Safeli
DemoPricingLogin

GOVERNANCE

Information Security Policy

This policy describes the information security controls Safeli Limited applies to protect client data and systems. It is published in support of our due-diligence obligations to clients and regulators.

Version 1.0 — 27 August 2026

1. Purpose and scope

This Information Security Policy sets out the standards and controls Safeli Limited applies to protect the confidentiality, integrity and availability of all data it processes on behalf of clients (Reiss and others) as well as its own operational data. It applies to all Safeli staff, contractors, assessors and sub-processors with access to Safeli systems or client data.

2. Roles and responsibilities

Overall responsibility for information security rests with Safeli management. A named individual acts as the security lead accountable for maintaining this policy, monitoring controls, and coordinating incident response. All staff and contractors are required to complete security awareness practices commensurate with their role and to report suspected security incidents immediately.

3. Encryption

All data is encrypted in transit using TLS (Transport Layer Security). All data at rest is encrypted using AES-256. Encryption and key management are maintained by Safeli’s managed cloud provider (Base44), which operates ISO/IEC 27001:2022 certified infrastructure.

4. Access control

Access to client data is governed by role-based permissions (admin, consultant, client) with per-site scoping. Each user only sees the sites and records they are explicitly assigned to. User accounts are created by invitation only. Multi-factor authentication is enforced through Google or Microsoft single sign-on, or email and password with one-time passcode (OTP) verification. Access is reviewed on a regular basis and revoked promptly on role change or departure.

5. Audit logging

Every assessment, action and status change is timestamped and recorded in a complete audit log. Login events and key administrative actions are logged. Audit logs are retained in line with the hosting provider’s retention controls and are available for client and regulator review on request.

6. Data hosting and transfers

Safeli data is hosted on certified cloud infrastructure in the United States (Base44 managed cloud, Builder plan). As data is stored outside the UK/EU, Standard Contractual Clauses (SCCs) together with the UK Addendum apply under the Base44 Data Processing Agreement. Sub-processors are bound by DPAs using SCCs, adequacy decisions or the Data Privacy Framework. The full sub-processor list is maintained at base44.com/dpa.

7. Data portability and deletion

Clients may export their reports as branded PDFs and their records as a spreadsheet at any time. On termination, Safeli provides a full export of client data and deletes all records and accounts, revoking access cleanly. Individual records may be deleted on request at any time; backups are overwritten in the provider’s normal cycle.

8. Vulnerability management and testing

Safeli relies on its hosting provider’s periodic penetration testing and vulnerability assessments performed by external auditors under an ISO/IEC 27001:2022 certified security programme. Security patches and updates are applied by the managed cloud provider. Staff and contractors are required to keep devices used to access Safeli systems patched and protected.

9. Business continuity and backups

Managed backups and data redundancy are provided by the Base44 managed cloud platform, supporting recovery in the event of failure. Safeli maintains procedures to restore access to client data and services in line with the provider’s recovery objectives.

10. Policy review

This Information Security Policy is reviewed at least annually and updated whenever there is a material change to Safeli’s systems, services, or regulatory obligations. The current version date is 27 August 2026.

Safeli

Commercial Compliance. Done Properly.

The modern alternative to clipboard compliance and spreadsheet audits - software that tracks every obligation, backed by people who know your buildings.

Nottinghamshire·Lincolnshire

Platform

  • Live Demo
  • Pricing
  • Client Login
  • Contact Us

Resources

  • Security & IT
  • Privacy Notice
  • Terms
  • DPA
  • Info Security Policy
  • Incident Response Policy

Get in touch

  • 0330 043 3501
  • WhatsApp
  • hello@safeli.co.uk

Email answered 24/7 · Site visits Mon-Sat

Safeli Limited is a company registered in England and Wales. Company number: 16932254. Registered office: 11 Woodland Walk, Newark, NG23 7QX.

© 2026 Safeli. All rights reserved.

Chat for a quote