Data & Integrity

Data Protection & Privacy

Foundational

Privacy is mostly won or lost in the data tier. It depends on how you classify, store, encrypt, and access-control data at rest. This is the engineering side of the policy view (see Privacy & Data Protection (GDPR)). It covers the practical patterns that keep sensitive data safe where it actually lives.

Start by knowing what data you hold and how sensitive it is. Then match the protection to the sensitivity. Ordinary data, personal data, and special-category data (our biometric KYC material) each need a different level of encryption, access control, and care. The rule is least exposure: the fewest copies, the fewest readers, and the least precision that does the job.

The Finperiti audit found that biometric data was open to cross-tenant risk. This shows how a weak data tier can become a serious breach. Classification, encryption, tenant isolation, and tight access at the storage layer stop a bug elsewhere from turning into a regulatory disaster.

Classify and minimise

Protect at rest and in access

Self-review checklist

Why it matters: When a breach happens, what leaks is whatever the data tier failed to protect. For us that can include biometric, special-category data at the most serious end of GDPR. Classifying, minimising, encrypting, and isolating data at rest is the difference between a contained incident and a reportable disaster.