Security, Compliance & Trust
Security is the architecture, not a feature
Fisar processes some of the most sensitive information an organisation holds: personal data pulled from across your systems, much of it concerning people other than the requester. We treat security as the foundation everything else is built on, not a feature added at the end.

Trust at a glance
The essentials, up front
Every stage of a Subject Access Request happens inside one protected environment, in the UK, under access controls you set. This page explains where your data lives, how it is protected and how compliance is proven rather than promised.
UK data residency
AWS London (eu-west-2). Data stays within UK borders.
Encrypted everywhere
AES-256 at rest · TLS 1.3 in transit.
Least-privilege access
Role-based permissions, protected by MFA.
GDPR Article 28
Processor agreement in place.
7-year audit trail
Every operation logged and retained.
ISO/IEC 27001
Aligned with controls · certification in progress.
01 · The protected environment
Where your data lives – and who can reach it
One protected environment in the UK, built for containment with permissioned, one-way access.
Data never leaves the UK.
All processing runs in the AWS London region (eu-west-2). Application servers sit in private network segments with no direct route to the internet; databases live in isolated, encrypted subnets.
Encrypted everywhere.
AES-256 with managed key rotation at rest, TLS 1.3 in transit. Each organisation's data is kept in its own isolated storage and schema – no crossover between customers, ever.
You hold the keys.
Fisar reads from your systems only with credentials your administrators grant – and can revoke at any time. Access is role-based and protected by multi-factor authentication.

02 · Compliance by design
Proof of compliance, not just a promise
Compliance is not a filed-away policy – it is built into how the system behaves on every request.
Built around regulation.
A GDPR Article 28 processor agreement, designed around UK GDPR and the Data Protection Act 2018. Data minimisation is enforced automatically; breach-notification obligations are supported.
A tamper-evident record.
Fisar fingerprints every operation – each retrieval, redaction and human decision – chained into one record. Alter the history and it breaks, producing a signed certificate of what happened.
Then it cleans up.
Working copies of personal data are destroyed 30 days after a case closes, with deletion certificates kept as proof. Audit trails are retained for seven years; source systems are only ever read from.

03 · Connecting safely
Plugs into the systems you already use
Microsoft 365 and Google are connected through their official routes today, with school MIS platforms following – all scoped, read-only connections you control, and onboarding always starts in a safe sandbox.
Vendor-approved connections.
Fisar connects through each platform's official integration route – scoped, read-only access your administrators control and can withdraw at any time. It never writes back to your systems.
Sandbox-first onboarding.
Every new connection starts with dummy data in an isolated environment, so you can see exactly how Fisar behaves before it ever touches live information.
Sector-agnostic by design.
The same secure pipeline serves education, healthcare, financial services and government – any organisation that receives Subject Access Requests.

Official, vendor-approved, read-only connections – controlled by your administrators.