Certifications
Our compliance framework
Tempest AI maintains its own security certifications and considers independent assurance held by its sub-processors as part of its wider security and compliance framework.
Cyber Essentials
UK government-backed certification confirming our baseline security controls are in place. Issued to Tempest AI Limited.
ISO 27001
External consultant engaged. Target certification: February 2027. Audit programme underway.
SOC 2 Type II
Our sub-processors maintain SOC 2 Type II assurance, providing independent validation of the security controls supporting the services used by Tempest AI.
ICO Registration
Tempest AI Limited is registered with the Information Commissioner's Office.
Data & Privacy
How we handle your data
We process only the data necessary to deliver our service. All client and resident data is handled in accordance with UK GDPR and the terms of our Data Processing Agreement.
| Data type | Purpose | Retention | Location |
|---|---|---|---|
| Resident contact detailsName, email, mobile number | Resident identification and matching against client-provided records | Deleted within 90 days of contract termination | London, UK |
| Knowledge base documentsLease documents, handbooks, technical data | Providing property-specific context for AI-assisted responses and workflows | Held for contract duration; deleted on termination | London, UK |
| Interaction logsChat transcripts, ticket records | Audit trail, quality assurance, escalation management | Retained per agreed retention schedule | London, UK |
| AI inference dataSelected interaction context required for AI-assisted functions | Performing AI-assisted platform functions | Handled under approved provider data-processing arrangements; not used by providers to train their models | Available on request |
- Client and resident data is not currently used by Tempest for model training or fine-tuning
- All data encrypted at rest and in transit
- Role-based access controls on all systems
- International transfers protected through appropriate contractual safeguards
- Defined retention and deletion controls applied throughout the data lifecycle
- Special category data is not routinely solicited; sensitive disclosures are handled through appropriate workflows and escalation
Security Controls
How we protect your systems
Security is built into how we develop, deploy and operate the platform — not bolted on afterwards.
- Layered AI security controls including controlled context and tool access, workflow constraints and permission controls
- Managed data and configuration updates restricted to authorised users
- Phishing simulation, dark web monitoring and deep scanning via CFC cyber insurance
- £1,000,000 specialist cyber liability insurance (CFC) — including AI hallucination cover
- Secure development practices (SDLC) including code review and structured testing
- Sandbox testing and client UAT before every go-live
- Incident Response Plan with defined response and client notification procedures
- No data breaches recorded to date
- Data breach response procedures aligned with UK GDPR obligations
- Multi-provider AI architecture supporting alternative inference routes where appropriate
- 99% monthly availability target with documented continuity and disaster recovery arrangements
- Formal penetration testing on ISO 27001 roadmap (target Feb 2027)
Sub-processors
Sub-processor governance
Tempest AI works with carefully selected third-party service providers for cloud infrastructure, communications and AI services. Where a sub-processor handles personal data, appropriate data protection, security and contractual requirements are applied as part of our supplier due diligence and risk management processes.
Our current full sub-processor list, including processing purposes and relevant data-processing information, is available to clients and prospective clients on request.
Policies & Documentation
Available on request
The following documents are available to clients and prospective clients on written request. Contact us using the details below.
- Data Processing Agreement (DPA)
- AI Risk Register
- Business Continuity Plan
- Disaster Recovery Plan
- Incident Response Plan
- Sub-processor full list
- Cyber Essentials certificate
- CFC cyber insurance summary
Contact
Request documentation or ask a question
For compliance queries, documentation requests, or to discuss our security posture in relation to your procurement process, contact our team directly.
We aim to respond promptly to compliance and security enquiries. For DPIA-related requests, please include the nature of processing in your message.
Contact Tempest AI →