Watch Taking a Sledgehammer to Bottlenecks 🎥 as Ruth & Steph show how AI actually fixes margins.

Compliance Standards

Compliance standards

GoSmarter runs on Microsoft Azure, which is certified against a broad set of compliance frameworks. This page maps the most commonly requested standards to our deployment.

Standards relevance

StandardRelevant?How GoSmarter aligns
GDPRYesAll persistent data in UK South. DPA available. Microsoft sub-processor DPA applies. No AI model training on customer data. See Privacy.
UK GDPR / Data Protection Act 2018YesUK South data residency. EU processing (Sweden Central) within adequacy framework. See Data Residency.
SOC 2 Type IIAzure platform certifiedAzure holds SOC 2 Type II. No current plans to attain this.
ISO 27001Azure platform certifiedAzure holds ISO 27001. Planning to attain GoSmarter application-level certification.
ISO 27017Azure platform certifiedCloud-specific security controls — covered by Azure certification.
ISO 27018Azure platform certifiedPII protection in cloud — covered by Azure certification.
Cyber Essentials PlusAzure platform certifiedUK government security scheme — Azure is certified. Planning to attain GoSmarter application-level certification.
PCI DSSNot applicableGoSmarter does not process, store, or transmit payment card data.
HIPAANot applicableGoSmarter does not process protected health information.
CCPALimited relevanceGoSmarter is B2B with minimal personal data. No California consumer data processing.

What “Azure platform certified” means

When we say Azure is certified, it means:

  • Microsoft has undergone independent third-party audits for the services GoSmarter uses (Azure SQL, Blob Storage, Container Apps, Key Vault, Service Bus, AI services)
  • Audit reports are available through the Microsoft Service Trust Portal
  • These certifications cover the infrastructure, physical security, and platform-level controls

GoSmarter’s application-level controls (authentication, tenant isolation, encryption configuration, AI data handling) are described throughout this trust centre and verified against our infrastructure code.

GDPR alignment summary

GDPR requirementGoSmarter implementation
Lawful basis for processingContractual necessity — processing to deliver the service
Data minimisationLimited personal data: user accounts, audit logs, and document contents
Storage limitationData retained for subscription duration; deletion on termination [VERIFY — process]
Data subject rightsAccess, rectification, erasure supported [VERIFY — specific process]
Data protection by designEncryption at rest and in transit, managed identity, tenant isolation
International transfersUK/EU only — no transfers outside adequacy framework
Breach notificationFor confirmed personal data breaches, customer notification target is within 72 hours of confirmation. UK GDPR/ICO escalation is assessed and, where required, actioned within applicable statutory timelines.
Data Processing AgreementAvailable on request [VERIFY — process]
Sub-processor disclosureMicrosoft Azure is the primary sub-processor

Compliance matrix

For a detailed control-by-control mapping, see the compliance matrix (CSV).

Key points for your security team

  • GDPR / UK GDPR: Fully aligned: UK South residency, DPA available, no international transfers outside adequacy
  • SOC 2 / ISO 27001: Azure platform certified; GoSmarter has no current SOC 2 attestation plan and is planning application-level ISO 27001 certification
  • Incident response notification target: 72 hours for confirmed personal data breaches, with UK GDPR/ICO escalation criteria applied
  • Availability target: 99.99% monthly availability target for the production service
  • PCI DSS / HIPAA: Not applicable: GoSmarter doesn’t handle payment or health data
  • Evidence available: Azure compliance reports via Service Trust Portal; GoSmarter-specific detail in this trust centre

Request evidence

Email us, contact us online, or book a compliance call.