Security taken seriously.
ISO 27001 certified. SOC 2 backed. UK-located. Built on AWS. The boring controls done properly, because keeping your data safe is your priority, and as your solutions partner, it is ours too.
Independently audited. Continuously checked.
ISO 27001
Annually certified to the international standard for information security management. UKAS accredited.
SOC 2
Underlying AWS infrastructure independently audited against SOC 2 controls for security, availability, and confidentiality.
CSA STAR Level One
Cloud Security Alliance STAR registry. A transparent record of the controls behind the platform.
UK-located
All application servers located in the UK. NHS, Blue Light, and corporate estates supported with that residency in mind.
AWS-hosted. UK-located.
AWS-hosted, with premier certifications
The platform runs on AWS infrastructure that holds ISO 27001, SOC 2, and CSA STAR Level One. AWS Security and AWS Compliance documentation is referenceable on request.
Servers in the UK
All application servers are located in the UK. The platform is reachable globally over the public internet, but the data does not leave UK jurisdiction.
Encrypted in transit and at rest
Client data is secured with encryption both at rest and in transit. All connections use SSL/TLS 1.2+. The service is HTTPS-only, with certificate verification performed both ways.
Multi-AZ redundancy
Application and client data are redundantly stored across multiple AWS availability zones, ensuring fast recovery. Service status is published at status.meetuma.ai.
Containerised compute. Routes traffic to data, media, workers and notification services.
SSO. Multi-factor. Least privilege.
SSO via SAML 2.0
Authentication uses your existing Office 365 or Google Workspace credentials over SAML 2.0. When a colleague leaves, disabling their account in your IdP immediately revokes UMA access.
MFA across the team
All UMA staff use two-factor authentication and unique passwords. Customer-data access is restricted to a small group of essential personnel.
VPN and key-based access
Customer data access is gated by VPN IP whitelisting and public-key authentication. Access follows least-privilege principles and is reviewed quarterly.
Logged in multiple places
Access and security logs are preserved across multiple locations and retained for forensic use in the event of an incident investigation.
Peer reviewed. Deployed responsibly.
Every change is reviewed
All code requires peer review and passes through multiple approval stages before it can reach production. Nothing is shipped by a single engineer in isolation.
Unit, integration, and static analysis
Modifications run through unit tests, integration tests, and static analysis on every change. Internal security teams conduct evaluations on top of that.
Production data stays in production
Production data is kept fully separate from development environments. Engineers do not work against customer data in any non-production context.
Multiple releases each month
New features, enhancements, and security fixes ship multiple times monthly under an agile framework that prioritises code quality and security at every step.
Collected purposefully. Deleted properly.
What is synchronised
When you link an external calendar, UMA synchronises with the room calendars you specify. The event details we hold are:
- Organiser
- Attendees
- Title
- Description
- Start and end times
- Location
Event attachments are not stored.
Retention
Personal and operational data is held only for as long as needed for its stated purpose, or as required by law. Data passes through a secure deletion cycle every three years unless a shorter retention applies.
Deletion
On contract termination, all customer data is deleted in full. Backup retention is 30 days, after which data is unrecoverable. On request, identifiable calendar data is manually removed; anonymised derivative data may persist.
Transparent reporting. Documented practice.
Incident response
If a security incident affects your data, we will notify you promptly. Customers can request supplementary access logs to support their own investigation, granted responsibly by the security team.
Security policies
All UMA staff operate under documented security policies covering acceptable use, customer data handling, and encryption standards. Copies are available through your account manager.
Privacy
Data protection is a first-class concern. Full detail is in the privacy policy.
Need our paperwork
If you need ISO 27001 evidence, a signed DPA, sub-processor list, or specific control documentation, email info@askuma.ai and we will route it to the right person.