Security & Data Protection
How the Global 4-Domain Communication Skills Rating Tool™ protects your data, from infrastructure to deletion.
Where We Stand Today
| Control Area | Status |
|---|---|
| Encryption in transit (TLS v1.3) | In place |
| Encryption at rest | In place |
| Data residency — dedicated virtual server, Germany | In place |
| Data Processing Agreement | Signed before access is granted |
| Personal data deletion on request | Within 30 days |
| Multi-tenant data isolation | Enforced at the query layer |
| Role-based access control | Enforced at the application layer |
| Password policy | Minimum length & complexity enforced |
| Audit logging | Insert-only |
| SOC 2 Type II | Planned for the next phase |
| ISO 27001 | Aligned to principles — planned for the next phase |
Infrastructure & Encryption
Where Your Data Lives
The platform runs on a dedicated virtual server, hosted in Germany. Data does not leave this hosting environment except as described in the Data Processing Agreement.
Encryption
All data in transit is encrypted using TLS. All data at rest is encrypted. This applies across the entire platform. For institutional/organisational tiers, this is governed by the Data Processing Agreement, and for the Individual tier by our Terms & Conditions and Privacy Policy, under which Global 4-Domain Communications Limited acts as Controller.
Platform Availability
Platform availability
The G4D platform targets 99.97% monthly uptime across all deployments, matching the uptime of the single dedicated server that hosts all clients.
SLA-backed guarantees
Formal service-level commitments, including guaranteed uptime and 4-hour critical response times, apply to Organisational and Global Enterprise tiers as set out in the Order Form. Strategic Partner terms are negotiated individually and take this baseline into account.
Data Isolation & Access Control
Tenant Isolation
Multi-tenant data isolation is enforced at the query layer, not left to interface-level filtering alone. A request for another organisation's data returns a 404 response rather than a filtered result. The separation exists below the presentation layer, where a misconfigured screen or report cannot bypass it.
Role-Based Access
Internal access to platform data is controlled by a role-based permission system enforced at the application layer, with defined boundaries between roles. Access is scoped by design, not solely by policy.
Licence-Scoped Access
Partner and enterprise access to participant data is limited to the scope and duration of the licence agreement and enforced at the application layer. Where a client elects to export their data upon termination, access is retained for 30 days for that purpose; otherwise, access is revoked in accordance with the Data Processing Agreement.
Audit Logging
Insert-Only Records
Access and administrative activity are recorded in an insert-only audit log. Entries cannot be edited or deleted after the fact, which preserves a reliable record for internal review and supports the compliance information we provide to clients on request under the Data Processing Agreement.
Data Protection & Your Rights
Data Processing Agreement
A Data Processing Agreement is signed by the client's designated primary contact via a secure link provided during onboarding before any platform credentials are issued.
Applicable Law
Data protection obligations are governed by UK GDPR, EU GDPR, and the Data Protection Act 2018, together with any other data protection law applicable to a client's own jurisdiction.
Deletion on Request
Personal identifiers — name, email address, and contact details — are deleted or permanently anonymised within 30 days of a verified request. Full details on how this applies to individual participants and organisational deployments are set out in our Governance Framework.
Breach Notification & Compliance Information
Notification & Information Rights
In the event of a confirmed personal data breach, clients are notified within 72 hours. Clients may also request information reasonably necessary to demonstrate our ongoing compliance with the Data Processing Agreement.
Sub-Processors
Current List
A current list of sub-processors is published and maintained on our Sub-Processors page.
Security Roadmap
The following controls are not yet in place. We state this directly as a matter of institutional integrity and in alignment with our commitment to accuracy.
SOC 2 Type II
Not currently available. Planned for the next phase, as part of the enterprise security roadmap.
ISO 27001
Practices are aligned to ISO 27001 principles. Formal certification is not yet held and is planned for the next phase.
SSO, MFA & API Access
Single sign-on and API access are not available at launch. We would build these in our next development phase, prioritised once a specific client's requirement makes them necessary. Multi-factor authentication would be considered alongside the single sign-on offering.