Security & data
Built to survive a review of the tool itself.
A compliance tool has to meet the standard it enforces. Here is exactly how PromoCheck handles your firm’s data, what we store, where it runs, who can see it, and what we deliberately don’t do. No hand-waving, and we’re clear about what is in place today versus on the roadmap.
Your data stays your firm's
- Per-firm isolation. Every check and audit record is scoped to your organisation. Queries are filtered by your firm on the server, so no one outside it can read your promotions, enforced in code and covered by tests, not a setting you can misconfigure.
- Verified sign-in. Access requires a one-time magic link sent to your work email, so a session is only issued to someone who controls that inbox. Sessions are signed and tamper-proof; they cannot be forged client-side.
- No training on your content. Your submitted promotions are used to produce your review and nothing else. They are not used to train models.
We keep as little as possible
- Data minimisation. The audit trail stores a short preview and a cryptographic (SHA-256) hash of each promotion plus the finding, not more than a defensible review requires.
- Defined retention. Audit records are retained for six years to match the FCA's financial-promotion record-keeping expectations, then deleted or anonymised. Account data is kept only while your account is active. You can request export or deletion at any time.
You choose where it runs
- Stated model provider & region. The language-model provider and its processing region are stated plainly on the Privacy page, so your vendor review and DPIA have a straight answer.
- Self-hosted / UK residency option. On the Firm plan, PromoCheck can run against a self-hosted model on your own UK infrastructure, your promotions never leave your estate. The review engine is the same; only where the model runs changes.
- UK-region hosting. The application is deployed with UK-region hosting, or on your own cloud if you self-host the whole service.
Application security
- Hardened HTTP surface. A strict Content-Security-Policy, HSTS, clickjacking protection, and MIME-sniffing protection are set on every response.
- Abuse & cost controls. Per-firm and per-IP rate limits and an input-size cap protect the service (and your bill) from abuse.
- Safe data access & secrets. All database access is parameterised (no injection); billing webhooks are signature-verified; and secrets live in your platform's environment or secret manager, never in the codebase.
Defensible by design
- Grounded, cited findings. Every finding is tied to a specific FCA rule and quotes the exact text that triggered it; findings that can't be grounded are dropped in code. This is verified by an internal evaluation, and the exact-quote integrity is enforced, not hoped for.
- Versioned audit trail. Each review is recorded with the rule-set version applied, so you can evidence which rules were used on a given draft, and when.
- You remain responsible. PromoCheck is decision-support: it does not carry on a regulated activity, approve promotions, or act as your compliance function. Accountability stays with your firm.
What we don’t claim (yet)
We are not going to overstate our posture to win a deal. PromoCheck does not yet hold SOC 2 or ISO 27001 certification, and independent penetration testing is planned, not completed. If your procurement requires these, talk to us about timelines and the on-premise (self-hosted) option, which keeps your data entirely within your own estate today.
Security or data-protection question?
We’re happy to walk your compliance or IT team through any of the above, share our data-processing terms, or scope a self-hosted deployment.