SECURITY & TRUST FRAMEWORK
Built to Institutional Standards
We protect wealth, not just data. Here is how we approach security, privacy, and compliance at every layer of the platform.
SECURITY PILLARS
Our Approach to Security
🔒
Encryption Everywhere
All data is encrypted in transit using TLS 1.3 (HTTPS). Sensitive data including asset values, serial numbers, and documents is encrypted at rest. Passwords are never stored in plain text.
🎛
Zero-Knowledge Permissions
Collectors own their data entirely. We do not share, sell, or disclose any vault data without explicit, scoped, revocable permission from the data owner. Every access event is logged.
📋
Access Logging (In Development)
Permission grants are timestamped and scoped, and access revocation is immediate. A comprehensive, queryable audit trail covering every platform action — logins, uploads, AI queries — is planned and not yet built; see our Compliance Roadmap below.
🤖
AI Data Minimisation
We send only the minimum necessary data to AI services. Personal identifiers (name, email, account number) are never included in AI prompts. Customer data is never used to train AI models.
🛡
UK GDPR Compliant
We are building in compliance with UK GDPR from day one — not retrofitting it later. Full privacy documentation, subject access request processes, and data deletion procedures are in place.
🔐
Access Controls
Every user sees only what they are authorised to see. Collectors, insurers, family offices, and dealers each have strictly scoped views based on permissions granted by the data owner.
COMPLIANCE ROADMAP
Where We Are & Where We're Going
STAGE 1 — BETA (NOW)
✓HTTPS / TLS encryption
✓Privacy Policy published
✓Terms & Conditions published
✓Permission & access control system
✓AI data minimisation
⏳ICO registration
⏳Company incorporation
⏳MFA for all accounts
⏳Structured audit logging
STAGE 2 — LAUNCH (Q4 2026)
◯AWS cloud migration
◯Cyber Essentials certification
◯Professional penetration test
◯Database encryption at field level
◯Signed URL document access
◯Incident response plan
◯Cyber Essentials Plus
◯Annual security review
STAGE 3 — ENTERPRISE (2027)
◯ISO/IEC 27001 certification
◯SOC 2 Type II audit
◯Disaster Recovery Plan
◯Business Continuity Plan
◯Third-party security assessments
◯Hardware security key support
◯Watermarked document viewing
◯Emergency account lock
DATA SHARING MODEL
Zero-Knowledge Permission Architecture
The collector owns their data. Every access grant is explicit, scoped, time-bound, and revocable. We act as a conduit — not a data broker.
LEVEL 1
Basic Verification
- Asset category confirmed
- Verified existence only
- Estimated value range
- No personal data shared
- No documents shared
LEVEL 2
Full Underwriting Access
- Full asset detail
- Valuation data
- Photographs
- Provenance records
- Condition reports
- Document access
LEVEL 3
Claims Access
- Temporary (30-day) access
- Purchase documents
- Ownership history
- Photographs
- Automatically expires
- Full audit trail
POLICY FRAMEWORK
Security & Compliance Policies
The following policies govern how we operate. Full documents available on request to enterprise partners and institutional clients.
📄
Information Security Policy
Governs how we classify, protect, and handle all information assets across the platform.
🔒
Data Protection Policy
UK GDPR compliance framework including lawful basis, retention schedules, and subject rights.
🎛
Access Control Policy
Role-based access, permission levels, and account privilege management procedures.
🚨
Incident Response Plan
Detection, containment, notification, and recovery procedures for security incidents.
🤖
AI Governance Policy
How we use AI services, data minimisation practices, and limitations on customer data in AI systems.
🏢
Vendor Risk Management
How we assess and manage third-party providers including hosting, AI, and payment services.
💻
Secure Development Policy
Code review, dependency scanning, secret management, and deployment security standards.
🌐
Privacy & Cookie Policy
Published at luxuryassetsindex.com/privacy.html — UK GDPR compliant.
CERTIFICATIONS & STANDARDS
Current & Target Certifications
ACTIVE
HTTPS / TLS 1.3
All data encrypted in transit
IN PROGRESS
ICO Registration
UK data protection registration
PLANNED 2026
Cyber Essentials
UK government-backed certification
PLANNED 2027
ISO/IEC 27001
International security standard