Skip to main content
GreenSlope

Security & trust

Current trust facts, not trust theatre.

This page collects the security and compliance facts a launch evaluator usually needs: company identity, processing region, retention, encryption, Legal Documents, accessibility, and how to report a vulnerability.

§ 01Current posture

What we can honestly say today.

UK-registered company

ESSORIX LTD, trading as GreenSlope. Company number 17307626. Registered in England and Wales. Registered office: 50 Thistle Grove, Welwyn Garden City, England, AL7 4AN.

Single EU processing region

Customer telemetry and account data are processed in a single EU region for launch.

GDPR and UK-GDPR posture

GreenSlope acts as processor for customer telemetry. The DPA, Privacy Policy, and sub-processor list are public.

Retention is deliberately short

Hot spans are short-lived; warm span archive is 30 days. Legal and docs pages describe the retention boundaries.

Encryption

Traffic uses HTTPS/TLS. Data at rest uses managed encryption in the EU processing region.

Accessibility commitment

We self-test against WCAG 2.2 AA patterns and publish an Accessibility Statement.

§ 02Boundaries

What is not claimed at launch.

We would rather be explicit than ask evaluators to discover gaps during procurement.

SOC 2 / ISO 27001 have not yet been pursued. We will not claim readiness, in-progress status, or certification without a signed audit engagement.
HIPAA and BAAs are not supported at launch. Do not send PHI to GreenSlope.
There is no public status page yet. Incidents are communicated by email/support until a real public history exists.
Customer-managed encryption keys and single-tenant deployments are not available on self-serve plans.
§ 03Legal and data handling

The detailed documents are public.

Responsible disclosure

Found something? Tell us directly.

Email security [at] greenslope [dot] io with enough detail to reproduce the issue. We respond within two UK working days.