Security and data
An AI Assessment means letting us look inside how your business runs. This page sets out what we can see, where it goes, who touches it and when it is deleted.
How we access your systems
Read-only. During an assessment we look at your systems, we do not change them.
Access runs on credentials your own team issues, scoped to the named mailboxes and tools we agreed in advance. You can revoke them at any moment, without telling us first and without giving a reason. We never hold permission to send email from one of your mailboxes. If we go on to build something, any write access, for example creating a task in your project tool, is agreed in writing first, scoped to that one named action, and logged.
Where your data lives
Assessment working data sits in a Postgres database hosted by Supabase in London, region eu-west-2. Your client portal and our backend services run on Railway in the EU, region europe-west4, in Amsterdam. Email, documents, calendar and e-signature run on Google Workspace. Meeting recordings and transcripts sit in Fathom.
Certifications, as published by each provider: Supabase holds ISO 27001:2022 and SOC 2 Type II. Railway holds SOC 2 Type II and SOC 3. Google Workspace holds ISO 27001, 27017, 27018 and 27701, plus SOC 2 and SOC 3. Anthropic holds ISO 27001:2022, ISO 42001 and SOC 2 Type II. The full sub-processor list is yours on request.
Working files may be opened on a company laptop during an assessment. That laptop runs full-disk encryption, a screen lock and a password manager. The system of record is the London database.
What the AI sees
Language model processing runs on the Anthropic API. Our commercial terms with Anthropic state that your content is not used to train models, and zero data retention is enabled on our account: prompts and responses are not stored by Anthropic after the response is returned. That is a setting on our organisation, and you can ask us to show it.
The models read what we point them at and write findings for us. No outbound communication to your customers is ever generated or sent by our systems. Replies to your customers are written by your own people, from your own accounts, in your own words.
How long we keep it
We typically review the last 90 days of historical records, and may review such further data as is reasonably needed, telling you when we do.
Working data, meaning exports, copies and extracted records, is deleted within 14 days of your readout meeting, and Olly confirms that deletion in writing. Recordings and transcripts are kept as our record of the engagement, with your knowledge, and deleted on written request. Deliverables are kept as our work product; they contain your quotes and figures, so they are yours to keep too. Contracts and invoices are kept for six years because the law requires it. Backups are managed by our providers and age out on their schedule.
Who is accountable
Olly Sleep, Director of Inreachly Ltd, is the data protection lead and the named accountable person. He runs every assessment and holds your credentials. Two build engineers, Adam Goodyer and Roko, work under signed confidentiality and intellectual property agreements; their access is granted per engagement, scoped, and revoked by Olly at the end. Nobody else. No offshore teams and no account managers.
If anything goes wrong, meaning any actual or suspected unauthorised access, loss, disclosure or alteration of your data, we tell you within 24 hours of becoming aware, by email and by phone, with what we know, what we have done and what happens next. As the data controller, the decision to notify the ICO is yours. Olly owns the response and completes a review within seven days.
What we will sign
A data processing agreement on UK GDPR Article 28 terms. A mutual non-disclosure agreement. Your own supplier security schedule or data protection addendum, where you have one, subject to a read. Our agreements are governed by the law of England and Wales, and the same obligations flow down to our subcontractors. Our privacy notice and terms sit alongside them.
Certifications
Straight answer: Inreachly Ltd holds no security certification of its own, and we would rather tell you that than imply otherwise. What is certified is every provider that stores your data, listed above: ISO 27001 or SOC 2 Type II in each case.
We do not hold Cyber Essentials or ISO 27001 ourselves. Every provider that stores your data does.
Questions
If your IT function or your insurer needs something this page does not cover, email [email protected] and you will get a direct answer, not a brochure.