Advanced Features
We apply enterprise-grade security practices throughout our technology infrastructure and business processes.

We use 256-bit encryption for all data in transit. All connections are protected using TLS 1.3 with a AES 256-bit symmetric encryption and 2048-bit authenticated key agreement.
Data is also encrypted at rest in the same way and we rotate volume keys on a regular basis using a key management system, meaning your data is never available in plain text.
We regularly test our network and verify our supported cipher suites with external audits, the results of which are publicly available.

We allow clients to control access to their workflow with advanced user role-based permissions.
Clients are able to match permissions to job functions based on the Principle of Least Privilege (PoLP), ensuring best practice for high value data and assets.
All user passwords are also masked with a separate salt and encrypted with bcrypt, along with have enforced minimums for length and complexity.

All our systems and processes are GDPR compliant, in accordance with our privacy agreement.
We also offer best in class data processing agreements for all clients, with back-to-back DPAs across our suppliers, so your data-processing obligations are covered end to end.

InsiderList is certified to both ISO 27001 (Information Security) and ISO 9001 (Quality Management) standards.
Our dual certification demonstrates our commitment to protecting your sensitive data while delivering consistent, high-quality service.
We also maintain Cyber Essentials certification, backed by the National Cyber Security Centre. Our infrastructure runs on AWS, whose data centres maintain independent security attestations.
InsiderList is designed with security first. We employ a comprehensive Information Security Management System (ISMS) ensuring first class industry standards
All the code produced for our core services follows OWASP guidelines and recommendations, preventing common security issues such as cross site scripting (XSS) or SQL injections.
Every code change is signed, tracked in a versioning system and covered by a change management policy, which requires peer code review. Similarly, publishing rights are limited to a small group of maintainers.
We scan for vulnerabilities and actively monitor for new threats. We use static code analyser tools and software dependency scanners to detect issues and vulnerabilities.
All of our services are actively monitored and logged. We review alerts from these systems as well as application logs on a regular basis to look for unusual or suspicious activity.
InsiderList was created with the goal of disaster recovery in mind. Our infrastructure and data are distributed across multiple availability zones and will continue to function if any of those data centres fails.
We have a procedure in place for dealing with information security incidents that includes escalation procedures, rapid mitigation, and communication.
Advanced Security
We are dedicated to improving our security through continuous review.
We perform an independent third-party penetration test annually to ensure that the security of our services is uncompromised.
We continuously monitor our security and compliance status to ensure there are no lapses.
Our information security program is a core part of our operations and follows criteria in line with ISO 27001.
We provision all roles and responsibilities on a principal of least privilege, ensuring individuals are only given access required to complete specific tasks.
Our team members are required to go through employee security awareness training covering industry standard practices and information security topics such as phishing and password management.
We maintain a robust compliance program to ensure adherence to relevant industry standards and regulations, conducting regular audits and assessments.
Please download our security documentation if you want more information about our security or want to share it with others.
Download