Safecall Technical & Security

Frequently Asked Questions (FAQs)

SafeCall’s technical infrastructure and security webpage addresses critical questions about our enterprise whistleblowing platform’s technical capabilities and security protocols.

The page covers comprehensive solutions including UK-based data centres, GDPR compliance, and robust security frameworks aligned with ISO 27001 standards.

Key features include enterprise-scale capacity supporting millions of users, customizable workflows, and automated routing systems.

Security measures encompass incident response procedures, data sovereignty protocols, and cross-border transfer mechanisms.

These FAQs outline SLA commitments, performance benchmarks, and security guarantees, demonstrating our commitment to maintaining the highest technical and security standards for global compliance requirements.

  • What backup and disaster recovery measures do you have?   

    We have robust availability controls to prevent data loss or destruction. These include: 

    • A comprehensive backup strategy (online/offline; on-site/off-site) 
    • Uninterruptible power supply (UPS) 
    • Virus protection and firewalls 
    • Documented reporting procedures 

    Our backup and disaster recovery plans are part of our ISO 27001 ISMS, independently verified by BSI UK. 

  • How often do you conduct security testing?   

    We carry out automated testing at least monthly, and independent physical penetration testing at least annually. These tests help validate our security controls and support continuous improvement.  

  • Do you use role-based security?   

    Yes. We use a hierarchical role-based security model based on a need-to-know approach. This ensures privacy controls are clearly defined, and access is limited appropriately to maintain confidentiality and integrity. 

  • How do you ensure data transfer security?   

    We protect data during electronic transfer using encryption, VPNs, and digital certificates and signatures, helping prevent unauthorised access, changes, or deletion. 

  • What access controls do you have in place?   

    We apply a combination of: 

    • Physical access controls (e.g. key cards, security services, CCTV) 
    • Electronic access controls (e.g. secure passwords, automatic locking) 
    • Internal access controls based on user roles and logged system access events 

    These measures help ensure only authorised individuals can access sensitive systems and data. 

  • How do you prevent DDoS attacks?   

    Our data centres use advanced security protocols to actively prevent DDoS attacks and block unauthorised traffic both to and within the centres.