Home Pricing Contact Sign in Try UMA for Free

Security taken seriously.

ISO 27001 certified. SOC 2 backed. UK-located. Built on AWS. The boring controls done properly, because keeping your data safe is your priority, and as your solutions partner, it is ours too.

Certifications & standards

Independently audited. Continuously checked.

UMA is annually certified to ISO 27001. The underlying AWS infrastructure is independently assessed against SOC 2 and listed on the Cloud Security Alliance STAR registry.
01 / Information security

ISO 27001

Annually certified to the international standard for information security management. UKAS accredited.

02 / Service organisation

SOC 2

Underlying AWS infrastructure independently audited against SOC 2 controls for security, availability, and confidentiality.

03 / Cloud assurance

CSA STAR Level One

Cloud Security Alliance STAR registry. A transparent record of the controls behind the platform.

04 / Data residency

UK-located

All application servers located in the UK. NHS, Blue Light, and corporate estates supported with that residency in mind.

Independent assurance
  • ISO 27001
    Annually certified · UKAS accredited
  • GDPR
    Compliant data handling
  • Pentest People
    Independent penetration testing
Network architecture

AWS-hosted. UK-located.

UMA runs on AWS infrastructure inside UK availability zones. Disaster recovery is built in. Service status is public at status.meetuma.ai.
01 / Datacentre

AWS-hosted, with premier certifications

The platform runs on AWS infrastructure that holds ISO 27001, SOC 2, and CSA STAR Level One. AWS Security and AWS Compliance documentation is referenceable on request.

02 / Data localisation

Servers in the UK

All application servers are located in the UK. The platform is reachable globally over the public internet, but the data does not leave UK jurisdiction.

03 / Encryption

Encrypted in transit and at rest

Client data is secured with encryption both at rest and in transit. All connections use SSL/TLS 1.2+. The service is HTTPS-only, with certificate verification performed both ways.

04 / Disaster recovery

Multi-AZ redundancy

Application and client data are redundantly stored across multiple AWS availability zones, ensuring fast recovery. Service status is published at status.meetuma.ai.

CLIENTS · 01
C-01 Mobile App
C-02 Web Dashboard
SSO Microsoft 365 · Google
HTTPS · 443
UMA CLOUD · AWS
APP · 02
Application Layer

Containerised compute. Routes traffic to data, media, workers and notification services.

A-01 AWS Fargate ECS · serverless
MEDIA · 03 Media Object storage for assets
M-01 Amazon S3 object store
DATA · 04 Data Persistence + cache
D-01 RDS · Aurora primary store
D-02 ElastiCache Redis cache
WORKERS · 05 Workers Async processing & sync
W-01 Analytics reporting
W-02 MQ Broker event bus
W-03 DataSync cal sync
NOTIFY · 06 Notifications Email & push delivery
N-01 Email Service SES · SMTP
N-02 Amazon SNS push · sms
EXTERNAL · 07 Calendar Services Source-of-truth booking systems OAuth · Webhooks
Office 365
EXT-01 · Microsoft Graph
Google Workspace
EXT-02 · Calendar API
Access & authentication

SSO. Multi-factor. Least privilege.

Authentication piggybacks your existing identity provider. Internal access is layered, audited, and reviewed every quarter.
01 / Single sign-on

SSO via SAML 2.0

Authentication uses your existing Office 365 or Google Workspace credentials over SAML 2.0. When a colleague leaves, disabling their account in your IdP immediately revokes UMA access.

02 / Two-factor

MFA across the team

All UMA staff use two-factor authentication and unique passwords. Customer-data access is restricted to a small group of essential personnel.

03 / Network controls

VPN and key-based access

Customer data access is gated by VPN IP whitelisting and public-key authentication. Access follows least-privilege principles and is reviewed quarterly.

04 / Audit trail

Logged in multiple places

Access and security logs are preserved across multiple locations and retained for forensic use in the event of an incident investigation.

Change management

Peer reviewed. Deployed responsibly.

Every change goes through review, automated testing, and security evaluation before it reaches a customer environment.
01 / Peer review

Every change is reviewed

All code requires peer review and passes through multiple approval stages before it can reach production. Nothing is shipped by a single engineer in isolation.

02 / Tested at three layers

Unit, integration, and static analysis

Modifications run through unit tests, integration tests, and static analysis on every change. Internal security teams conduct evaluations on top of that.

03 / Environment separation

Production data stays in production

Production data is kept fully separate from development environments. Engineers do not work against customer data in any non-production context.

04 / Release cadence

Multiple releases each month

New features, enhancements, and security fixes ship multiple times monthly under an agile framework that prioritises code quality and security at every step.

Data lifecycle

Collected purposefully. Deleted properly.

UMA holds the minimum data needed to make the platform work, retains it only for as long as it is required, and removes it on request.

What is synchronised

When you link an external calendar, UMA synchronises with the room calendars you specify. The event details we hold are:

  • Organiser
  • Attendees
  • Title
  • Description
  • Start and end times
  • Location

Event attachments are not stored.

Retention

Personal and operational data is held only for as long as needed for its stated purpose, or as required by law. Data passes through a secure deletion cycle every three years unless a shorter retention applies.

Deletion

On contract termination, all customer data is deleted in full. Backup retention is 30 days, after which data is unrecoverable. On request, identifiable calendar data is manually removed; anonymised derivative data may persist.

Incidents & policies

Transparent reporting. Documented practice.

If something goes wrong, you hear about it. Documentation is available to customers on request.

Incident response

If a security incident affects your data, we will notify you promptly. Customers can request supplementary access logs to support their own investigation, granted responsibly by the security team.

Security policies

All UMA staff operate under documented security policies covering acceptable use, customer data handling, and encryption standards. Copies are available through your account manager.

Privacy

Data protection is a first-class concern. Full detail is in the privacy policy.

Need our paperwork

If you need ISO 27001 evidence, a signed DPA, sub-processor list, or specific control documentation, email info@askuma.ai and we will route it to the right person.

Want our security paperwork.

Email info@askuma.ai for ISO 27001 evidence, DPA, sub-processor list, or any control documentation you need.