Security at Setyl
Security is central to how we build and run Setyl. Because our platform helps organisations manage their IT assets, software, and people, we treat the confidentiality, integrity and availability of your data as a first-order priority. This page summarises our security programme. It is a summary for information only and does not form part of any contract; specific commitments are set out in your agreement with us, our Master Software License Agreement, and our Master Data Processing Agreement.
Certifications and compliance
ISO/IEC 27001 — our information security management system is certified to ISO/IEC 27001.
UK GDPR and EU GDPR — we act as a processor of the personal data our customers hold in the platform, under our Master Data Processing Agreement. See our Privacy Notice and Sub-processor list for more.
Customers and prospects can request our current certifications, penetration test summary, and security documentation under NDA by contacting security@setyl.com.
Data protection and encryption
Encryption in transit. All data transmitted between you and the platform is encrypted using TLS.
Encryption at rest. Customer Data is encrypted at rest using industry-standard algorithms.
Data segregation. Customer Data is logically segregated so that each customer can access only their own data.
Data hosting. The platform is hosted with a leading cloud infrastructure provider in the UK/EU region. Our sub-processors and processing locations are published on our Sub-processor list.
Access control
Least privilege. Internal access to systems and data is granted on a need-to-know, least-privilege basis, and reviewed regularly.
Authentication. We enforce multi-factor authentication for administrative and remote access to our systems. The platform supports single sign-on (SSO) and multi-factor authentication for customer users.
Role-based access. Within the platform, customers can configure roles and permissions to control what each of their users can see and do.
Joiners and leavers. Access is provisioned and promptly revoked in line with personnel changes.
Application and infrastructure security
Secure development. Security is built into our software development lifecycle, including code review and dependency management.
Vulnerability management. We carry out regular vulnerability scanning, apply security patches in a timely manner, and commission periodic independent penetration testing.
Network security. We use firewalls, network segmentation, and monitoring to protect our infrastructure.
Logging and monitoring. Security-relevant events are logged and monitored to help us detect and respond to potential issues.
Resilience and continuity
Backups. Customer Data is backed up regularly, and backups are encrypted.
Business continuity and disaster recovery. We maintain and periodically test business continuity and disaster recovery plans.
Availability. Our availability commitment and status page are described in our Service Level Agreement and at status.setyl.com.
People and governance
Policies. We maintain a set of information security and data protection policies, reviewed at least annually.
Training. Our personnel receive security and data protection training, and are bound by confidentiality obligations.
Background checks. We carry out pre-employment screening where lawful and appropriate.
Vendor management. We conduct due diligence on our sub-processors and bind them to data protection terms no less protective than our own.
Incident response
We maintain a documented incident response process. In the event of a personal data breach affecting Customer Data, we notify affected customers without undue delay and in accordance with our Master Data Processing Agreement, and support them in meeting their own notification obligations.
Reporting a vulnerability
If you believe you have found a security vulnerability in our platform, please report it in accordance with our Vulnerability Disclosure Policy. We appreciate the work of the security community and will work with you to verify and address valid reports.
Contact
For security questions, documentation requests, or to report a concern, contact us at security@setyl.com.