For security & procurement reviews

Trust & security

The questions a review asks, answered up front — including the honest ones.  ·  Last updated 4 August 2026.

At a glance

Hosting & residencyAmazon Web Services, eu-west-2 (London, UK) — storage, compute, authentication and email
AI processingAnthropic (text) and ElevenLabs (voice), as processors — content is not used to train their general models
PaymentsStripe — card details never touch CaseConduit systems
Sign-inManaged authentication (AWS Cognito); SAML / OIDC single sign-on available
DPAStandard data processing agreement included at every paid tier, on request
CertificationsNone held yet by CaseConduit itself — stated plainly below, with what we run on and what's planned

Hosting & data residency

CaseConduit runs entirely on Amazon Web Services in the eu-west-2 (London) region: your content and account data are stored there, the platform's compute runs there, and account emails are sent from there. Data is encrypted in transit (TLS) and at rest.

The exception is AI generation: when you ask the platform to generate or analyse something, the relevant content is sent to our AI processors, some of which operate outside the UK (in the United States), process it transiently to produce your output, and return the result. These transfers rely on the safeguards recognised under UK data-protection law (the UK International Data Transfer Agreement / Addendum). Full detail is in our privacy notice.

Sub-processors

We use a deliberately short list of providers, each bound to process data only on our instructions:

ProviderPurposeLocation of processing
Amazon Web ServicesHosting, storage, compute, authentication (Cognito), content delivery, account email (SES)UK (eu-west-2, London); CDN edge locations globally
AnthropicAI text generation and analysis of the content you submitUnited States
ElevenLabsText-to-speech voice synthesis for stories and simulationsUnited States / EU
StripePayment processing and billing for paid plansUnited States / EU (card data handled entirely by Stripe)

Under our AI providers' business terms, your content is not used to train their general-purpose models — it is processed only to produce the output you requested. Site pages also load fonts and icon libraries from public CDNs (Google Fonts, cdnjs, unpkg), which see standard web-request metadata such as IP addresses but none of your content.

Retention & deletion

  • Your content and library — kept until you delete it or close your account.
  • Account and profile data — deleted within 30 days of account closure, except where the law requires retention.
  • Technical and security logs — retained up to 12 months.
  • Self-serve, not by ticket: signed-in users can view, export and permanently delete their data themselves from the MyData panel in their workspace — no request needed.

Security practices

  • TLS everywhere; stored data encrypted at rest by AWS.
  • Serverless architecture — no long-lived servers to patch; the platform is static content plus managed AWS services.
  • Managed authentication — passwords are handled by AWS Cognito and never stored by us in readable form; enterprise single sign-on (SAML / OIDC) is available so your identity provider stays in control.
  • API keys and secrets live server-side only — the browser never holds credentials for our AI providers; all AI calls route through our backend, which also enforces rate and usage caps.
  • Payment isolation — checkout and billing happen on Stripe's hosted pages; webhook messages are cryptographically verified.
  • Versioned storage — user-data storage keeps prior versions, so accidental deletions and overwrites are recoverable.
  • Protected case viewer — cases delivered to learners render in a protected, watermarked viewer that blocks downloading and casual copying. We say honestly: no web viewer can make content impossible to capture (a phone camera exists); ours raises the effort and marks every page with the viewer's identity.

Certifications & testing — the honest answer

CaseConduit itself does not yet hold Cyber Essentials, ISO 27001 or a third-party penetration test report. We'd rather tell you that than let you find it in question 40 of a questionnaire. Three things are true alongside it:

  • The infrastructure everything runs on — AWS — holds ISO 27001, SOC 1/2/3, Cyber Essentials Plus and the rest of the usual alphabet; our serverless design means there is very little surface that isn't theirs.
  • Cyber Essentials certification is planned as our next formal step, with independent security testing to follow as the platform grows.
  • If your review needs specific answers in the meantime, email us — we answer security questionnaires in writing, from the people who built the system.

Data processing agreement

Every paid plan includes our standard data processing agreement on request — covering UK and EU GDPR processor obligations, the sub-processor list above, international-transfer safeguards and our security measures. Email us and we'll send it for countersigning. Bespoke DPA terms are available on the Enterprise plan.

Related reading: our privacy notice (the full data-protection picture, including your rights), accessibility statement, and terms of service.