Trust

Security and data handling

What is actually implemented in the platform today, stated plainly. We make no certification or audit claims.

Last updated 1 September 2026

Tenant isolation

Every organisation has its own workspace. Decisions, evidence, uploaded material, councils and decision records are scoped to that organisation and enforced at the database level with row-level security policies — not only in application code. A consultant working across several clients sees each client's work separately.

Isolation is covered by an automated test suite that attempts cross-organisation reads and writes across every user-facing table and fails the build if any of them succeed.

Access control

Access requires an authenticated session. Sign-in is available by email and by Google. Every server call is authorised against the signed-in user's identity; ownership is derived from the verified session, never from values supplied by the browser.

Uploaded material

Files you upload are stored in private buckets with no public access. They are served only through short-lived signed links issued to a user who is authorised for that organisation.

Encryption and hosting

All traffic is served over TLS. The database and file storage are hosted in the European Union (Ireland) and encrypted at rest by the underlying infrastructure provider.

The platform assistant

The in-product assistant can only read data belonging to the organisation the signed-in user is currently working in. It cannot query another organisation's decisions, evidence or records.

What this does not do

Decision content, briefs, evidence and notes are stored as readable text so the platform can search them and generate outputs from them. Personnel with infrastructure credentials are technically capable of reading that content. The protections against this are least privilege, logged administrator access the customer's own owner can see, confidentiality obligations and our data processing agreement — not encryption that would make the content unreadable to us. We hold no SOC 2, ISO 27001 or HIPAA certification and none is in progress.

Sub-processors

Every third party that processes customer data is named, with its purpose and location, on our sub-processors page. Your decision content is not used to train general-purpose models.

Documents for procurement

Our pre-answered security questionnaire and data processing agreement are published, and the dated isolation test report is available on request. Everything is collected in the trust centre.

Reporting a vulnerability

If you believe you have found a security issue, email security@personalobby.ie with enough detail to reproduce it. We will acknowledge within three working days. Please do not disclose publicly before we have had a chance to respond.