Security verified, not just asserted
We hold ourselves to the same standards our clients’ regulators expect of them. Every certification referenced on this page is independently audited, every control continuously monitored, and every claim below checked directly against the certificate or report behind it.
Certifications & Compliance
SaaScada is ISO/IEC 27001:2022 certified, the international standard for information security management, covering all processes, activities, systems and information within our Information Security Management System.
We have also received a SOC 2 Type II attestation covering the Security Trust Services Criteria, examined by an independent auditor for the period 1 December 2025 to 28 February 2026, with no exceptions noted.
We partner with Vanta as our compliance monitoring platform, giving continuous, automated evidence collection across both certifications rather than a once-a-year check.
Independent assurance you can point to during due diligence, not just a claim on a page.
Infrastructure & Cloud Architecture
SaaScada is hosted on Amazon Web Services (AWS), giving every client the benefit of enterprise-grade cloud infrastructure already trusted by financial institutions worldwide: regulatory-aligned certifications, physical security controls at data-centre level, redundant availability across multiple zones, and encryption by default.
Each client operates within a dedicated environment, with custom configuration, control over data residency, and a structure that makes escrow agreements simpler where required. Within that environment, production, staging and development are kept strictly separate. No data moves between them without explicit authorisation, and production data is never used in non-production systems without client consent.
The security of a private cloud with the operational simplicity of managed SaaS.
Network & Access Security
Access to SaaScada is controlled at every layer, from the network perimeter down to individual user permissions. A Zero Trust network model governs connectivity: encrypted tunnels, device posture checks, DNS filtering and DDoS mitigation protect every access point. Company devices are centrally managed, with full-disk encryption, automated patching and remote lock/wipe across the fleet.
Within the platform, access follows the principle of least privilege: users hold only the permissions their role requires, multi-factor authentication is mandatory on all privileged access, permissions are reviewed on a regular cycle and on every role change, and access is removed immediately on termination. SaaScada also holds membership of the Secure Swiss Finance Network (SSFN), next-generation infrastructure built on SCION technology, established by the Swiss National Bank and SIX, giving cyber-resilient, high-availability connectivity to other SSFN members.
Every access point to SaaScada, human or machine, is authenticated, monitored and reviewed on a regular cycle.
Data Protection & Privacy
Data is protected using industry-standard cryptographic controls: AES-256 for data at rest and on endpoints, TLS 1.2+ with RSA-2048 certificates for data in transit, with encryption keys managed through AWS Key Management Service. Data is classified into tiers, confidential, restricted and public, each with its own defined handling, storage and disposal rules.
Customer data is retained only as long as necessary, and for 90 days following contract termination before secure, cryptographic deletion. Verified data-subject requests are honoured throughout. Customer data is never used in non-production environments without explicit client permission, and any transfer to a third party requires a legal agreement and management sign-off.
Under UK GDPR, individuals have the right to access their personal data, correct inaccurate data, request deletion, withdraw consent to processing, and request data portability. Anyone with concerns about how we use their information can also complain to the Information Commissioner’s Office (ICO). This page covers our security and technical controls; our full Privacy Policy is the definitive reference for data-protection rights.
Your customers’ data is protected to the same standard your own regulator expects of you.
Secure Development
Security is built into our engineering process, not inspected in afterwards. We follow secure-by-design and privacy-by-design principles: minimising attack surface, secure defaults, defence in depth and separation of duties.
Every code change undergoes mandatory peer review against secure coding standards and OWASP compliance; no single person can develop, test and deploy a change without oversight. All developers receive annual secure development training covering the OWASP Top 10. We conduct regular penetration testing using CREST-certified, independent third-party testers.
Every release is checked by more than one person, tested against real attack techniques, and measured against an independent standard.
Incident Response
All personnel are required to report known or suspected security events, including policy violations and observed weaknesses, through documented reporting and escalation procedures. We maintain a documented Incident Response Plan with defined procedures for detection, containment, investigation and remediation.
Security documentation, penetration test reports and audit certifications are available on request.
If something goes wrong, there is already a plan, and a team ready to run it.