Security
Security is core to how TriaGuard is built, not an afterthought. Here is an overview of how we protect your data and our service.
Last updated: September 2026
Built on human control
TriaGuard comments on alerts with its findings but takes no action on your behalf unless you choose to allow it. You stay in control of what TriaGuard is permitted to do in your environment.
Platform Security
TriaGuard is hosted on Microsoft Azure in the UK South region. Customer data stays in the UK.
Encryption
Data is encrypted at rest and in transit using Azure’s built-in encryption standards.
Certifications and compliance
TriaGuard is Cyber Essentials certified and registered with the UK Information Commissioner’s Office (ICO).
Data Handling
We maintain a list of subprocessors used to deliver the service, including what each one does and where data is processed. This is available on request. Contact us if you would like a copy.
A Data Processing Agreement is available as part of our standard SaaS agreement. Contact us if you would like to review it ahead of a purchase decision.
Business continuity
TriaGuard maintains a business continuity and disaster recovery plan covering service availability.
Access & Authentication
Product access: Customer accounts require multi-factor authentication. TriaGuard uses rate limiting and bot protection to guard against brute-force login attempts.
Internal access: TriaGuard staff use individual, non-shared logins to access production systems. Multi-factor authentication is enrolled on all internal accounts.
Incident Response
TriaGuard maintains an incident response process for identifying, containing, and resolving security incidents. Affected customers are notified in line with our contractual and legal obligations.
Responsible Disclosure
If you believe you’ve found a security issue, we want to hear about it. Please report it to us directly rather than disclosing it publicly.