Trust Center

Security is the foundation of what we build.

Approaching Summit works with some of the most sensitive data an organisation has — reporting lines, internal communications, and strategic context. Here's how we protect it today, and where we're headed as we grow.

At a Glance

Built on established security fundamentals.

Encryption everywhere

Data is encrypted in transit and at rest, with access limited to what each system actually needs.

Least-privilege access

Role-based access control and MFA govern who can reach production data and systems.

Vetted infrastructure

We build on cloud infrastructure with independently audited physical and network security.

Privacy by design

GDPR-aligned data handling, minimal retention, and a clear deletion policy for every customer.

Security Controls

The controls we hold ourselves to.

This is the same checklist a B2B security review would use. We're publishing it before we hold SOC 2 or ISO 27001 certification, because our customers shouldn't have to wait for an audit to know where we stand.

Encryption in transit

All traffic between your browser, our application, and our infrastructure is encrypted with TLS 1.2+.

In place

Encryption at rest

Customer data is encrypted at rest using provider-managed AES-256 encryption.

In progress

Key management

Encryption keys are managed through a cloud key management service, not handled manually.

In progress

Secrets management

API keys and credentials live in a managed secrets store and are never committed to source control.

In progress

Tenant data isolation

Each customer's organisational data is logically isolated from every other customer's.

In progress

Multi-factor authentication

MFA is enforced on all internal systems that touch customer data.

In progress

Single sign-on (SSO / SAML)

Enterprise customers can enforce their own identity provider for their users.

Planned

Role-based access control

Access to customer data is scoped by role rather than granted broadly by default.

In progress

Least-privilege production access

Engineers gain production access only when needed, not as a standing default.

In progress

Periodic access reviews

Access to internal systems is reviewed on a recurring cadence and revoked promptly on offboarding.

Planned

Audited cloud infrastructure

We run on cloud infrastructure whose physical and network security is independently audited.

In progress

Network segmentation

Production systems are isolated from development and staging environments.

In progress

DDoS & edge protection

Traffic is filtered at the edge before it reaches application servers.

In progress

Centralized logging & monitoring

Access and system events are logged centrally and monitored for anomalies.

In progress

Backups & disaster recovery

Data is backed up on a regular schedule with a documented, tested recovery process.

Planned

Secure development lifecycle

Code changes require review before merging to production.

In progress

Dependency & vulnerability scanning

Automated tooling flags known vulnerabilities in third-party packages.

In progress

Static analysis in CI

Static application security testing runs automatically on every change.

Planned

Independent penetration testing

A third-party firm tests the application at least annually.

Planned

Responsible disclosure

Security researchers can report issues to security@approachingsummit.com and expect a timely response.

In progress

GDPR-aligned processing

As an Ireland-based company, our data handling is built around GDPR principles from the start.

In progress

Data Processing Agreement

A DPA is available for every customer contract on request.

In progress

Data minimisation

We ingest only the organisational data needed to build your model — not a full copy of every connected system.

In progress

Retention & deletion

Customer data is deleted within a defined period after contract termination, on request.

In progress

Data subject request process

We have a defined process for handling access, correction, and deletion requests.

In progress

Disclosed sub-processor list

Every third party that touches customer data is listed and kept current — see below.

In place

No training on customer data

Customer data sent to AI providers is not used to train their foundation models.

In progress

Minimized AI data exposure

Only the data needed for a given analysis is sent to AI providers, scoped and access-controlled.

In progress

Contractual terms with sub-processors

Data protection terms are in place with every vendor that processes customer data.

In progress

Incident response plan

A documented plan defines how we detect, contain, and respond to security incidents.

In progress

Breach notification commitment

Customers are notified without undue delay in the event of a data breach.

In progress

Status & uptime visibility

A public status page tracks uptime and incidents.

Planned

Security awareness training

All employees complete security and privacy training.

Planned

Background checks

Employees with access to customer data undergo background screening.

Planned

Confidentiality agreements

All staff and contractors are bound by confidentiality obligations.

In progress

Authentication audit logs

Every sign-in, failed sign-in, password reset, and authentication event is logged with a timestamp and user identity.

Planned

Workspace activity history

Who created, edited, or deleted key organisational data — departments, people, priorities, technology, documents — and when, is recorded.

Planned

AI activity logging

AI requests are logged with timestamp, requesting user, and the sources consulted, without storing unnecessary prompt or personal data.

Planned

Administrative action logs

Privileged actions such as role changes, permission changes, workspace deletion, and API key rotation are logged.

Planned

Immutable records & retention policy

Audit logs cannot be modified or deleted by ordinary application users, and a defined policy governs how long they're retained and how they're securely deleted afterward.

Planned

Operational monitoring

Application errors, failed API requests, authentication failures, and infrastructure events are centralized so issues can be detected quickly.

Planned

Audit export & real-time alerts

Customers can export their audit history for compliance or investigations, and administrators are notified in real time of suspicious events such as repeated failed logins or unexpected permission changes.

Planned

Sub-processors

Every third party that touches customer data.

We keep this list current as we add or remove vendors. Rows marked in brackets still need to be filled in with the actual provider before this table is accurate.

VendorPurposeLocation
VercelApplication hosting, edge network, and web analyticsUnited States
ResendTransactional email delivery (e.g. demo request notifications)United States
Microsoft ClarityProduct analytics and session insightsUnited States
SupabasePrimary storage for customer organisational dataEU
OpenAIPowers organisational analysis and summarisation featuresUnited States

Compliance Roadmap

We don't hold SOC 2 or ISO 27001 today. Here's the plan.

Formal certification takes time to earn honestly. Rather than stay quiet about it, here's exactly where we are and what's next.

01

Foundations

In progressIn progress

The baseline controls every B2B buyer expects before they'll even discuss a security questionnaire.

  • MFA and least-privilege access enforced internally
  • Encryption in transit and at rest
  • Written InfoSec policy and incident response plan
  • Vendor / sub-processor risk review
02

Audit Readiness

TBDPlanned

Standing up the evidence trail an auditor will actually ask for, before booking one.

  • Compliance automation platform in place (e.g. Vanta, Drata, Secureframe)
  • Formal policy set (access control, change management, data handling)
  • Internal gap assessment against SOC 2 Trust Services Criteria
03

SOC 2 Type I

TBDPlanned

A point-in-time audit of control design — the fastest credible signal for enterprise sales conversations.

  • Independent CPA firm engaged
  • Controls audited as designed on a single date
04

SOC 2 Type II

TBDPlanned

Controls audited for operating effectiveness over an observation window — what most enterprise contracts actually require.

  • ~6 months of evidence collected under the Type I controls
  • Independent audit of operating effectiveness
05

ISO 27001

ConditionalPlanned

Pursued if EU, enterprise, or government demand specifically requires it — typically after SOC 2, not instead of it.

  • Scoping decision based on customer/region demand
  • ISMS build-out and certification audit