each stage reads from and writes to the customer's partition and nowhere else.
Security is reviewed at every release. Changes to authentication, storage or the processing pipeline require a second engineer's approval before deployment.
Architecture
Available
Azure-native, asynchronous processing with storage partitioned by customer and request.
Ingestion: files are uploaded over TLS to Azure Blob Storage in the customer's chosen region and stored immutably for the life of the case.
Processing: Azure Functions orchestrate extraction (Azure AI Document Intelligence), detection (Azure AI Language, pattern rules and Azure OpenAI) and person resolution. Each stage is idempotent and logged.
Metadata: findings, people, decisions and audit events are stored in Azure Table Storage, partitioned by customer and request.
Application: the review workspace is a web application authenticated through Microsoft Entra ID or username and password with multi-factor authentication.
An architecture document with data flow diagrams is included in the procurement pack.
Data residency
Available
UK South and UK West, or EU regions, selected at onboarding and fixed for the tenant.
Customer data is stored and processed in the selected region only. Model calls use Azure OpenAI deployments in the same region.
Backups remain within the region pair. No customer data leaves the region for support, analytics or training.
Support staff access customer data only with the customer's written authorisation for a specific case, and every access is logged.
Encryption
Available
TLS 1.2 or higher in transit; AES-256 at rest with Azure Storage encryption.
All connections to Redactics and between Redactics components use TLS 1.2 or higher.
Data at rest is encrypted with AES-256 using Azure Storage Service Encryption. Enterprise customers can use customer-managed keys in their own Azure Key Vault.
Disclosure packages are encrypted separately with a per-package key and expire on a schedule the customer sets.
Access control
Available
Single sign-on, role-based access and case-level permissions.
Roles: administrator, case owner, reviewer and read-only auditor. Administrators manage users and settings but do not see case content unless assigned to the case.
Single sign-on with Microsoft Entra ID, including conditional access and group-based role assignment. Multi-factor authentication is required for local accounts.
Every access to source material is recorded with user, time and item in the case audit trail.
Audit logging
Available
Append-only case logs plus platform security logs retained for twelve months.
Case audit trails are append-only and exportable by the customer at any time.
Platform logs (authentication, administration and infrastructure events) are retained for twelve months and monitored for anomalies.
Customers can receive audit events into their own SIEM on the Enterprise tier.
Retention and deletion
Available
Retention per case type, set by you, with secure deletion and a certificate at the end.
Retention periods are configured per case type. Closed cases retain their evidence and audit trail until the period ends.
Deletion removes case content, findings and derived data from primary storage immediately and from backups within 30 days. A deletion certificate is recorded in the platform audit log.
Customers can request deletion of a case or a tenant at any time.
Subprocessors
Available
Microsoft Azure is the only infrastructure subprocessor. The full list is published here.
Microsoft Azure (UK or EU regions): hosting, storage, Document Intelligence, AI Language and Azure OpenAI. Microsoft does not use customer data to train models.
Transactional email provider: notification emails containing no case content.
Customers receive 30 days' notice before a subprocessor is added or changed.
Business continuity
Available
Regional redundancy within Azure, tested restore procedures and a published status page.
Storage is replicated within the region pair. Restore procedures are tested quarterly.
Recovery objectives: RPO of one hour and RTO of eight hours for the platform. Case data is never lost on a failed processing step; the step is retried from the immutable source.
Planned maintenance and incidents are published on the status page.
Data processing agreement
On request
A standard DPA under UK GDPR Article 28, with processor obligations built into the platform.
Redactics acts as processor. The customer is controller and makes every disclosure decision.
The DPA covers processing instructions, confidentiality, security measures, subprocessors, assistance with data subject rights, deletion and audit.
Public sector customers can use their own standard terms where required; we review them promptly.
DPIA support
Available
A DPIA template pre-populated with Redactics processing details, and time with our team to complete it.
The template describes the processing, the data flows, the lawful basis considerations and the risks and mitigations specific to Redactics.
Our team will work through the DPIA with your DPO and answer follow-up questions in writing.
Penetration testing
In progress
Independent penetration testing of the platform and the review application.
Independent testing is scheduled before general availability, and annually after that. A summary report will be available to customers under NDA once complete.
Findings are tracked to closure and re-tested.
Cyber Essentials
In progress
Cyber Essentials certification for Redactics Ltd.
Assessment is in progress. This page will be updated with the certificate number when issued.
Cyber Essentials Plus
Planned
Cyber Essentials Plus following Cyber Essentials.
Planned to follow Cyber Essentials certification. This page will be updated when the assessment is scheduled.
ISO 27001
Planned
ISO/IEC 27001 certification of the Redactics information security management system.
An ISMS aligned to ISO 27001 is in place. Certification is planned; this page will be updated when the audit is scheduled.
Service status
Available
Live platform status, incident history and planned maintenance.
Published on the status page, with email subscription for incidents and maintenance notices.
Accessibility
Available
WCAG 2.2 AA is the target for the review application and this website.
The accessibility statement describes the current level of conformance, known issues and how to report a problem.
The review application supports keyboard navigation, screen readers and reduced motion.
Human-controlled disclosure
By design
Redactics suggests. Your reviewers decide. Nothing is disclosed without a named person's approval.
The platform cannot release a disclosure package without a case owner's approval, and cannot record a disclosure decision without a reviewer. Automated steps are limited to collection, extraction, classification, resolution and suggestion, and every automated step is logged as such. See why human oversight matters.
Report a security issue
If you believe you have found a vulnerability in Redactics, email security@redactics.co.uk. We acknowledge reports within two business days and do not pursue good-faith researchers.
Get the procurement pack.
The architecture document, security overview, DPA, DPIA template, retention schedule, business continuity summary and accessibility statement.