Security at Graylark
Graylark holds some of the most sensitive material an employer has: consultation documents, works council correspondence, restructuring plans and collective agreements, often long before any of it is public. This page is the short version. The full evidence pack is ready for your security team today.
Last updated: 1 September 2026
Certifications and independent assurance
Cyber Essentials. Certified at Whole Organisation scope, Profile 3.2 (Willow), on 15 October 2025, with recertification due 15 October 2026, through an IASME Cyber Essentials Partner. Whole Organisation means the scope is the entire company, not a carved-out subset.
Independent penetration testing. An external penetration test of the platform was carried out by an independent security firm in 2026. Scope, report and remediation status are shared with customers under NDA.
Internal security testing. A standing internal security baseline runs every quarter across authentication, multi-tenancy isolation, AI safety, secrets posture, cloud security posture and dependency vulnerabilities.
Aligned to ISO 27001. We operate an Information Security Management System aligned to ISO 27001, with external audit targeted for 2027 H2.
Cloud assurance. The platform runs on a major public cloud provider within the European Economic Area, holding ISO 27001, ISO 27017, ISO 27018 and SOC 2. Provider certificates are captured annually as evidence under our ISMS.
Getting Graylark through your procurement process
The hard part usually is not choosing the software. It is getting a new vendor through your own security, privacy and procurement review, and knowing you will personally have to shepherd that for months is enough to stop a lot of worthwhile projects before they start.
We have built the company so that this part is our job, not yours.
The evidence pack is ready now, not in three weeks. Our Customer Security Pack, DPIA information pack, Data Processing Agreement, Transfer Impact Assessments, Cyber Essentials certificate, penetration test report, insurance certificates and full information security policy set are standing documents. When your security team asks, we send them the same day.
We complete your questionnaires. Whatever format your organisation uses, whether a spreadsheet, a supplier assurance portal or your own DPIA template, we fill it in. We have been through full enterprise vendor security assessment and DPA negotiation with a multinational customer, so the questions are familiar ones.
We answer the difficult questions early. Data residency, sub-processor objection rights, encryption key ownership, audit rights, exit and data portability, AI governance, breach notification terms. If there is something we cannot do, you will hear it in the first conversation rather than in week ten.
The deployment can be shaped to your risk appetite. Several of the decisions your DPO will care about are configuration rather than negotiation: customer-managed encryption keys, routing notifications through your own SMTP so our email provider leaves your data path entirely, mandatory multi-factor authentication across your tenant, per-feature and whole-tenant AI off-switches, and country or business-unit scoping of who can see what. We would rather tune those with you up front than have your risk team find them late.
Talk to us before you raise it internally. A short call with your security or privacy lead, before you have to make the case inside your own organisation, is usually the fastest route through. Email security@graylarktechnologies.com and we will work to your template and your timetable.
Where your data lives
Inside the EEA. Primary customer data is stored and processed within the European Economic Area. It is not transferred outside the EEA.
Your own database. Each customer tenant has a dedicated relational database, not a shared table with a filter column. This matters more than it sounds. With shared-schema designs, a single application bug can expose another customer’s rows. With dedicated databases, another tenant’s data is not present to be exposed.
Encrypted throughout. AES-256 encryption at rest and TLS 1.2 or higher in transit. Customer-managed encryption keys are available on request.
Deletion. On termination the tenant database is dropped and document storage is purged, under the terms of the Data Processing Agreement.
Access and identity
Single sign-on. OIDC SSO per tenant, covering Microsoft Entra ID, Okta, Google, or your own OIDC provider.
Multi-factor authentication is available platform-wide and can be made mandatory across your tenant.
Passwords aligned to NIST SP 800-63B and UK NCSC guidance. Length-based rather than composition-based, screened against known breach corpora, and with no calendar-based forced rotation, because forced rotation is well evidenced to produce weaker passwords rather than stronger ones. We rotate on evidence of compromise instead.
Permissions built for employee relations. Access is privilege-based on a default-deny model. On top of that, users can be scoped to particular countries or business units, with read and write scoped independently, so a country HR lead sees their country and no more.
Document confidentiality classification. Every document is classified as Public, Employees, Works Council or Confidential, and role profiles govern which classifications a user can reach.
Administrative access to production is restricted to named administrators through centralised, group-based identity management, with quarterly access reviews and written sign-off.
AI you can put in front of a works council
GrAI is Graylark’s labour-relations AI layer. Its security posture is the reason customers can use it on consultation material.
Inference runs on Graylark-managed infrastructure inside the EEA. There are no calls to external AI APIs in the customer-data path. No third-party model provider receives your consultation documents.
No training on customer data. Models are adapted only with synthetic data, public legal corpora and Graylark-owned examples. This is enforced by code path as well as by policy.
Not an open chatbot. GrAI is a set of bounded services over records the user is already authorised to see. There is no surface that hands an arbitrary prompt to a model with arbitrary context.
A mandatory output-safety layer runs on every AI call. If it cannot run, the call fails and no output is returned.
Prompt-injection defences are tested continuously against an OWASP LLM Top 10 aligned benchmark suite that runs on every build.
Every AI call is recorded in a per-tenant audit log your administrators can browse.
A master off-switch disables every AI surface for your tenant, with per-feature controls beneath it.
No automated decision-making producing legal or similarly significant effects on individuals. GDPR Article 22 negative, contractually committed. Under the EU AI Act risk framework, none of our AI features are classified as high-risk.
Audit and accountability
Privileged operations are recorded in an application audit log capturing actor, action, entity and timestamp. Infrastructure audit logs are held in immutable storage with seven-year retention.
Tenant administrators can browse the AI request audit log directly in the platform. Broader application audit data is available by export on request, with administrator-facing access on the roadmap.
Resilience
Automated daily backups with point-in-time recovery, held in the EU. Recovery point objective under one hour. Recovery time objective four hours for a major incident. Restore validation is exercised on a recurring schedule.
Breach notification
If we confirm a personal data breach affecting your data, we notify your nominated contact in writing within 48 hours, stricter than the 72 hours GDPR Article 33 requires of controllers.
Sub-processors
We use a small number of sub-processors, in these categories:
cloud hosting and managed data services, within the EEA
transactional email delivery, which can be removed from your data path entirely if you prefer to route notifications through your own SMTP
login-page bot protection, which receives commodity request metadata only, never consultation content
The named register is Annex II of the executed Data Processing Agreement, and is provided to customers and to prospects under NDA. We give 14 days’ written notice of any new or replacement sub-processor, with a right of objection.
Available under NDA
Customer Security Pack · Data Processing Agreement · Cyber Essentials certificate · penetration test scope and report · AI Use and Safety Policy · information security policy set · disaster recovery and business continuity plan · incident management runbooks · Transfer Impact Assessments · insurance certificates · architecture documentation for a technical deep-dive.
Talk to us
Security and vendor assessment: security@graylarktechnologies.com
Data protection and privacy: privacy@graylarktechnologies.com
Responsible disclosure. If you believe you have found a security issue in Graylark, email security@graylarktechnologies.com. We acknowledge reports within five business days. We will not pursue action against researchers who report in good faith and who do not access, modify or retain other people’s data.