Security & Compliance

Shout is a privacy-first platform where data protection and security are engineered into all of our tools. We're compliant with the GDPR, UK-GDPR, CCPA, and other international data protection regulations.

Compliance Standards We Meet

GDPR

General Data Protection Regulation compliance for EU and international data subjects.

UK-GDPR

UK General Data Protection Regulation compliance post-Brexit.

CCPA

California Consumer Privacy Act compliance for California residents.

Core Security Infrastructure

UK-Based Hosting

Our production server is hosted in the UK. All development and support is conducted from the UK. Encrypted backups are stored in Microsoft Azure with geo-redundancy.

  • ISO 27001:2022 certified data centre
  • 24/7 physical security and monitoring
  • CCTV, access cards, and backup generators

Encryption

All data is protected with strong encryption standards, both in transit and at rest.

  • TLS 1.3 in transit via Cloudflare
  • AES 256-bit encryption at rest
  • Full disk encryption on all staff devices

Network Security

Multiple layers of network protection sit between the internet and your data.

  • Cloudflare DDoS protection
  • Firewall protected
  • Encrypted mesh VPN for remote access

Business Continuity

We ensure your data is always available and recoverable.

  • Incremental backups every 15 minutes
  • Geo-redundant backup storage on Azure

Zero-Trust Security Framework

We operate a zero-trust security framework, which requires all users to be authenticated, authorised, and continuously validated for security configuration and posture before being granted or keeping access to applications and data.

Two-Factor Authentication

TOTP-based 2FA enforced on all devices and servers

Single Sign-On (SSO)

Google Workspace SSO with Cloudflare Access for admin areas

Least Privilege

Conditional access with minimal permissions for all users

Device Management

Centrally managed devices with endpoint detection and compliance monitoring

Modern Development Practices

Hardened Linux Workstations

All development is done on hardened Linux machines with full disk encryption, centrally managed policies, and endpoint detection.

CI/CD Pipelines

All code changes go through automated build and deployment pipelines. No manual deployments to production.

Code Review

Every change is peer reviewed before it reaches production. All work is tracked in version control with a full audit trail.

Built-In Compliance Features

Compliance Groups

Group contacts by lawful basis for processing their data.

Record Consent

Collect and record explicit consent directly to contact profiles.

Pseudonymize PII

Separate personal data from response data for maximum compliance.

Right to Deletion

Automatically purge PII from reports when deleting contacts.

Need More Information?

Have questions about our security or compliance measures? Our team is here to help.

help@shout.com