Security & compliance posture

Built for procurement,
not for marketing.

Procurement, DPO, and CISO reviews ask the same questions in different orders. This page answers them in one place. Where the answer is "we have not done this yet", it says so. Where the answer is "this is enforced cryptographically, not by convention", it says that too.

Last updated: April 2026. For DPA, security questionnaire, or DPIA support, email compliance@79thunit.com.

01 · Jurisdiction

Data lives where UK/EU law applies.

02 · Infrastructure

Single-server discipline. Documented exit ramps.

03 · Cryptography

Signing keys are the differentiator.

04 · Auth, RBAC, and the audit log

Identity is Keycloak. Audit is append-only.

05 · Sub-processors

Three named processors. All under DPA.

Processor Purpose Jurisdiction DPA
OVHcloud SAS Primary hosting (bare metal, Roubaix) France (EU) In place
Hetzner Online GmbH DR mirror and external uptime monitor Germany (EU) In place
Anthropic PBC LLM inference for analyst-opted-in routes only USA (with EU data clauses) In place; analyst opt-in required per route
Stripe Payments UK Ltd Subscription billing UK In place; PCI-DSS Level 1

Anthropic is the single non-EU processor and is opt-in per analyst per route. No personal data leaves the EU on default routes. Stripe receives only what it needs to charge the subscription; card data never reaches CLEARSKY.

06 · Backup & DR

Three independent copies. One immutable.

07 · Subject rights

UK GDPR served by default, not as an afterthought.

08 · Vulnerability disclosure

Coordinated disclosure, no bounty yet.

09 · Incident response

72-hour notification, written into the schema.

10 · Certifications and roadmap

What we have, what we are working towards.

Contact

Procurement, DPO, security review.

Email compliance@79thunit.com for DPA, DPIA support, security questionnaires, sub-processor audits, or pen-test scoping. The same address handles ICO referrals and subject-rights escalations. Expect a working-day reply.