Skip to main content
Parousia Group

Trust centre

Security, data residency and reporting routes

Access control, data residency, standards, availability commitments and the function that receives a report.

One control framework across the group

Group Security owns the control framework, the Compliance Department monitors it, Internal Audit tests it independently, and evidence is produced under contract.

Security

How the group protects what it operates

The measures below are set by Group Security, implemented by Group Operations and tested by Internal Audit.

  • Access is granted by role and recordedProduction access is granted per role and per environment. Every privileged action is logged where it cannot be altered.
  • Encryption in transit and at restTraffic is encrypted end to end. Data at rest is encrypted with group-managed or customer-managed keys.
  • Independent review before releaseNo change reaches production without a review by someone who did not write it. Group Security reviews security changes.
  • Environments are separatedDevelopment, test and production are separate estates with separate credentials. Production data is never copied into test.
  • Recovery is testedBackups are restored on a defined schedule, and Group Operations documents each test with Group Security.
  • Incident response with a named ownerEvery incident has one owner from detection to review, and Group Security tracks each corrective action to completion.

Data residency

Where the data stays

Customer data remains in the jurisdiction the customer chooses, and the Data Protection Office holds the record of processing and of transfers.

Group offices

Where a customer requires that data never leave a jurisdiction, that requirement is written into the contract by the Legal Department and implemented in the architecture of the service.

Standards

What is held, and what is only targeted

The Compliance Department maintains the register of applicable standards and the group’s status against each one.

Certificates held

The group does not hold a certificate issued against these standards; a certificate number and its issuing body are published on this page as soon as one is awarded.

Engineered to

  • ISO/IEC 27001
  • ISO/IEC 27701
  • ISO/IEC 22301
  • ISO 9001
  • PCI DSS
  • SOC 2
  • NIST SP 800-53
  • CIS Benchmarks
Compliance

Availability

What the group commits to

Service objectives are agreed contract by contract, according to the criticality of the service concerned.

  • Objectives are contractualGroup Operations agrees recovery time and recovery point objectives in writing with the customer before a service goes live.
  • Maintenance is announcedPlanned maintenance is notified in advance and carried out within a window agreed with the customer.
  • Incidents are reported to those affectedAn affected customer is told what is known at the time, and again when the review is complete.