Security and certification
Independently audited security posture, not marketing claims. Certifications count only where the provider names the standard on its own site.
What we check (8)
- ISO/IEC 27001 certification held and stated publicly
- SOC 2 Type II report available
- Cyber Essentials or Cyber Essentials Plus, the UK government scheme increasingly required in public sector and regulated procurement
- Encryption at rest and in transit, with the standard named
- Granular folder and document level permissions
- Dynamic watermarking, download control and screenshot protection
- Two-factor authentication and SSO
- Complete, exportable audit trail
ISO 27001 and SOC 2 Type II both held, AES-256 named, full permission and watermarking controls, audit log exportable.
No named certification, vague encryption claims, or controls only available on an enterprise tier.