Private by default. Clear about what we do with your data.
Credbase holds documents on behalf of your suppliers, subcontractors, vendors and partners. This page explains how we protect that trust: how the product is built, where data lives and how you stay in control.
Credbase is designed to hold third-party business documents on behalf of small and mid-sized teams. Security is treated as a product feature, not an afterthought. Every workspace is private by default and every document is protected in transit and at rest.
Private-by-default workspaces
Encryption in transit and at rest
Role-based access with audit trail
Regular internal security review
Data hosting
Credbase is hosted on managed cloud infrastructure inside the UK and EU. Application data and uploaded documents sit in regionally resident storage with automated backups. We do not move customer data outside the UK or EU without a clear lawful basis and, where relevant, appropriate safeguards.
Encryption
All connections to Credbase use TLS 1.2 or above. Documents and structured data are encrypted at rest using industry-standard AES-256. Encryption keys are managed by our infrastructure provider and rotated on their published schedule.
Access control
Access inside Credbase is scoped to the workspace. Team plans include role-based permissions so you can separate reviewers, editors and admins. Internal Credbase access to production systems is limited to a small, named group and requires multi-factor authentication. All privileged access is logged.
Multi-factor authentication for all staff
Least-privilege access for production
Role-based permissions for workspace members
Session and admin activity logging
Tenant separation
Each workspace is logically isolated at the data layer. Every query is scoped to the requesting workspace, enforced by row-level security policies on the database. A user in one workspace cannot read, list or reference documents in another.
Secure upload links
When you request a document, Credbase sends a single-purpose upload link scoped to that request. Links are time-limited, expire after use and can be revoked at any time. Recipients do not need a Credbase account to respond, which reduces friction without compromising the audit trail.
Private document storage
Uploaded documents are stored in private buckets that are not publicly reachable. Access is served through signed, short-lived URLs granted only to authenticated members of the workspace or to recipients of a shared pack link within its validity window.
AI data use
Credbase uses AI to help you organise documents faster. Files may be sent to a vetted AI provider so we can suggest a document type and expiry date. AI suggestions are never saved automatically, a human on your team always approves. We do not use your documents to train third-party foundation models and we do not sell your data.
AI is used for suggestions only
Humans approve before anything is recorded
No training of third-party models on your data
See the AI page for the full statement
Data deletion and export
You can export your workspace data at any time from your account. When you delete a document, company or workspace, we schedule the underlying data for removal from primary storage. Encrypted backups age out on our standard retention cycle, after which residual copies are unrecoverable.
Subprocessors
Credbase relies on a short list of vetted subprocessors for hosting, transactional email, error monitoring and AI-assisted document understanding. A current list is available on request and will be published here as the product matures. Material changes will be notified in advance.
Incident response
We maintain a lightweight incident response process. Suspected incidents are triaged within one working day, contained as a priority and communicated to affected customers without unnecessary delay. Post-incident notes are shared with impacted workspaces, with a clear description of what happened and what changed as a result.
Compliance roadmap
Credbase is built to align with UK GDPR obligations for personal data processed on your behalf. We are not currently ISO 27001 or SOC 2 certified. Formal certification is on our roadmap and we will publish evidence here once it is in place. In the meantime, we are happy to walk buyers through our controls in detail.
Security contact
If you believe you have found a security issue in Credbase, please contact security@credbase.app. We will acknowledge your report within one working day, keep you informed of progress and credit responsible disclosures where welcome.
A note on claims
This page describes controls and practices that are in place today. Credbase does not claim certifications it has not earned. If you need something documented for procurement, email hello@credbase.app and we will get back to you promptly. For the AI-specific policy, see the dedicated AI in Credbase page.
FAQ
Data processing, retention and your rights
Common questions from buyers, DPOs and end users. If we haven't answered yours, email privacy@credbase.app.