Security & Trust

Finance data is the most sensitive in the business. Pythia is built and operated to protect it, with a formal information security program behind the platform. This page summarises our certifications, our approach to data protection, and the documentation we can share with prospective and current customers.

Certifications & compliance

  • Cyber Essentials: we have completed Cyber Essentials, the UK government-backed scheme that independently assesses an organisation against a baseline of security controls.
  • GDPR: we are built and operated in line with UK and EU GDPR. Personal data is processed under a Data Processing Agreement, stored on EU infrastructure, and subject to the access, correction, deletion, and export rights set out in our Privacy Policy.
  • ISO 27001 & SOC 2: both are in progress.

How we protect your data

The platform is architected to meet the standards your security team expects:

  • Encryption: all data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Private by default: your models are never used to train foundation models. Model content sent for evaluation is processed under zero-data-retention terms.
  • Regional data residency: hosting in the EU, US, or UK - you decide.

Documentation available on request

We maintain a full suite of security and data protection documentation. These documents are available to prospective and current customers on request:

  • Data Processing AgreementGoverns how we process personal data on your behalf, including sub-processors, data residency, and your rights under UK and EU GDPR.
  • Access Control PolicyDefines who can access systems and data, and the least-privilege controls that enforce it.
  • Business Continuity & Recovery PlanHow we maintain service and recover data in the event of disruption, including backup and restore procedures.
  • Data Privacy PolicyHow personal data is collected, used, retained, and protected across the business.
  • Incident Response PlanHow we detect, contain, investigate, and communicate security incidents.
  • Information Security PolicyThe overarching framework governing our security controls, responsibilities, and review cycle.

Request our documentation

To request any of the documents above, email admin@getpythia.co.uk.