← Back to estaraai.com
Security & Data
Last updated: 21 July 2026
Clients trust us with access to their systems and data. This page describes the controls we actually use — no vague claims. If you need specifics for a vendor assessment, email hello@estaraai.com.
Access management
- Unique, named accounts — no shared logins — with access limited to what each engagement requires.
- Multi-factor authentication enabled wherever the service supports it.
- Client-granted access is removed at the end of an engagement, or immediately on request.
Credential handling
- Credentials and API keys are stored in encrypted password/secret managers — never in plain text, shared documents or source code repositories.
- Where possible we ask clients to grant scoped access rather than share passwords.
Encryption and infrastructure
- Services we build and use encrypt data in transit (TLS); data at rest is encrypted by the managed cloud providers we build on.
- We build on reputable managed cloud platforms (for example Render and Supabase); hosting regions are confirmed per project based on client requirements.
- Backups for systems we operate are handled through the managed providers' backup facilities, with restoration options confirmed per project.
Development practices
- Secure development practices: changes are tested before deployment, secrets are kept out of code, and production access is restricted.
- Systems are documented and handed over so clients aren't dependent on any single person's memory.
Data protection
- GDPR-aware data handling: minimum necessary access, defined retention, and deletion or return of client data at the end of an engagement unless agreed otherwise.
- Where we process personal data on a client's behalf, we do so under the client's instructions; a list of relevant subprocessors is available on request.
Incident response
If we become aware of a security incident affecting client data or a client system we operate, we notify the affected client without undue delay, contain the issue, and support any notification obligations that apply under UK GDPR.
Insurance
Estara AI Ltd holds Professional Indemnity, Public & Product Liability and Cyber Liability insurance. Documentation is available on request.
Estara