Trust & Security

Your workforce data, protected by design.

Everything you need for due diligence, in plain English. If something's missing, email security@feaniks.com and we'll answer directly, not through a portal.

Download the full statement (PDF) Email our security team
At a glance
  • UKApplication data held only in the UK, on Google Cloud in London
  • AES-256Encryption at rest, with TLS 1.2+ for everything in transit
  • Your MFAYour own identity provider's controls flow straight through
  • No poolingYour data is never used to train AI across customers
  • 24 hoursOur target for telling you about a breach affecting your data
  • 7 yearsTraining records kept after your contract ends, at no cost
01

Where your data lives

UK only, fixed by design. Not a preference, and not an option you have to ask for.

United Kingdom · London

Your application data

Staff records, competency evidence, training records, supervisions, observations, feedback and assessments, all held on Google Cloud in London (europe-west2). We run no Feaniks HQ infrastructure outside the UK.

United Kingdom · UK South

Your staff's sign-in

Where your people sign in through Feaniks, a dedicated identity tenant holds sign-in details only: email, MFA status and session tokens. If you connect your own identity provider, no credentials touch Feaniks at all.

Europe · EMEA

Feaniks staff sign-in

Our own team signs in through a separate Microsoft business tenant. No customer data flows to it.

02

Sign-in and multi-factor authentication

Your organisation's staff

MFA is enforced by your own identity provider, and Feaniks never overrides or weakens your controls. Your policy flows into Feaniks HQ automatically, with nothing extra to configure.

Feaniks staff

MFA is enforced for everyone at Feaniks with no exceptions, using the Microsoft Authenticator app. Text-message and voice codes are switched off. Independently verified on 4 August 2026.

Why there's no second "Feaniks MFA"

A second product-controlled layer on top of your own adds little security, but adds recovery problems and one more thing that can fail at 2am when a manager needs urgent access.

Helping you meet the Data Security and Protection Toolkit

4.5.3 (MFA on cloud services): because your MFA flows straight through, Feaniks HQ lets you answer "yes" without extra work. 4.4.1 (least privilege): three separate privileges mean no one needs to be a super-user. Feaniks is currently below the size threshold for its own DSPT return as an IT supplier. If your procurement needs this now, we'll work with you on an appropriate assurance response.

03

Encryption

In transit
TLS 1.2 or higher on every endpoint. Older versions are rejected.
At rest
AES-256 on all data stores, with keys managed by Google Cloud KMS.
Between services
Encrypted channels throughout. Nothing sensitive travels in clear text.
Passwords and secrets
Never stored in plain text. Integration keys sit in Google Cloud Secret Manager with tightly restricted access.
04

Roles and privileges

You decide who sees what, following your real structure.

Admin

Invite users, assign roles, set up your organisation and manage integrations.

Reporting

Exports, Board Pack, audit log extracts and competency evidence packs.

Billing

Credits, licences and seats, invoices and payment details.

Each privilege can be given to anyone independently. A finance controller can hold Billing without ever seeing operational data; a compliance lead can hold Reporting without admin rights. Two safeguards prevent lockout: the Owner's privileges can only be moved by a formal Owner transfer, and no administrator can remove their own Admin privilege.

  • OwnerEverything in your organisation, with all three privileges by default
  • RegionalAcross a defined set of regions or services
  • Service ManagerTheir assigned service
  • Team LeadTheir team, including approving competency evidence
  • StaffTheir own competency and training records
05

Audit logging

Today

Append-only, kept for 12 months or more

Sign-ins, sign-outs and rate-limit events are logged with who, when, where from and what. The log can't be edited, enforced at database level. Feaniks staff look at it only for a specific support ticket or incident, and that access is logged too.

On the roadmap

Every change to every record

Broader coverage of changes to staff records, evidence, training, supervisions and assessments is coming as those areas launch. If your contract needs it sooner, tell us and we'll scope it with you.

06

What we do as your processor

You're the data controller. We're the processor, and we keep to it.

  • We process your data only on your documented instructions, never for our own purposes.
  • We never sell, rent or share it, beyond the sub-processors listed below.
  • We aim to tell you about any breach affecting your data within 24 hours, well inside the 72 hours you have to notify the ICO.
  • We help you answer access, correction and erasure requests.
  • When a contract ends, we return or delete your data as you instruct, with one carve-out for training records (below).
  • Insights such as scheduling suggestions and competency-gap alerts run on your own data, for your benefit, and never on pooled data from other customers.
07

Sub-processors

Listed in full. We give you 30 days' notice of any change.

ProviderWhat it doesWhere
Google CloudHosting, databases and file storage for all application dataUK (London)
Microsoft Entra External IDSign-in for your staff on the Feaniks-hosted path: email, MFA status and session tokens onlyUK South
Microsoft Entra IDSign-in for Feaniks staff only. No customer dataEMEA
LearnWorldsRuns Feaniks World, the learning platform. Your contract stays with Feaniks; completions are stored in Feaniks HQ in the UKContracted by Feaniks
HighLevelEngagement messages and the portable training-record registry. The only sub-processor holding personal data outside the UK, under the UK Extension to the EU-U.S. Data Privacy Framework and Standard Contractual ClausesUnited States
08

Training records that outlast the contract

Care workers shouldn't have to retrain from scratch every time they change employer.

Retention

Seven years, at no extra cost

When a contract ends we keep a narrow training record (course, completion date, certificate reference and learner identifier) for seven years, one year beyond the NHS Records Management Code of Practice. Everything else is returned or deleted under the DPA.

Portability

The previous employer decides

A worker asks their new employer to import their record. We ask the previous employer, who approves or declines. Only training records move. Competency evidence, assessments, observations, supervisions and notes stay with the employer who recorded them.

09

What we don't do

  • Clinical care planning. Feaniks HQ is about your workforce. Where the people you support are mentioned in a record, it's incidental.
  • Text-message or voice MFA codes.
  • Replace your identity provider. Where you connect your own, it stays the source of truth.
  • Train AI on your data across customers.
  • Pool customer data for cross-customer analytics. Any future benchmark will be opt-in, never a default.
10

Certifications

Not yet, and we won't pretend otherwise.

Feaniks doesn't currently hold ISO 27001, SOC 2 or Cyber Essentials Plus. We treat certifications as commitments to make honestly, not logos to display, and we'll pursue them as our scale and customers' needs make it right. If your procurement needs evidence in the shape of one of these standards, talk to us about the equivalent assurance we can give today.

11

Report a security concern

Found something? Tell us directly. We respond within one working day and acknowledge every substantive report in writing.

We don't run a public bug bounty, but we welcome responsible disclosure.

security@feaniks.com

Last updated 5 August 2026 (version 2.4). For the definitive commercial terms, see your Master Subscription Agreement and Data Processing Addendum. Nothing on this page overrides them.