Security Overview
Cyber Horizon Intelligence Ltd
Last Updated: 11 July 2026
This overview summarises how we protect the confidentiality, integrity, and availability of the data entrusted to us. It is a high-level summary for prospective and current customers; our detailed internal security policies and documentation are available to customers and prospects under NDA on request. We continuously mature our security programme; where a control is being established rather than fully operational, we say so.
Data Protection
- Encryption of data in transit (TLS) and at rest (AES-256), provided by our managed infrastructure.
- Encrypted, managed backups with point-in-time recovery.
- Logical tenant isolation — Tenant isolation is enforced by application- and database-level controls, including row-level database security scoped by a unique organisation identifier, designed to prevent cross-tenant access.
Access Control
- Multi-factor authentication (MFA) and single sign-on (SSO) via SAML/OIDC.
- Role-based access control (RBAC) on a least-privilege basis.
- Access reviews and prompt revocation on role change or offboarding.
Hosting & Data Residency
The primary data store for Customer Data is located in the European Union. CHI's sub-processors, the services they provide and the regions in which they process Customer Data are listed in the DPA. Where processing takes place outside the UK or EEA, CHI applies the transfer safeguards set out in the DPA.
Application & Operational Security
- Secure development practices, peer code review, and separated development, staging, and production environments.
- Dependency and vulnerability scanning in our build pipeline; timely patching.
- Automated application and error monitoring with alerting.
- A documented incident-response process covering identification, containment, eradication, recovery, and post-incident review.
Compliance
- UK GDPR and EU GDPR compliance for personal data, backed by our Data Processing Agreement.
- ISO 27001 — controls aligned, certification targeted Q3 2027 (not yet certified).
- A limited set of vetted sub-processors, each bound by appropriate data-protection obligations.
Reporting & More Information
To report a suspected vulnerability, see our Vulnerability Disclosure Policy. For our security posture and to request detailed documentation, visit the Trust Center or contact security@cyberhorizon.co.
- Version
- 1.0
- Effective
- 31 August 2026
- Last reviewed
- 31 August 2026
- Next review
- 31 August 2027
- Classification
- Public