Security

Security is core to how TriaGuard is built, not an afterthought. Here is an overview of how we protect your data and our service.

Last updated: September 2026

Built on human control

TriaGuard comments on alerts with its findings but takes no action on your behalf unless you choose to allow it. You stay in control of what TriaGuard is permitted to do in your environment.

Platform Security

TriaGuard is hosted on Microsoft Azure in the UK South region. Customer data stays in the UK.

Encryption

Data is encrypted at rest and in transit using Azure’s built-in encryption standards.

Certifications and compliance

TriaGuard is Cyber Essentials certified and registered with the UK Information Commissioner’s Office (ICO).

Data Handling

We maintain a list of subprocessors used to deliver the service, including what each one does and where data is processed. This is available on request. Contact us if you would like a copy.

A Data Processing Agreement is available as part of our standard SaaS agreement. Contact us if you would like to review it ahead of a purchase decision.

Business continuity

TriaGuard maintains a business continuity and disaster recovery plan covering service availability.

Access & Authentication

Product access: Customer accounts require multi-factor authentication. TriaGuard uses rate limiting and bot protection to guard against brute-force login attempts.

Internal access: TriaGuard staff use individual, non-shared logins to access production systems. Multi-factor authentication is enrolled on all internal accounts.

Incident Response

TriaGuard maintains an incident response process for identifying, containing, and resolving security incidents. Affected customers are notified in line with our contractual and legal obligations.

Responsible Disclosure

If you believe you’ve found a security issue, we want to hear about it. Please report it to us directly rather than disclosing it publicly.

Security Contact