Trust & Security
Draft — review before publication. See
README.md. This is the public Trust page content (for denainfra.com / a "Security" link). Keep every claim here backed by a real control indocs/security/— never claim more than we operate.
byRazLabs Ltd (trading as "Dena") builds an AI-powered inspection platform for critical river-frontage infrastructure. The people who use it — engineering consultancies and asset owners such as port and transport authorities — trust us with operational data. This page summarises how we protect it.
Our security posture at a glance
- UK data residency. The platform runs on Google Cloud in the **London
(europe-west2) region**.
- Encryption everywhere. Data is encrypted in transit (TLS) and at rest
(provider-managed encryption for databases, object storage, and backups). Report signing uses dedicated managed keys (Cloud KMS).
- Strong tenant isolation. Every customer's data is isolated at the database layer
using PostgreSQL row-level security — each request runs under a tenant-scoped role, not just an application check.
- Least-privilege access + MFA. Access to systems is role-based, least-privilege, and
protected by multi-factor authentication on administrative and cloud-console access. No long-lived cloud service-account keys.
- Resilience. Automated backups with point-in-time recovery and documented,
rehearsed restore procedures.
- Monitoring & audit. Centralised structured logging, distributed tracing, and
monitoring, with retained security audit logs.
- Secure development. Version control, peer review, automated CI checks, and
controlled deployments for every change.
- Privacy by design. We minimise personal data, and we **do not use customer content
to train third-party AI models** — our AI provider is contractually bound not to train on data submitted via its API.
Compliance & certifications — status
We are honest about where we are: Dena is an early-stage company building toward formal certification rather than claiming it.
| Framework | Status |
|---|---|
| UK GDPR / EU GDPR / DPA 2018 | We operate a GDPR program: a published Privacy Policy, a Data Processing Agreement for customers, a sub-processor list, a Record of Processing Activities, and procedures for data-subject requests and breach notification. ICO registration: [TODO]. |
| SOC 2 | In progress / aligned. We have built the underlying control set (the ISMS) and a readiness roadmap. A SOC 2 report is an independent auditor's attestation; we will pursue a Type I then Type II report when a customer requires it. We are not yet SOC 2 audited. |
| ISO/IEC 27001 | Aligned, not certified. Our policies are mapped to ISO 27001:2022 Annex A; certification is a future step. |
We will never describe ourselves as "certified" or "compliant" with a framework we have not been independently assessed against. When we hold a report or certificate, it will be named and dated here.
Sub-processors
The third parties we rely on to deliver the Service (hosting, identity, AI inference) are listed, with their roles and locations, on the sub-processor page. Customers can subscribe to change notifications.
Reporting a vulnerability (responsible disclosure)
We welcome good-faith security research.
- Contact: security@denainfra.com
[TODO: consider a security.txt + PGP key]. - Please do: report privately and give us reasonable time to fix before disclosing;
provide enough detail to reproduce.
- Please don't: access/modify/exfiltrate other users' data, run disruptive tests
(DoS, mass scanning) against production, or use social engineering or physical attacks.
- Our commitment: we will acknowledge your report, keep you updated, and not pursue
good-faith research conducted under these terms.
Asking for more
Prospective and current customers can request our security documentation (DPA, TOMs, policy summaries, and — when available — audit reports) under NDA: security@denainfra.com.
_Last updated: 2026-06-05 (draft). Backed by the ISMS policies and compliance program._