Trust & Compliance

Security you can
evidence, not just assert

Our security posture, certifications, data handling practices, and compliance documentation — all in one place.

Last updated: August 2026

Our compliance framework

Tempest AI maintains its own security certifications and considers independent assurance held by its sub-processors as part of its wider security and compliance framework.

Held — Current

Cyber Essentials

UK government-backed certification confirming our baseline security controls are in place. Issued to Tempest AI Limited.

In Progress

ISO 27001

External consultant engaged. Target certification: February 2027. Audit programme underway.

Sub-processor Assurance

SOC 2 Type II

Our sub-processors maintain SOC 2 Type II assurance, providing independent validation of the security controls supporting the services used by Tempest AI.

Registered

ICO Registration

Tempest AI Limited is registered with the Information Commissioner's Office.


How we handle your data

We process only the data necessary to deliver our service. All client and resident data is handled in accordance with UK GDPR and the terms of our Data Processing Agreement.

Data typePurposeRetentionLocation
Resident contact detailsName, email, mobile numberResident identification and matching against client-provided recordsDeleted within 90 days of contract terminationLondon, UK
Knowledge base documentsLease documents, handbooks, technical dataProviding property-specific context for AI-assisted responses and workflowsHeld for contract duration; deleted on terminationLondon, UK
Interaction logsChat transcripts, ticket recordsAudit trail, quality assurance, escalation managementRetained per agreed retention scheduleLondon, UK
AI inference dataSelected interaction context required for AI-assisted functionsPerforming AI-assisted platform functionsHandled under approved provider data-processing arrangements; not used by providers to train their modelsAvailable on request

How we protect your systems

Security is built into how we develop, deploy and operate the platform — not bolted on afterwards.


Sub-processor governance

Tempest AI works with carefully selected third-party service providers for cloud infrastructure, communications and AI services. Where a sub-processor handles personal data, appropriate data protection, security and contractual requirements are applied as part of our supplier due diligence and risk management processes.

Our current full sub-processor list, including processing purposes and relevant data-processing information, is available to clients and prospective clients on request.


Available on request

The following documents are available to clients and prospective clients on written request. Contact us using the details below.


Request documentation or ask a question

For compliance queries, documentation requests, or to discuss our security posture in relation to your procurement process, contact our team directly.

We aim to respond promptly to compliance and security enquiries. For DPIA-related requests, please include the nature of processing in your message.

Contact Tempest AI →