AI Governance: Building a Defensible Governance Framework — 22 Apr

Register Now →

Platform · Security & Trust

Enterprise-grade security
built in from day one.

Your governance data is mission-critical. SustainGRC is designed for regulated industries where audit trails, data sovereignty, and access controls are non-negotiable — not bolt-ons added after the fact.


ISO 27001:2022 Compliant
Cyber Essentials Plus
GDPR Compliant
Azure-hosted Infrastructure
Document & Policy Vault

99.9%

Uptime SLA

AES-256

Encryption standard

72hr

Breach notification

Bi-annual

Pen testing cadence

7yr

Audit log archive

30 min

P1 incident response

Security by Architecture

Security isn't a feature we layered on top — it's the reason the platform architecture looks the way it does. Immutable audit logs, tenant isolation, and separation of duties are structural properties of the platform, not configuration options.

Data Encryption

  • correct

    AES-256 encryption at rest across all data stores

  • correct

    TLS 1.3 in transit — no exceptions for internal services

  • correct

    Field-level encryption for sensitive disclosures and financial data

  • correct

    Encryption key management via Azure Key Vault with BYOK option

Identity & Access

  • correct

    SAML 2.0 and OIDC SSO — compatible with Entra ID, Okta, Ping

  • correct

    Role-based access control enforced at the API layer

  • correct

    Separation of duties baked into all governance workflows

  • correct

    MFA mandatory for all admin and approver roles

Audit & Monitoring

  • correct

    Immutable audit log for every data change, approval, and export

  • correct

    SIEM integration via Azure Sentinel — alerts on anomalous access

  • correct

    Session recording available for enterprise tier

  • correct

    30-day log retention standard; 7-year archive for regulated entities

Infrastructure

  • correct

    Hosted on Microsoft Azure — EU West and UAE North regions

  • correct

    Multi-region failover with 99.9% uptime SLA

  • correct

    Dedicated tenant isolation — no shared database schemas

  • correct

    Penetration tested bi-annually by independent CREST-accredited firms

Data Residency

  • correct

    EU data never leaves EU-West Azure region by default

  • correct

    GCC clients served from UAE North — KSA compliance roadmap Q3 2026

  • correct

    Data residency confirmed in contractual DPA at onboarding

  • correct

    No data shared with third parties or used for model training

Business Continuity

  • correct

    RPO: 1 hour | RTO: 4 hours — tested quarterly

  • correct

    Automated daily backups with geo-redundant storage

  • correct

    Disaster recovery runbook available to enterprise clients

  • correct

    Incident response SLA: P1 acknowledged within 30 minutes

AI Proposes. Humans Confirm. System Records Both.

Every AI-generated suggestion in SustainGRC is presented as a proposal, not a decision. No AI layer can approve a risk rating, sign off a disclosure, or authorise a control. Human confirmation is required and the audit trail captures both the AI reasoning and the human decision — separately and immutably.

  • AI Governance Principle
  • AI reasoning displayed, not hidden
  • No same-user create and approve
  • Locked periods are immutable — no back-dating
  • Methodology version tracked on every calculation
  • Override requires written justification + audit entry

Ready to share this page with your InfoSec team?

All certificates and report are available