SECURITY
Decisity is engineered in line with the most rigorous international safety and security standards, so your strategy documents stay protected at every step.
Your data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. All uploaded documents and analysis outputs are stored in isolated, access-controlled environments within our cloud infrastructure.
Our access control architecture follows the principle of least privilege. Multi-factor authentication, role-based permissions, and comprehensive audit logging ensure that only authorised users can access sensitive engagement data.
You maintain control over your data at all times. Manage data retention periods to align with your internal policies and regulatory requirements. Your data is never used to train AI models.
From encryption to access management, Decisity enforces rigorous standards to keep your strategy documents secure, private, and defensible, giving your team the confidence to focus on what matters most.
Compliance
Decisity is engineered in line with ISO 27001:2022, the international standard for information security management systems.
GDPR-first data handling, designed to align with the world’s strictest standard for data privacy and protection.
Our controls are aligned to SOC 2 principles for the secure and responsible management of customer data across our platform.
Our AI governance framework is engineered in line with ISO 42001, giving customers confidence in how we build, deploy, and operate AI responsibly.
Decisity is designed to align with the EU AI Act, supporting transparent, accountable, and human-centric use of artificial intelligence.
Decisity is designed to align with the EU NIS2 Directive, supporting robust cybersecurity measures for network and information systems across our infrastructure.
Infrastructure
All data is encrypted in transit using TLS 1.2+ and at rest with AES-256 encryption. Encryption keys are regularly rotated and managed via hardware security modules, logically separated from customer data.
Our cloud environment is protected by industry-standard firewalls, threat detection tools with daily signature updates, and comprehensive monitoring for suspicious activities and potential threats.
Independent third-party penetration tests are conducted at least annually. Vulnerabilities are prioritised and remediated based on severity, critical issues within 48 hours, high-severity within 7 days.
In the event of a security incident, Decisity will notify affected customers within 72 hours and promptly take steps to contain, investigate, and mitigate the issue with full transparency.
Book a demo to see how Decisity protects your most sensitive strategy documents while delivering AI-powered insights at speed.
Request a demoFor detailed security documentation, visit our Security Policy.