Heresafe's security and data position is documented and available for review, so approval doesn't depend on taking anyone's word for it.
ISO 27001-certified
UK-only data processing
Controlled, auditable access
Before Heresafe goes live, IT and security teams need to confirm it doesn’t introduce unacceptable risk on access, data handling, hosting, continuity or support. ISO/IEC 27001:2022 certification, with a published certificate and scope, sits alongside an Information Security Policy, a Service Level Agreement covering hosting, backups, business continuity and support, and an annual penetration-testing statement. All of it sits on the Trust page directly, rather than arriving late or spread across sales, technical and legal contacts.
Day-to-day users work through auditable workflows rather than spreadsheets and shared files, with access managed on the principle of least privilege and access and security events logged and monitored. External contractors use a separate self-service portal entirely, never touching an internal user account. For organisations that require tighter identity and access control, Heresafe can support Microsoft Entra ID SSO and configurable role-based permissions.
Reviewing evidence and a security questionnaire before approval, then, where SSO and role-based permissions are part of the setup, a one-time configuration afterward, which an administrator can run instead if you’d rather hand it off.
“We liked the simplicity of the system and the ease with which things could be changed and developed to meet our needs.” – Di Hudson, Head of IT, Goodwood Group
Heresafe also runs multi-site contractor control for Avis Group, across operational sites where a paperwork gap turns into a continuity problem fast.
Start at the Trust page for the certificate, the policy and the SLA directly.