Security built in, not bolted on
GuardFlow holds sensitive operational, staff and compliance data for UK security firms. Here's a plain-English, honest account of the controls we have in place today, and what we're working towards.
What's in place today
Role-based access control
Every user has a defined role: company owner, operations manager, HR, finance or staff, plus custom roles you define. What each person can see and do is scoped to their role, so officers and managers only ever access what's relevant to them.
Row-level security on every table
Access rules are enforced in the database itself, not just the interface. Each company's data is isolated by tenant at the row level, so one customer can never read or write another customer's records.
Audit logging
Sensitive actions are recorded to an audit trail with the user and timestamp, giving you accountability over changes to staff, compliance, finance and operational records.
Encrypted in transit and at rest
Every connection to GuardFlow uses HTTPS with TLS 1.2 or later, so data moving between your team, our servers and the database is encrypted in transit. Stored data is encrypted at rest by our infrastructure provider.
Private document storage
Compliance documents, incident photos and site files are held in private storage and opened through short-lived links, only by authorised users in the owning company.
Hosted in Zurich, Switzerland
Production data is hosted in Zurich, Switzerland, which the UK recognises as providing an adequate level of data protection. GuardFlow runs on managed cloud platforms (Supabase and Cloudflare) with automated backups.
Records that can't be quietly changed
Clock-ins, written occurrence book entries and key custody records can't be edited or deleted through GuardFlow. A corrected clock time is kept alongside the original punch, so the history stays intact.
Least-privilege administration
Platform administration is limited and role-gated. Support access to a customer account is controlled and, where used, is logged.
GDPR-conscious by design
We provide a Data Processing Agreement, a clear privacy policy and tooling to support data subject access and deletion requests. Personal data is collected for defined operational purposes only.
Certifications & assurance
We believe in being straight about where we are. We don't claim certifications we don't hold.
We are aligning our controls to the Cyber Essentials scheme.
On our roadmap as the business scales; not currently certified.
Considered for future enterprise requirements; not currently held.
Your data, your control
- Your data belongs to you and can be exported.
- We process personal data as a processor on your behalf, under a Data Processing Agreement.
- We support data subject access and deletion requests.