Trust Centre

Private by default. Clear about what we do with your data.

Credbase holds documents on behalf of your suppliers, subcontractors, vendors and partners. This page explains how we protect that trust: how the product is built, where data lives and how you stay in control.

Security overview

Credbase is designed to hold third-party business documents on behalf of small and mid-sized teams. Security is treated as a product feature, not an afterthought. Every workspace is private by default and every document is protected in transit and at rest.

  • Private-by-default workspaces
  • Encryption in transit and at rest
  • Role-based access with audit trail
  • Regular internal security review

Data hosting

Credbase is hosted on managed cloud infrastructure inside the UK and EU. Application data and uploaded documents sit in regionally resident storage with automated backups. We do not move customer data outside the UK or EU without a clear lawful basis and, where relevant, appropriate safeguards.

Encryption

All connections to Credbase use TLS 1.2 or above. Documents and structured data are encrypted at rest using industry-standard AES-256. Encryption keys are managed by our infrastructure provider and rotated on their published schedule.

Access control

Access inside Credbase is scoped to the workspace. Team plans include role-based permissions so you can separate reviewers, editors and admins. Internal Credbase access to production systems is limited to a small, named group and requires multi-factor authentication. All privileged access is logged.

  • Multi-factor authentication for all staff
  • Least-privilege access for production
  • Role-based permissions for workspace members
  • Session and admin activity logging

Tenant separation

Each workspace is logically isolated at the data layer. Every query is scoped to the requesting workspace, enforced by row-level security policies on the database. A user in one workspace cannot read, list or reference documents in another.

Private document storage

Uploaded documents are stored in private buckets that are not publicly reachable. Access is served through signed, short-lived URLs granted only to authenticated members of the workspace or to recipients of a shared pack link within its validity window.

AI data use

Credbase uses AI to help you organise documents faster. Files may be sent to a vetted AI provider so we can suggest a document type and expiry date. AI suggestions are never saved automatically, a human on your team always approves. We do not use your documents to train third-party foundation models and we do not sell your data.

  • AI is used for suggestions only
  • Humans approve before anything is recorded
  • No training of third-party models on your data
  • See the AI page for the full statement

Data deletion and export

You can export your workspace data at any time from your account. When you delete a document, company or workspace, we schedule the underlying data for removal from primary storage. Encrypted backups age out on our standard retention cycle, after which residual copies are unrecoverable.

Subprocessors

Credbase relies on a short list of vetted subprocessors for hosting, transactional email, error monitoring and AI-assisted document understanding. A current list is available on request and will be published here as the product matures. Material changes will be notified in advance.

Incident response

We maintain a lightweight incident response process. Suspected incidents are triaged within one working day, contained as a priority and communicated to affected customers without unnecessary delay. Post-incident notes are shared with impacted workspaces, with a clear description of what happened and what changed as a result.

Compliance roadmap

Credbase is built to align with UK GDPR obligations for personal data processed on your behalf. We are not currently ISO 27001 or SOC 2 certified. Formal certification is on our roadmap and we will publish evidence here once it is in place. In the meantime, we are happy to walk buyers through our controls in detail.

Security contact

If you believe you have found a security issue in Credbase, please contact security@credbase.app. We will acknowledge your report within one working day, keep you informed of progress and credit responsible disclosures where welcome.

A note on claims

This page describes controls and practices that are in place today. Credbase does not claim certifications it has not earned. If you need something documented for procurement, email hello@credbase.app and we will get back to you promptly. For the AI-specific policy, see the dedicated AI in Credbase page.

FAQ

Data processing, retention and your rights

Common questions from buyers, DPOs and end users. If we haven't answered yours, email privacy@credbase.app.