Trust & security

How Poyntr earns the trust to be inside your organisation

One page that gives your security, legal, and procurement teams everything they need: regulatory mapping, data-processing terms, sub-processor register, encryption architecture, SSO setup, and our responsible-disclosure policy. Every claim links to the underlying evidence.

Last reviewed: 2026-05-13 · Owner: Engineering Lead · Questions: [email protected]

Data residency
United Kingdom (europe-west2 London)
Encryption at rest
AES-256-GCM, three-layer envelope, HSM root
Encryption in transit
TLS 1.2+ enforced, HSTS preload
Session security
argon2id, HIBP, 8h idle, MFA-enforced privileged roles
Audit log
HMAC-chained, 7-year retention, immutable
AI training on customer data
Contractually prohibited; zero-retention agreements with every AI provider

App update-signing certificates

The Android apps are not distributed through the Play Store. Each one accepts code updates only from a single certificate compiled into the binary itself. These are the SHA-256 fingerprints of those certificates, published here so the value can be checked somewhere other than the machine that serves the updates. Two certificates, never one: no single key signs code for both an adult and a student audience. Download and verification instructions are on the install page.

Poyntr (adult app)
b29da549 b0c07c07 a27a33ad 1567e375 2cd2abb4 f1388641 666fa90b fff005fc
Poyntr Student Den
3f833a2e 4052c4cc 669085a5 c9e1ec96 f9bb9a96 e6f3fd57 30ae7b19 3837ae32

Regulatory compliance

UK GDPR, DPA 2018, Children's Code, KCSIE 2025, and the DfE Generative AI Product Safety Standards, mapped to specific platform controls with code-path evidence.

Data processing

Where your data lives, who processes it on our behalf, and the legal mechanisms protecting every transfer. Sub-processor changes are notified at least 30 days in advance.

Security architecture

AES-256-GCM at rest with HSM root key, per-tenant and per-user envelope encryption, crypto-shredding for right-to-erasure, two-tier authorisation enforced by CI. Every decryption is recorded in a tamper-evident transparency log anchored externally to Sigstore Rekor, verifiable without trusting us.

Identity & access

Production SAML 2.0 and OIDC for enterprise SSO; SCIM 2.0 for directory sync; argon2id + HIBP for passwords; TOTP and WebAuthn passkeys for MFA; HMAC-chained immutable audit log for every privileged action. Microsoft Entra is supported via the standard SAML/SCIM integration; Okta is supported via SCIM with SAML or OIDC; Microsoft Graph platform integration ships as a multi-tenant app for one-click admin consent.

Responsible disclosure

Found a security issue? We respond to good-faith reports within 2 working days and commit not to pursue legal action against research consistent with our policy.

Subject rights

Individuals can export their data, request erasure, and object to processing. Institutional admins can do the same on behalf of users they control. We respond within 30 days; most exports complete within 72 hours.

Need a full security questionnaire response?

Email [email protected] with your standard form (CAIQ, SIG, vendor-specific) and we will return it within 5 working days. We do not insist on our own form; we complete yours.

For pre-procurement conversations, ask for our compliance pack, it bundles the DPA, sub-processor register, cryptography policy, security model, DPIAs, incident response runbook, and the enterprise compliance roadmap so your team can read everything in one sitting.