Loading your compliance data…
Loading your compliance data…
Last updated: August 2026 — Enigma Partners Global Limited (SC893958)
Enigma Comply handles sensitive compliance data on behalf of organisations operating under frameworks including ISO 27001, GDPR, and the EU AI Act. Security is not a feature we add at the end — it is the reason customers trust us with their compliance work. This page explains how the platform is built, what controls protect your data, and how to report a security issue.
We operate a responsible disclosure policy. If you discover a security vulnerability in Enigma Comply, please report it to us before disclosing it publicly. We will acknowledge your report within 48 hours, keep you informed of our progress, and credit you in our disclosure once the issue is resolved.
Please do not use this channel for general support requests. Security issues only.
We plan to commission an independent penetration test by Q4 2026. Results and remediation status will be summarised and shared with Enterprise customers on request under NDA. Customers requiring a copy of the test report should contact [email protected].
We are honest about our current certification status. A platform that sells compliance advisory services must hold itself to the same standard it recommends to its customers.
| Standard | Status | Expected |
|---|---|---|
| Cyber Essentials | In progress | Q4 2026 |
| ISO 27001:2022 | Planned | Q1 2027 |
| SOC 2 Type II | Planned | 2027 |
| UK GDPR / DPA 2018 | Active | Ongoing |
AI agent workflows are disabled in the current Early Access release. The customer workflow uses manual assessments, registers and policy templates. If AI features are introduced, their data handling and provider terms will need to be reviewed before activation.
We use the following sub-processors to deliver the service. All international transfers to the USA are covered by Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Anthropic | AI compliance analysis | USA | SCCs / UK IDTA |
| Railway | Backend hosting & database | USA | SCCs / UK IDTA |
| Vercel | Frontend hosting | USA | SCCs / UK IDTA |
| Clerk | Authentication & identity | USA | SCCs / UK IDTA |
| Stripe | Billing & payment processing | USA | SCCs / UK IDTA |
| Pydantic Logfire | Error and performance monitoring | EU | UK adequacy regulations |
| Resend | Transactional email | USA | SCCs / UK IDTA |
Customers who require a signed Data Processing Agreement should contact [email protected].
We maintain an internal incident response procedure aligned with GDPR Article 33/34 obligations. In the event of a personal data breach, we will notify the ICO within 72 hours of becoming aware and notify affected individuals without undue delay where required. We will notify affected customers as soon as practicable.
For security issues: [email protected]
For privacy and data protection questions: [email protected]
For enterprise procurement enquiries including DPA, SLA, or pen test report requests: [email protected]