Trust Centre
Security, privacy & compliance
We build the software behind interpreting agencies, so the data we handle is sensitive by nature. We think the only honest way to earn trust is to show our working, so this page sets out the standards we are working towards, the controls we operate, the data we hold, and the providers we rely on. We keep it current as things change, rather than refreshing it once a year.
In progress Our formal certifications are in progress. This page shows where we genuinely are today, not a finished audit, and it moves as we do.
Compliance
In ProgressThe standards we are working towards. We build against them now rather than waiting for audit day.
Readiness
In ProgressWe would rather show our working than stay quiet until the certificates arrive. These are the standards we are working towards, and where we honestly stand against each one today. We are closing the remaining work at pace, and we will publish each certification the day it is issued.
- Cyber Essentials 80%Working towards Plus · Remediation underway
- NHS DSPT 55%2026/27 self-assessment · Mapped, not yet submitted
- NCSC CAF 50%Framework alignment · Assessed and mapped
- ISO 27001:2022 30%Certification · Foundations in place
Self-assessed at 22 September 2026.
Controls
In Progress- Data & privacy
- Product security
- Infrastructure security
- Backups & resilience
- Organisational security
- Internal security procedures
Data Collected
In Progress- Service User PII
- Service Client PII
- Interpreter PII
Subprocessors
CurrentResources
Current- Privacy Notice
- Cookie Policy
- Sub-processor List
- End User Agreements
- Acceptable Use Policy
- Data Processing Agreement (DPA)
- Information Security Policy Ongoing
- Security Overview Ongoing
Resources
Security, privacy and legal documentation. Everything we have published is linked below and free to read without asking us first. The rest is being written now, and each one goes up as soon as it is ready. If you need something before then, email security@tupi.solutions and we will share what we have and tell you plainly what is still in progress.
- Privacy Notice View →
- Cookie Policy View →
- Sub-processor List View →
- End User Agreements View →
- Acceptable Use Policy View →
- Data Processing Agreement (DPA) View →
- Information Security Policy Ongoing
- Security Overview Ongoing
Controls
The security domains we operate across. Each one has a named owner and a position we revisit as the product changes, rather than a policy written once and filed.
Data & privacy
How personal data is collected, processed, stored, retained, and deleted.
In progressProduct security
Secure development lifecycle, access controls, and application safeguards.
In progressInfrastructure security
Hosting, network segmentation, encryption in transit and at rest.
In progressBackups & resilience
Files, documents and the database are copied to a separate AWS account in another EU region: files as they are written, the database nightly. Each copy is held under a 21-day lock the primary account cannot alter or delete, and database backups also run daily in our primary account. A full restore of the database and files was tested in September 2026, restores are tested at least annually, and data is recoverable to within about 24 hours.
In progressOrganisational security
Policies, staff vetting, security training, and governance.
In progressInternal security procedures
Monitoring, logging, incident response, and operational runbooks.
In progressSubprocessors
Every third-party provider that processes personal data on our behalf, where we act as processor. We publish the list openly on our sub-processors page, and we tell affected agencies before a change takes effect, not after.
- AWS Hosting, sign-in, email & background processing UK (email: Ireland)
- Google Google Workspace: email & documents Ireland (EMEA)
- Xero Our accounting records (Agency billing) UK
- Mintly Bank account detail validation UK
- VoIPstudio Telephony: in-browser calls & SMS codes UK
Agency-connected integrations
Where an agency connects its own provider, an accounting package for example, that provider is the agency's sub-processor, under the agency's control, not ours. We process the underlying data only as the agency's processor (bring your own provider).
- Accounting The Agency’s own package: QuickBooks now, Sage Accounting and FreeAgent to follow Agency-provided
Frequently asked questions
Is tupi.solutions an interpreting provider?
No. We build software for interpreting agencies and interpreters. We do not provide interpreting services ourselves.
How often does this page change?
Whenever our position does. We treat this as a living record rather than an annual statement, so an item here can move in either direction as we learn more. We would rather you saw an honest status that changes than a polished one that never does.
Where is our data hosted?
Primarily in AWS, London region (eu-west-2). The full list of providers is under Subprocessors.
Which standards are you working towards?
NHS DSPT 2026/27, ISO 27001:2022, Cyber Essentials, GDPR alignment, and the NCSC Cyber Assessment Framework (CAF). All are in progress, and the Readiness panel shows how far we have got with each one.
How do I report a security vulnerability?
Email security@tupi.solutions. We welcome reports, and we aim to acknowledge every one within 5 working days. Please give us reasonable time to fix an issue before disclosing it. Our machine-readable contact details are published at /.well-known/security.txt.
How can I request security documentation?
Email security@tupi.solutions. We will send what exists today and tell you plainly what is still being written, rather than leaving you to guess.