Uncompromising customer data management.
Your financial data is your most critical asset. We do not just 'store' it; our entire architecture is engineered around a single principle: providing the strongest possible data isolation, encrypted end-to-end.
Our core technical whitepaper
The "Security Architecture & Data Governance Overview" is our primary transparency asset, detailing our multi-layered 'Defence-in-Depth' approach and 'Secure by Design' philosophy.
Database-per-tenant architecture
We deliberately reject shared-schema databases. iplicit provisions every customer with their own dedicated, logically separate database instance. This architectural decision completely eliminates the possibility of cross-tenant data leakage at the database layer.
Future-Proofed for the UK Data (Use and Access) Act 2025 (DUAA)
Our highly indexed Database-per-Tenant architecture enables rapid, automated data isolation and collation. This allows your organisation to fully meet the aggressive new statutory 15-day Subject Access Request (SAR) deadlines easily without operational downtime or panic.
Physical Data Eradication: At contract termination, data hygiene does not rely on risky row-level software filters. The customer’s dedicated database container is physically dropped and permanently eradicated from live storage using verified cryptographic erasure key deletion.
The corporate jurisdictional shield
Because iplicit Limited is a 100% UK-owned entity governed solely by the laws of England and Wales, our contracts form a rigid corporate jurisdictional barrier against foreign data interception demands (e.g. the US CLOUD Act).
This legal protection is mathematically enforced: encryption keys are centralised in FIPS 140-2 validated Hardware Security Modules (HSMs) completely separated from the data layer. The underlying cloud provider holds only scrambled, unintelligible data, ensuring absolute extraterritorial denial.
Local productivity endpoint governance (Excel add-in)
Traditionally, localised financial plug-ins function as dangerous threat vectors for shadow IT or unauthorised data exfiltration. The iplicit Excel Add-In is explicitly restricted by design: it functions strictly as a directional data-retrieval mechanism. It holds zero processing permission to scan, read, or transmit arbitrary information or local cell formulas. Furthermore, it is directly bound to core application Role-Based Access Controls (RBAC)—preventing unauthorised extraction at the endpoint.
Traditionally, localized financial plug-ins function as dangerous threat vectors for shadow IT or unauthorized data exfiltration. The iplicit Excel Add-In is explicitly restricted by design: it functions strictly as a directional data-retrieval mechanism. It holds zero processing permission to scan, read, or transmit arbitrary information or local cell formulas. Furthermore, it is directly bound to core application Role-Based Access Controls (RBAC)—preventing unauthorized extraction at the endpoint.
AI Governance (ISO 23894 & 38507)
Formally aligned with ISO/IEC 23894:2024 for specialised algorithmic hazard identification, and ISO/IEC 38507:2022 for organisational overwatch controls.
Systems Engineering (ISO 15288)
Platform release mechanisms follow the rigorous stage-gated guidelines of ISO/IEC/IEEE 15288:2023 to balance agile iterations with strict safety gates.
Self-Regulation (ISO 19011)
Our multi-discipline internal audit program operates under strict ISO 19011 methodologies, ensuring proactive mitigation of compliance drift.
Our commitment to UK GDPR.
We are fully compliant with UK GDPR. We provide customers with a clear choice of data residency. All customer data, including backups, is processed and stored exclusively within your chosen geographical region (UK or EU).
Data is never moved outside this region without explicit customer consent. For all data privacy enquiries, contact our governance team at datacompliance@iplicit.com.
Data processing agreement
Data protection policy
Privacy policy
Subprocessors details
Need more detail?
For specific attestations, like our Penetration Test Summary or a pre-filled security questionnaire, please use our simple 'Trust Request' form. This is a low-friction verification step that avoids legal NDAs for most requests.
