A Sticklebrick robot kneels beside a connector seam, placing a glowing blue padlock-shield over the join.
— Trust & Security
How a consultancy keeps your data safe

Trust lives in the join.

We are a consultancy, not a platform — so the security story is not about our software. It is about how we vet the AI partners we recommend, how we contract them on your behalf, how we build the integration that connects them to your systems, and how we leave the whole thing aligned with the ISO 9001, 14001 and 45001 posture you already hold. This page tells you what’s in place today, what’s in flight, and where we’ll be next year.


— 01 Compliance roadmap

What we’ve done. What’s next.

SOC
● In progress

SOC 2 Type II

Programme in flight. Type I attestation expected Q3 2026; Type II observation period running through 2026.

ISO
● Roadmap 2027

ISO 27001

Information security management system scoped. Certification audit planned H1 2027.

UK
● Live

UK GDPR · DPA

Standard DPA template available pre-signature. UK data residency by default; EU regions on request.

CE+
● Live

Cyber Essentials Plus

Certified. Renewed annually. The baseline UK assurance most FM tenders specify.

— 02 Six security pillars

How the work actually holds.

S—01
Encryption

Encryption in transit and at rest.

TLS 1.3 between every component. AES-256 at rest in customer regions. Per-tenant encryption keys. Customer-managed keys (BYOK) available on Enterprise — revoke a key, revoke access, immediately.

S—02
Identity

SSO and least-privilege by default.

SAML 2.0 and OIDC SSO available on all paid tiers. SCIM provisioning. Role-based access control with workspace isolation. MFA enforced for all administrative actions.

S—03
Integrations

Every join scoped, encrypted, audited.

OAuth or service-account scoping per system — we only read and write the fields you explicitly approve. Field-level redaction at the integration boundary for PII and commercial data. Specialist SaaS security partners harden each connector.

S—04
Audit trail

Every action recorded. Every action reversible.

Tamper-evident audit log of every read, write, and human review action — with the prompt, the model, the operator and the affected records. Streamed to your SIEM on Enterprise. One-click rollback on writes.

S—05
Data handling

Your data is not training data.

Customer data is never used to train any model, ours or a third party’s. Default retention is 30 days for debugging, configurable down to zero on Enterprise. Models can be pinned to zero-retention provider endpoints.

S—06
Incident response

A response process, written down.

24/7 on-call rotation. Customer notification within 24 hours of confirmed incident. Quarterly tabletop exercises. Status page at status.sticklebrick.com. Post-mortems published for any P0 / P1 event.

— 03 How an integration works

A join, in plain English.

  1. 01

    Scoped connection

    You approve which fields Sticklebrick can read and write — per system, per workspace. Nothing else is exposed.

  2. 02

    Boundary redaction

    PII, commercial fields and customer identifiers are masked at the source side of the integration before they leave your perimeter.

  3. 03

    Encrypted transport

    TLS 1.3 with certificate pinning between the connector and the platform. Outbound calls only — never callbacks into your network.

  4. 04

    Reversible writes

    Every write is logged with a one-click reverse. High-stakes writes (customer comms, financial postings) require human approval by default.

  5. 05

    Streamed audit

    Every event is hashed into the tamper-evident audit log and streamed to your SIEM in near real time.

// integration audit log ● live
cafm.read scope=workorders200 · scoped
telematics.read scope=location200 · redacted
customer.write draft=true405 · review
finance.read scope=invoice200 · masked
workorder.write rev=#84210200 · reversible
audit.stream → siem.acme.com200 · hashed
→ tamper-evident chain ok 200
— 04 Sub-processors

Who handles what. Where.

A current list of third parties that may process customer data on our behalf. We’ll notify customers in writing 30 days ahead of any addition.

Provider Purpose Region Certifications
Amazon Web Services Application hosting, primary storage UK (eu-west-2) SOC 2 · ISO 27001 · UK G-Cloud
Anthropic Foundation model inference (zero-retention) EU / US SOC 2 · zero retention
OpenAI Foundation model inference (zero-retention) EU / US SOC 2 · zero retention
Datadog Observability and performance monitoring EU (Frankfurt) SOC 2 · ISO 27001
Stripe Billing and invoicing UK / EU SOC 2 · PCI DSS L1
Okta (Auth0) Identity and SSO EU (Frankfurt) SOC 2 · ISO 27001

Last reviewed · May 2026 · Subscribe to changes at security@sticklebrick.com

— 05
Data residency

UK-first. Optionally EU.

Customer data is pinned to a single region per tenant. UK is the default; EU regions are available on request. Cross-region transfer requires explicit customer opt-in — we won’t move your data without telling you first.

For regulated buyers, we can deploy into your own VPC so that customer data never leaves your network at all, with the platform running as a private deployment under your encryption keys.

UK

London (eu-west-2)

Default region. UK GDPR compliant. All customer data, audit logs and backups remain in-region.

EU

Frankfurt (eu-central-1)

EU residency option. Same security posture, GDPR adequacy decision applies.

VPC

Customer VPC (Enterprise)

Private deployment inside your AWS / Azure / GCP account. Customer-managed keys, your network, your logs.

— Security pack

For procurement. Sent within one day.

Pre-prepared answers to your CISO questionnaire, our DPA template, a current sub-processor list, a network diagram, and the most recent penetration-test summary. NDA available on request.

Request the security pack security@sticklebrick.com

See it on your stack.

The fastest way to evaluate Sticklebrick is the 10-minute data readiness assessment, followed by a 20-minute working call. We’ll tell you straight what we can connect and what we can’t.

Start free assessment Book a 20-minute call