Sign in

Trust & Security

Draft — review before publication. See README.md. This is the public Trust page content (for denainfra.com / a "Security" link). Keep every claim here backed by a real control in docs/security/ — never claim more than we operate.

byRazLabs Ltd (trading as "Dena") builds an AI-powered inspection platform for critical river-frontage infrastructure. The people who use it — engineering consultancies and asset owners such as port and transport authorities — trust us with operational data. This page summarises how we protect it.

Our security posture at a glance

  • UK data residency. The platform runs on Google Cloud in the **London

(europe-west2) region**.

  • Encryption everywhere. Data is encrypted in transit (TLS) and at rest

(provider-managed encryption for databases, object storage, and backups). Report signing uses dedicated managed keys (Cloud KMS).

  • Strong tenant isolation. Every customer's data is isolated at the database layer

using PostgreSQL row-level security — each request runs under a tenant-scoped role, not just an application check.

  • Least-privilege access + MFA. Access to systems is role-based, least-privilege, and

protected by multi-factor authentication on administrative and cloud-console access. No long-lived cloud service-account keys.

  • Resilience. Automated backups with point-in-time recovery and documented,

rehearsed restore procedures.

  • Monitoring & audit. Centralised structured logging, distributed tracing, and

monitoring, with retained security audit logs.

  • Secure development. Version control, peer review, automated CI checks, and

controlled deployments for every change.

  • Privacy by design. We minimise personal data, and we **do not use customer content

to train third-party AI models** — our AI provider is contractually bound not to train on data submitted via its API.

Compliance & certifications — status

We are honest about where we are: Dena is an early-stage company building toward formal certification rather than claiming it.

FrameworkStatus
UK GDPR / EU GDPR / DPA 2018We operate a GDPR program: a published Privacy Policy, a Data Processing Agreement for customers, a sub-processor list, a Record of Processing Activities, and procedures for data-subject requests and breach notification. ICO registration: [TODO].
SOC 2In progress / aligned. We have built the underlying control set (the ISMS) and a readiness roadmap. A SOC 2 report is an independent auditor's attestation; we will pursue a Type I then Type II report when a customer requires it. We are not yet SOC 2 audited.
ISO/IEC 27001Aligned, not certified. Our policies are mapped to ISO 27001:2022 Annex A; certification is a future step.

We will never describe ourselves as "certified" or "compliant" with a framework we have not been independently assessed against. When we hold a report or certificate, it will be named and dated here.

Sub-processors

The third parties we rely on to deliver the Service (hosting, identity, AI inference) are listed, with their roles and locations, on the sub-processor page. Customers can subscribe to change notifications.

Reporting a vulnerability (responsible disclosure)

We welcome good-faith security research.

  • Contact: security@denainfra.com [TODO: consider a security.txt + PGP key].
  • Please do: report privately and give us reasonable time to fix before disclosing;

provide enough detail to reproduce.

  • Please don't: access/modify/exfiltrate other users' data, run disruptive tests

(DoS, mass scanning) against production, or use social engineering or physical attacks.

  • Our commitment: we will acknowledge your report, keep you updated, and not pursue

good-faith research conducted under these terms.

Asking for more

Prospective and current customers can request our security documentation (DPA, TOMs, policy summaries, and — when available — audit reports) under NDA: security@denainfra.com.


_Last updated: 2026-06-05 (draft). Backed by the ISMS policies and compliance program._

© 2026 byRazLabs Ltd (trading as “Dena”). All rights reserved.

PrivacyTermsCookiesDPAAcceptable useSub-processorsSecurity