Safecall Technical & Security

Frequently Asked Questions (FAQs)

SafeCall’s technical infrastructure and security webpage addresses critical questions about our enterprise whistleblowing platform’s technical capabilities and security protocols.

The page covers comprehensive solutions including UK-based data centres, GDPR compliance, and robust security frameworks aligned with ISO 27001 standards.

Key features include enterprise-scale capacity supporting millions of users, customizable workflows, and automated routing systems.

Security measures encompass incident response procedures, data sovereignty protocols, and cross-border transfer mechanisms.

These FAQs outline SLA commitments, performance benchmarks, and security guarantees, demonstrating our commitment to maintaining the highest technical and security standards for global compliance requirements.

  • Can you provide detailed penetration testing reports and security audit results? 

    We carry out regular independent penetration testing and security audits to validate our systems. While detailed results are confidential, we can share them under appropriate non-disclosure agreements during the procurement process. Our security team is also available to present high-level findings, outline remediation actions, and provide attestation letters confirming compliance with standards such as ISO 27001, SOC2, and others. 

  • What are your specific database technologies and data retention policies? 

    We use enterprise-grade database technologies with built-in redundancy and encryption at rest. Our data retention policies are configurable to meet your regulatory and organisational requirements — typically ranging from 3 to 7 years, with secure deletion options. We can provide full documentation on data lifecycle management and work with your data governance team to ensure compliance. 

  • What specific hardware specifications and network architecture support your platform? 

    For security reasons, we don’t publicly share detailed infrastructure specifications. However, our UK-based data centres use enterprise-grade hardware, with redundant systems, multiple network paths, and high availability guarantees. We also implement load balancing, failover mechanisms, and capacity planning to ensure performance and resilience. If needed, our technical team can provide more detailed information during a confidential technical briefing. 

  • Can you integrate with our Active Directory for single sign-on (SSO)? 

    Yes. We support SSO integration with Active Directory and other identity management systems. Our team can configure protocols such as SAML 2.0, OAuth 2.0, or others depending on your infrastructure. This ensures seamless and secure access, while maintaining our standards for two-factor authentication and overall system security. 

  • Do you offer API access for integration with our existing HR/compliance systems? 

    Yes. While our SaaS platform is designed to minimise integration complexity, we do offer API capabilities for organisations that need deeper system integration. Our technical team can work with you to review API endpoints, authentication protocols, and data exchange formats based on your existing technology stack. We’ve successfully integrated with a range of HR systems, case management platforms, and compliance tools. A technical consultation can help determine the best approach for your organisation. 

  • How do you ensure system security monitoring? 

    We maintain continuous oversight of system performance and security, monitoring industry trends and peak demand. Regular independent penetration testing is carried out to validate our controls and ensure ongoing system integrity.