Security is the foundation of what we build.
Approaching Summit works with some of the most sensitive data an organisation has — reporting lines, internal communications, and strategic context. Here's how we protect it today, and where we're headed as we grow.
At a Glance
Built on established security fundamentals.
Encryption everywhere
Data is encrypted in transit and at rest, with access limited to what each system actually needs.
Least-privilege access
Role-based access control and MFA govern who can reach production data and systems.
Vetted infrastructure
We build on cloud infrastructure with independently audited physical and network security.
Privacy by design
GDPR-aligned data handling, minimal retention, and a clear deletion policy for every customer.
Security Controls
The controls we hold ourselves to.
This is the same checklist a B2B security review would use. We're publishing it before we hold SOC 2 or ISO 27001 certification, because our customers shouldn't have to wait for an audit to know where we stand.
Encryption in transit
All traffic between your browser, our application, and our infrastructure is encrypted with TLS 1.2+.
Encryption at rest
Customer data is encrypted at rest using provider-managed AES-256 encryption.
Key management
Encryption keys are managed through a cloud key management service, not handled manually.
Secrets management
API keys and credentials live in a managed secrets store and are never committed to source control.
Tenant data isolation
Each customer's organisational data is logically isolated from every other customer's.
Multi-factor authentication
MFA is enforced on all internal systems that touch customer data.
Single sign-on (SSO / SAML)
Enterprise customers can enforce their own identity provider for their users.
Role-based access control
Access to customer data is scoped by role rather than granted broadly by default.
Least-privilege production access
Engineers gain production access only when needed, not as a standing default.
Periodic access reviews
Access to internal systems is reviewed on a recurring cadence and revoked promptly on offboarding.
Audited cloud infrastructure
We run on cloud infrastructure whose physical and network security is independently audited.
Network segmentation
Production systems are isolated from development and staging environments.
DDoS & edge protection
Traffic is filtered at the edge before it reaches application servers.
Centralized logging & monitoring
Access and system events are logged centrally and monitored for anomalies.
Backups & disaster recovery
Data is backed up on a regular schedule with a documented, tested recovery process.
Secure development lifecycle
Code changes require review before merging to production.
Dependency & vulnerability scanning
Automated tooling flags known vulnerabilities in third-party packages.
Static analysis in CI
Static application security testing runs automatically on every change.
Independent penetration testing
A third-party firm tests the application at least annually.
Responsible disclosure
Security researchers can report issues to security@approachingsummit.com and expect a timely response.
GDPR-aligned processing
As an Ireland-based company, our data handling is built around GDPR principles from the start.
Data Processing Agreement
A DPA is available for every customer contract on request.
Data minimisation
We ingest only the organisational data needed to build your model — not a full copy of every connected system.
Retention & deletion
Customer data is deleted within a defined period after contract termination, on request.
Data subject request process
We have a defined process for handling access, correction, and deletion requests.
Disclosed sub-processor list
Every third party that touches customer data is listed and kept current — see below.
No training on customer data
Customer data sent to AI providers is not used to train their foundation models.
Minimized AI data exposure
Only the data needed for a given analysis is sent to AI providers, scoped and access-controlled.
Contractual terms with sub-processors
Data protection terms are in place with every vendor that processes customer data.
Incident response plan
A documented plan defines how we detect, contain, and respond to security incidents.
Breach notification commitment
Customers are notified without undue delay in the event of a data breach.
Status & uptime visibility
A public status page tracks uptime and incidents.
Security awareness training
All employees complete security and privacy training.
Background checks
Employees with access to customer data undergo background screening.
Confidentiality agreements
All staff and contractors are bound by confidentiality obligations.
Authentication audit logs
Every sign-in, failed sign-in, password reset, and authentication event is logged with a timestamp and user identity.
Workspace activity history
Who created, edited, or deleted key organisational data — departments, people, priorities, technology, documents — and when, is recorded.
AI activity logging
AI requests are logged with timestamp, requesting user, and the sources consulted, without storing unnecessary prompt or personal data.
Administrative action logs
Privileged actions such as role changes, permission changes, workspace deletion, and API key rotation are logged.
Immutable records & retention policy
Audit logs cannot be modified or deleted by ordinary application users, and a defined policy governs how long they're retained and how they're securely deleted afterward.
Operational monitoring
Application errors, failed API requests, authentication failures, and infrastructure events are centralized so issues can be detected quickly.
Audit export & real-time alerts
Customers can export their audit history for compliance or investigations, and administrators are notified in real time of suspicious events such as repeated failed logins or unexpected permission changes.
Sub-processors
Every third party that touches customer data.
We keep this list current as we add or remove vendors. Rows marked in brackets still need to be filled in with the actual provider before this table is accurate.
| Vendor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting, edge network, and web analytics | United States |
| Resend | Transactional email delivery (e.g. demo request notifications) | United States |
| Microsoft Clarity | Product analytics and session insights | United States |
| Supabase | Primary storage for customer organisational data | EU |
| OpenAI | Powers organisational analysis and summarisation features | United States |
Compliance Roadmap
We don't hold SOC 2 or ISO 27001 today. Here's the plan.
Formal certification takes time to earn honestly. Rather than stay quiet about it, here's exactly where we are and what's next.
Foundations
The baseline controls every B2B buyer expects before they'll even discuss a security questionnaire.
- MFA and least-privilege access enforced internally
- Encryption in transit and at rest
- Written InfoSec policy and incident response plan
- Vendor / sub-processor risk review
Audit Readiness
Standing up the evidence trail an auditor will actually ask for, before booking one.
- Compliance automation platform in place (e.g. Vanta, Drata, Secureframe)
- Formal policy set (access control, change management, data handling)
- Internal gap assessment against SOC 2 Trust Services Criteria
SOC 2 Type I
A point-in-time audit of control design — the fastest credible signal for enterprise sales conversations.
- Independent CPA firm engaged
- Controls audited as designed on a single date
SOC 2 Type II
Controls audited for operating effectiveness over an observation window — what most enterprise contracts actually require.
- ~6 months of evidence collected under the Type I controls
- Independent audit of operating effectiveness
ISO 27001
Pursued if EU, enterprise, or government demand specifically requires it — typically after SOC 2, not instead of it.
- Scoping decision based on customer/region demand
- ISMS build-out and certification audit
Get in Touch