Hosting & data residency
CaseConduit runs entirely on Amazon Web Services in the eu-west-2 (London) region: your content and account data are stored there, the platform's compute runs there, and account emails are sent from there. Data is encrypted in transit (TLS) and at rest.
The exception is AI generation: when you ask the platform to generate or analyse something, the relevant content is sent to our AI processors, some of which operate outside the UK (in the United States), process it transiently to produce your output, and return the result. These transfers rely on the safeguards recognised under UK data-protection law (the UK International Data Transfer Agreement / Addendum). Full detail is in our privacy notice.
Sub-processors
We use a deliberately short list of providers, each bound to process data only on our instructions:
| Provider | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services | Hosting, storage, compute, authentication (Cognito), content delivery, account email (SES) | UK (eu-west-2, London); CDN edge locations globally |
| Anthropic | AI text generation and analysis of the content you submit | United States |
| ElevenLabs | Text-to-speech voice synthesis for stories and simulations | United States / EU |
| Stripe | Payment processing and billing for paid plans | United States / EU (card data handled entirely by Stripe) |
Under our AI providers' business terms, your content is not used to train their general-purpose models — it is processed only to produce the output you requested. Site pages also load fonts and icon libraries from public CDNs (Google Fonts, cdnjs, unpkg), which see standard web-request metadata such as IP addresses but none of your content.
Retention & deletion
- Your content and library — kept until you delete it or close your account.
- Account and profile data — deleted within 30 days of account closure, except where the law requires retention.
- Technical and security logs — retained up to 12 months.
- Self-serve, not by ticket: signed-in users can view, export and permanently delete their data themselves from the MyData panel in their workspace — no request needed.
Security practices
- TLS everywhere; stored data encrypted at rest by AWS.
- Serverless architecture — no long-lived servers to patch; the platform is static content plus managed AWS services.
- Managed authentication — passwords are handled by AWS Cognito and never stored by us in readable form; enterprise single sign-on (SAML / OIDC) is available so your identity provider stays in control.
- API keys and secrets live server-side only — the browser never holds credentials for our AI providers; all AI calls route through our backend, which also enforces rate and usage caps.
- Payment isolation — checkout and billing happen on Stripe's hosted pages; webhook messages are cryptographically verified.
- Versioned storage — user-data storage keeps prior versions, so accidental deletions and overwrites are recoverable.
- Protected case viewer — cases delivered to learners render in a protected, watermarked viewer that blocks downloading and casual copying. We say honestly: no web viewer can make content impossible to capture (a phone camera exists); ours raises the effort and marks every page with the viewer's identity.
Certifications & testing — the honest answer
CaseConduit itself does not yet hold Cyber Essentials, ISO 27001 or a third-party penetration test report. We'd rather tell you that than let you find it in question 40 of a questionnaire. Three things are true alongside it:
- The infrastructure everything runs on — AWS — holds ISO 27001, SOC 1/2/3, Cyber Essentials Plus and the rest of the usual alphabet; our serverless design means there is very little surface that isn't theirs.
- Cyber Essentials certification is planned as our next formal step, with independent security testing to follow as the platform grows.
- If your review needs specific answers in the meantime, email us — we answer security questionnaires in writing, from the people who built the system.
Data processing agreement
Every paid plan includes our standard data processing agreement on request — covering UK and EU GDPR processor obligations, the sub-processor list above, international-transfer safeguards and our security measures. Email us and we'll send it for countersigning. Bespoke DPA terms are available on the Enterprise plan.
