Security & Data

How Sense keeps your workforce data secure

Our company is an ISO27001-certified supplier, with UK-hosted infrastructure for GDPR compliance, and an enclosed AI data environment that never trains on your data.

UK-Hosted

Data never leaves the country

ISO27001

Audited annually

Enclosed AI

Never trained on your data

Hosting Infrastructure

Built and hosted in the United Kingdom

Sense Workplace is a British-built platform. All data that passes through is processed and stored by UK-based infrastructure, and is never routed through US or EU data centres. This ensures everything from your HR records and your timesheet entries to your location data and your AI queries, remains safe, secure, and compliant.

UK Data Residency

All data stored and processed in British data centres, with no cross-border data transfer. Fully compatible with UK GDPR and NHS or government data frameworks.

ISO27001 Certified

Our annual third-party audit covers our platform, infrastructure and internal processes, to ensure they meet internationally-recognised security standards.

SOC 2 Aligned

Our controls are designed and audited against SOC 2 Type II criteria for security, availability, and confidentiality – available on request for enterprise.

Penetration Tested

Annual independent pen-testing by CREST-certified testers, with results and remediation evidence available to enterprise customers (under NDA.)

End-to-end Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Location signals from hardware devices are encrypted before they leave the device.

99.9% Uptime

Guaranteed uptime as a service level agreement, with a real-time status page, automatic failover, and 24/7 infrastructure monitoring. Credits if SLA is breached.

GDPR & Privacy

Keep Your Sensitive Data GDPR Compliant

Collecting HR data and real-time location information is a significant responsibility, which is why we've built GDPR compliance into the platform's architecture. Here's how we protect your workers' rights while giving you the operational visibility you need.

Worker Transparency

Each worker tracked by Sense can see their own location history, check-in records, and whatever other data is stored about them, from directly within the Sense Workplace app.

Consent & Notification

Sense provides templates for worker notification consent documentation and DPIA (Data Protection Impact Assessment) records, designed by our team of Data Protection Officers.

Retention Policies

Automate data retention, and set sensitive data such as location information to be auto-deleted after 30, 60, or 90 days, with audit logs retained for the periods required by UK law.

Right to Erasure

When an employee leaves, Sense supports GDPR right-to-erasure laws, with workflows that remove personal data while retaining anonymised operational records for compliance.

AI Security

Practical AI Tools in a Secure, Contained Environment

Sense AI runs in a closed, UK-hosted inference environment. Your data is used generate answers. It stays within your customer account, and is never used to train future models.

What Sense AI does Status
Reads your company's own documents to answer questions ✓ Yes
Stores AI query logs for audit purposes ✓ Yes
Operates in a closed, UK-hosted environment ✓ Yes
Uses your data to train or improve models ✗ Never
Shares query data with other customers' environments ✗ Never
Routes queries through US or EU infrastructure ✗ Never
For IT & Procurement Teams

Let us help you complete your technical evaluation

We know that enterprise procurement requires more than just a flashy sales demo. Our technical teams can work with you to provide everything your IT, security and legal teams need, including:

Architecture overview

System architecture diagram, data flow documentation, and infrastructure spec.

Security questionnaire

Pre-completed SIG (Standardised Information Gathering) questionnaire.

ISO27001 Certificate

Full certification and scope documentation, available under NDA.

Penetration Test Summary

Executive summary of latest pen test findings and remediation status.

GDPR & DPA Documentation

Data Processing Agreement, sub-processor list, and DPIA template.

Reference Customers

IT and security leads at comparable organisations available for reference calls.

Talk to an Expert About Data Security

If you have more questions, you can request more information, or even book a quick call with our DPO who will happily answer your questions.