Security & Compliance

Security and Trust Centre

RaptorFM is building its security and privacy programme in stages, not shipping a static badge wall. The first layer — UK Cyber Essentials — is already underway, with GDPR, ISO/IEC 27001:2022 and SOC 2 being built in parallel behind it, so procurement teams can see real, current progress rather than a claim.

Request Security & Compliance Pack →
How it fits together

One control environment, four frameworks

Cyber Essentials, GDPR, ISO/IEC 27001 and SOC 2 are not four separate efforts. They share the same underlying control set — access control, encryption, incident response, vendor risk, backups, logging and security policy — built once and reused across every framework.

Which security controls are shared across UK Cyber Essentials, GDPR, ISO/IEC 27001:2022 and SOC 2
ControlCyber EssentialsGDPRISO 27001SOC 2
Access control✓✓✓✓
Multi-factor authentication (MFA)✓✓✓✓
Firewalls & network security✓✓✓✓
Secure configuration & patch management✓✓✓✓
Malware protection✓✓✓✓
Encryption (in transit & at rest)–✓✓✓
Logging & monitoring–✓✓✓
Incident response–✓✓✓
Vendor / third-party risk management–✓✓✓
Backups & disaster recovery–✓✓✓
What's already built

Real, verifiable, in place today

8-tier role-based access control, audited across every API route
Verified multi-tenant data isolation — organisations cannot access each other's data
Encrypted data in transit (TLS) and at rest
Complete audit logging of administrative and privileged actions
Request our Security & Compliance Pack

Get our security overview, DPA, subprocessor list, policy set and current certification status — under NDA where required.

Request the pack →
Documentation

Request our Security & Compliance Pack

Prospective customers' security and procurement teams can request our current documentation directly, under NDA where required.