Built GDPR-first, for UK MSPs
All your client data is stored in the UK. We treat security as a product feature β not an afterthought.
UK data residency
All customer data is hosted in London (DigitalOcean LON1); transactional email is sent from AWS London. Certificate-transparency look-ups use the providers listed in our sub-processor register. Error monitoring is self-hosted (GlitchTip) in DigitalOcean LON1.
Encryption at rest
PSA credentials and TOTP secrets are encrypted with AES-256-GCM before storage. TLS 1.2+ enforced for all connections.
Tenant isolation
Every database table has an msp_id column. PostgreSQL Row-Level Security (RLS) is enforced at the database level β not just in application code. A compromised API key cannot read another tenant's data.
Full audit log
Every action β sign-in, config change, certificate renewal, team membership change β is recorded with actor, timestamp, IP address, and entity. Owners and admins can export audit logs as CSV.
Two-factor authentication
TOTP-based 2FA is available for all accounts and can be enforced workspace-wide. TOTP secrets are stored AES-256-GCM encrypted, never in plain text.
PCI-DSS payments
Tidehawk never stores card numbers. All payments are processed by Stripe (PCI-DSS Level 1 certified). Stripe handles tokenisation, 3D Secure, and UK/EU VAT compliance.
Infrastructure at a glance
GDPR compliance
Tidehawk acts as a data processor for the personal data you store (client contacts, team member details). We provide a Data Processing Agreement, support the right to erasure, and offer a full data export for all workspaces.
DPA available
Signed Data Processing Agreement on request
Right to erasure
Account deletion with 30-day retention window
Data export
Full JSON export of all workspace data on demand
Security FAQs
Do you have a Data Processing Agreement (DPA)?βΌ
Is Tidehawk ISO 27001 certified?βΌ
How is PSA credential data protected?βΌ
What happens to data on cancellation?βΌ
How do I report a security vulnerability?βΌ
Security questions?
We are happy to share our security policy documentation and answer due-diligence questions.