Security and data
What is done, and what is not.
Frist holds residents’ names, addresses, the condition of their homes and, often, information about their health. That is special category data. A vendor who is vague about it should not be trusted with it, so here is the position stated plainly, including the parts that are unfinished.
Current position
Data residency
In placeCase data, resident records and evidence sit in the Supabase London region.
Row level security on every table
In placeAll 13 tables have RLS enabled. Every operational table carries an org isolation policy on read and write, scoped to the caller's organisation through a security definer function. There is no code path that bypasses it.
ICO registration
In placeOshy Labs Ltd, registration C1892619. Frist acts as processor for the landlord controller.
Data processing agreement
In progressA full Article 28 UK GDPR DPA is drafted as Schedule 1 to the Terms of Service, covering processor obligations, sub processor authorisation, 48 hour breach notification, international transfers, audit rights and the processing annexes. It is drafted and legally reviewed, and awaiting final solicitor sign off. It is signed with you before any resident data is entered.
Transport and application security headers
In placeStrict transport security, frame denial, content type protection, referrer policy and a restrictive permissions policy are set at the edge.
Data protection impact assessment
In progressFrist processes health and vulnerability information about residents, which is special category data under Article 9. A DPIA is being written for that processing. It is not finished, and it is not claimed as finished.
Cyber Essentials
Not yetThe self assessment is scheduled before the first paid contract. Cyber Essentials Plus and a penetration test are deferred until a buyer requires them, and will be done if you require them.
Single sign on
Not yetAvailable on the Scale tier when a customer needs it. Not built speculatively.
Sub processors, all of them
Every third party that can touch data processed on your behalf. There is no unnamed “and our trusted partners” category. You are notified before this list changes.
| Sub processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, authentication and file storage | United Kingdom, London region | None |
| Vercel | Application hosting and edge network | United States, with EU and UK edge | UK IDTA or the UK Addendum to the EU SCCs |
| Anthropic | Drafting the resident written summary from case data | United States | UK IDTA or the UK Addendum to the EU SCCs |
| Stripe | Subscription billing. No resident data reaches Stripe | United States | UK IDTA or the UK Addendum to the EU SCCs |
| Resend | Transactional email to your staff, not to residents | United States | UK IDTA or the UK Addendum to the EU SCCs |
The written summary and AI
The resident written summary is drafted by a large language model from the case record. Three things follow from that, and they are worth being direct about.
- It is a draft. Nothing is sent to a resident without a named person at your organisation reading and approving it.
- Case text is sent to Anthropic in the United States to produce the draft. That transfer is covered by the mechanism in the table above and named in the DPA.
- Your case data is not used to train anyone’s model.
Reporting something
If you find a vulnerability, email arnold.oshenye@oshylabs.eu with enough detail to reproduce it. There is no bug bounty. There is a person who reads that inbox and will answer you.
A personal data breach affecting your residents is notified to you within 48 hours of Frist becoming aware, under the DPA.