We’re a security company, so we hold ourselves to the standards we give you. Here’s exactly what SSM collects from your endpoints — and what it never touches.
The line is drawn here, and it’s non-negotiable.
Our own infrastructure is certified Cyber Essentials. We eat our own dog food.
Lawful-basis documented per data category. Full DPA available on request.
All customer data stays in the United Kingdom. No third-country transfers without explicit consent.
DigiCert EV Extended Validation on a hardware USB token. SHA-384 + timestamp counter-signature.
Any confirmed breach disclosed within 72 hours, regardless of whether customer data is affected.
12-month default retention. Customer-configurable down to 30 days or up to 7 years.
We publish every third-party service that touches your data, what role it plays, and where it lives.
We’re happy to jump on a call with your InfoSec team, procurement or auditor. Nothing’s too technical or too simple to ask.