Security & Governance

Trust is not claimed.
It is evidenced.

Ironvale serves institutions whose records carry legal, historical and personal weight. Governance, compliance and immutable logging are built into the platform's foundations — and our posture is designed to be inspected by client assurance teams, auditors and regulators, not merely described.

Defence in Depth

Layered controls across network, application, data and physical domains. Encryption in transit and at rest, hardened single-tenant environments, and continuous monitoring with independent penetration testing of the platform.

Personnel Assurance

Access to client material is restricted to named, vetted personnel operating under need-to-know. Vetting levels are matched to the sensitivity of each engagement and evidenced to the client before work begins.

Jurisdictional Residency

Client data resides in the jurisdiction the client designates, under deployment models agreed at contract. Cross-border movement of data occurs only with the client's explicit, documented authorisation.

Immutable Logging

Every interaction with a record — view, search, annotation, export — is captured in an immutable, tamper-evident audit log retained for the life of the engagement and available to client auditors on demand.

Operational Resilience

Multi-zone redundancy, tested recovery procedures, and business continuity planning proportionate to the criticality of institutional archives. Recovery objectives are contracted, not aspirational.

Compliance & Standards

Our governance and control framework is built on internationally recognised standards for information security and records management, including the ISO 27001 and ISO 15489 control families, and is mapped to each client's regulatory and compliance regime per engagement.

Security you can audit is the only kind
worth paying for.

Single-tenant infrastructure · Client inspection rights

Governance In Practice

How an engagement is governed, end to end.

Before contract Client assurance teams receive our security documentation pack and may conduct due-diligence reviews, site visits and technical assessments prior to signature.
At mobilisation A joint security management plan is agreed: named personnel, vetting evidence, data-handling procedures, incident response paths and escalation contacts.
In operation Scheduled service and security reporting, continuous audit logging, and client-initiated inspection rights exercised at the client's discretion.
On incident Contracted notification timelines, joint investigation protocols and full disclosure of root cause and remediation to the client.
At exit Complete return of records, metadata and audit history in open formats, followed by certified destruction of residual client data from our environments.
Assurance Teams Welcome

Put our posture under examination.

Our full security documentation pack is provided to counterparties under NDA during procurement, and we support technical due diligence by client security, audit and procurement functions.