SECURITY & TRUST FRAMEWORK

Built to Institutional Standards

We protect wealth, not just data. Here is how we approach security, privacy, and compliance at every layer of the platform.

SECURITY PILLARS

Our Approach to Security

🔒

Encryption Everywhere

All data is encrypted in transit using TLS 1.3 (HTTPS). Sensitive data including asset values, serial numbers, and documents is encrypted at rest. Passwords are never stored in plain text.

🎛

Zero-Knowledge Permissions

Collectors own their data entirely. We do not share, sell, or disclose any vault data without explicit, scoped, revocable permission from the data owner. Every access event is logged.

📋

Access Logging (In Development)

Permission grants are timestamped and scoped, and access revocation is immediate. A comprehensive, queryable audit trail covering every platform action — logins, uploads, AI queries — is planned and not yet built; see our Compliance Roadmap below.

🤖

AI Data Minimisation

We send only the minimum necessary data to AI services. Personal identifiers (name, email, account number) are never included in AI prompts. Customer data is never used to train AI models.

🛡

UK GDPR Compliant

We are building in compliance with UK GDPR from day one — not retrofitting it later. Full privacy documentation, subject access request processes, and data deletion procedures are in place.

🔐

Access Controls

Every user sees only what they are authorised to see. Collectors, insurers, family offices, and dealers each have strictly scoped views based on permissions granted by the data owner.

Where We Are & Where We're Going

STAGE 1 — BETA (NOW)

HTTPS / TLS encryption
Privacy Policy published
Terms & Conditions published
Permission & access control system
AI data minimisation
ICO registration
Company incorporation
MFA for all accounts
Structured audit logging

STAGE 2 — LAUNCH (Q4 2026)

AWS cloud migration
Cyber Essentials certification
Professional penetration test
Database encryption at field level
Signed URL document access
Incident response plan
Cyber Essentials Plus
Annual security review

STAGE 3 — ENTERPRISE (2027)

ISO/IEC 27001 certification
SOC 2 Type II audit
Disaster Recovery Plan
Business Continuity Plan
Third-party security assessments
Hardware security key support
Watermarked document viewing
Emergency account lock

Zero-Knowledge Permission Architecture

The collector owns their data. Every access grant is explicit, scoped, time-bound, and revocable. We act as a conduit — not a data broker.

LEVEL 1

Basic Verification

  • Asset category confirmed
  • Verified existence only
  • Estimated value range
  • No personal data shared
  • No documents shared
LEVEL 2

Full Underwriting Access

  • Full asset detail
  • Valuation data
  • Photographs
  • Provenance records
  • Condition reports
  • Document access
LEVEL 3

Claims Access

  • Temporary (30-day) access
  • Purchase documents
  • Ownership history
  • Photographs
  • Automatically expires
  • Full audit trail
POLICY FRAMEWORK

Security & Compliance Policies

The following policies govern how we operate. Full documents available on request to enterprise partners and institutional clients.

📄
Information Security Policy
Governs how we classify, protect, and handle all information assets across the platform.
🔒
Data Protection Policy
UK GDPR compliance framework including lawful basis, retention schedules, and subject rights.
🎛
Access Control Policy
Role-based access, permission levels, and account privilege management procedures.
🚨
Incident Response Plan
Detection, containment, notification, and recovery procedures for security incidents.
🤖
AI Governance Policy
How we use AI services, data minimisation practices, and limitations on customer data in AI systems.
🏢
Vendor Risk Management
How we assess and manage third-party providers including hosting, AI, and payment services.
💻
Secure Development Policy
Code review, dependency scanning, secret management, and deployment security standards.
🌐
Privacy & Cookie Policy
Published at luxuryassetsindex.com/privacy.html — UK GDPR compliant.
CERTIFICATIONS & STANDARDS

Current & Target Certifications

ACTIVE
HTTPS / TLS 1.3
All data encrypted in transit
IN PROGRESS
ICO Registration
UK data protection registration
PLANNED 2026
Cyber Essentials
UK government-backed certification
PLANNED 2027
ISO/IEC 27001
International security standard


Security Questions?

For security enquiries, vulnerability reports, or enterprise compliance questions, contact our team directly.

admin@luxuryassetsindex.com