Trust Centre

Everything a procurement or compliance team needs to evaluate CoverProof in one place — who we rely on, the terms we process your data under, and a candid view of our certification status.

Last updated: 27 May 2026

At a glance

Sub-processors

These are the third parties that process data to deliver CoverProof. We will update this list before adding a new sub-processor.

Sub-processorPurposeLocation
RailwayApplication hosting and managed PostgreSQL databaseUnited States
Cloudflare R2Encrypted storage of generated board evidence-pack PDFsConfigurable region
AnthropicAI classification of SM&CR gap analysis (Claude API)United States
ResendTransactional email (magic-links, declaration invites, reminders)United States
StripeSubscription billing and payment processingUnited States / UK
PostHogConsent-gated, IP-anonymised product analyticsEuropean Union

Data Processing Agreement

For firms (our controllers), our Data Processing Agreement sets out how we process personal data on your behalf, including security measures, sub-processor terms, and international-transfer safeguards. To request a countersigned copy for your records, email privacy@coverproof.co.uk.

Certifications roadmap — current status, not a claim

We will not display a badge we have not earned. CoverProof holds no third-party security certification today. The following is a forward-looking roadmap, not a statement of current compliance:

ProgrammeStatus
Independent penetration testPlanned — not yet commissioned
SOC 2 Type IIRoadmap — not started
ISO/IEC 27001Roadmap — not started