GOVERNANCE
This policy describes the information security controls Safeli Limited applies to protect client data and systems. It is published in support of our due-diligence obligations to clients and regulators.
This Information Security Policy sets out the standards and controls Safeli Limited applies to protect the confidentiality, integrity and availability of all data it processes on behalf of clients (Reiss and others) as well as its own operational data. It applies to all Safeli staff, contractors, assessors and sub-processors with access to Safeli systems or client data.
Overall responsibility for information security rests with Safeli management. A named individual acts as the security lead accountable for maintaining this policy, monitoring controls, and coordinating incident response. All staff and contractors are required to complete security awareness practices commensurate with their role and to report suspected security incidents immediately.
All data is encrypted in transit using TLS (Transport Layer Security). All data at rest is encrypted using AES-256. Encryption and key management are maintained by Safeli’s managed cloud provider (Base44), which operates ISO/IEC 27001:2022 certified infrastructure.
Access to client data is governed by role-based permissions (admin, consultant, client) with per-site scoping. Each user only sees the sites and records they are explicitly assigned to. User accounts are created by invitation only. Multi-factor authentication is enforced through Google or Microsoft single sign-on, or email and password with one-time passcode (OTP) verification. Access is reviewed on a regular basis and revoked promptly on role change or departure.
Every assessment, action and status change is timestamped and recorded in a complete audit log. Login events and key administrative actions are logged. Audit logs are retained in line with the hosting provider’s retention controls and are available for client and regulator review on request.
Safeli data is hosted on certified cloud infrastructure in the United States (Base44 managed cloud, Builder plan). As data is stored outside the UK/EU, Standard Contractual Clauses (SCCs) together with the UK Addendum apply under the Base44 Data Processing Agreement. Sub-processors are bound by DPAs using SCCs, adequacy decisions or the Data Privacy Framework. The full sub-processor list is maintained at base44.com/dpa.
Clients may export their reports as branded PDFs and their records as a spreadsheet at any time. On termination, Safeli provides a full export of client data and deletes all records and accounts, revoking access cleanly. Individual records may be deleted on request at any time; backups are overwritten in the provider’s normal cycle.
Safeli relies on its hosting provider’s periodic penetration testing and vulnerability assessments performed by external auditors under an ISO/IEC 27001:2022 certified security programme. Security patches and updates are applied by the managed cloud provider. Staff and contractors are required to keep devices used to access Safeli systems patched and protected.
Managed backups and data redundancy are provided by the Base44 managed cloud platform, supporting recovery in the event of failure. Safeli maintains procedures to restore access to client data and services in line with the provider’s recovery objectives.
This Information Security Policy is reviewed at least annually and updated whenever there is a material change to Safeli’s systems, services, or regulatory obligations. The current version date is 27 August 2026.