Trust Center
Operationally sensitive data, handled properly
UK housebuilders, contractors and housing providers trust Ubrix with buyer records, contractor coordination and audit-grade compliance evidence. This page collects the certifications, practices and documents your procurement team needs, in one place.
At a glance
Certifications and cover
Cyber Essentials
Current certification against the UK Government-backed baseline for the five core technical controls.
Certificate 726311be-0ee0-4009-a404-1d5ae226dcc1
UK GDPR aligned
Operates in alignment with the UK GDPR and the Data Protection Act 2018. ICO registration on file.
DPA registered
UK-hosted
Runs on Microsoft Azure UK South region by default. Customer data stays within the UK unless explicitly agreed.
Azure UK region
Insured to £1m
Professional Indemnity, Cyber Liability and Technology E&O cover through CFC Underwriting.
Certificates on request
The four pillars
What trust looks like at Ubrix
Security
How your data is protected
Encryption in transit and at rest, role-based access, single-tenant logical separation, continuous monitoring and least-privilege access for the Ubrix team.
See our security practicesPrivacy
How we treat personal data
Ubrix operates under UK GDPR and the Data Protection Act 2018. Personal data is processed lawfully, transparently and only for the purposes set out in the service agreement.
Read the privacy policyData processing
How Ubrix processes your data
The standard Ubrix Data Processing Addendum is available on request and signed as part of contracting for customers who require one.
Read data processing termsCompliance
How Ubrix helps you stay compliant
Building Regulations, Building Safety Act, NHQC, Future Homes Standard and NHBC compliance built into how the platform works, evidence-first.
See compliance coverageOperational commitments
What you can expect day to day
The commitments below are how Ubrix operates every day, not aspirational statements. If something changes here, we tell customers directly rather than update this page quietly.
99.9% uptime target
Measured monthly, excluding announced maintenance windows. Continuous monitoring, alerting outside working hours.
Live statusLeast-privilege staff access
Access to customer data by the Ubrix team is restricted to what is strictly required for support, and every access event is logged.
Data stays in the UK
Hosted in Microsoft Azure UK South by default. Sub-processor relationships are documented and available on request.
Responsible disclosure
The Ubrix team welcomes and acknowledges reports from security researchers acting in good faith.
security@ubrix.co.ukFor procurement
Documents available on request
The team is happy to complete standard vendor questionnaires and share the documents below to help procurement move quickly. Signed NDAs are handled at request.
- Cyber Essentials certificate
- Insurance certificates
- Data Processing Addendum
- Sub-processor list
- Penetration test summary (under NDA)
- Completed vendor questionnaire
Procurement contact
trust@ubrix.co.ukFAQ
Trust and procurement questions
Can you complete our vendor security questionnaire?
Yes. The Ubrix team completes standard customer security questionnaires as part of a procurement process, typically within five working days of receipt.
Where is our data hosted?
Customer data is stored in Microsoft Azure UK South region by default. Data is not transferred outside the UK without explicit customer agreement, and sub-processor relationships are documented and available on request.
Do you have a Data Processing Addendum we can sign?
Yes. The standard Ubrix Data Processing Addendum is available on request and is signed as part of the contracting process for customers who require one.
Are you SOC 2 or ISO 27001 certified?
Ubrix is not currently certified against SOC 2 or ISO 27001, but operates many of the same underlying controls as part of its Cyber Essentials certification and day-to-day practices. Formal certification against one or both standards is on the roadmap as the business scales.
Can we see a penetration test summary?
Penetration testing is conducted on a regular cadence, and summary reports are available under NDA to customers evaluating the platform at scale.
What happens to our data if we leave?
Customer data belongs to the customer. Standard exports are available on request throughout the contract and at exit, with no lock-in clauses.
Need something for your procurement process?
The team completes vendor questionnaires and shares documentation under NDA. Send us what you need and we will turn it around promptly.