Security and data handling, plainly stated

Where your data lives, how it's protected, and what we're doing about the rest. We're a young firm, and we'd rather tell you exactly what's in place today and what's still in progress than dress up either one.

Get your AI Exposure snapshot

What's in place today

Where your data lives

Client data is hosted on Supabase, in the EU region by default. Where a build needs something different — a specific region for regulatory reasons, for example — that's confirmed as part of your specification, before anything is built.

Backups

Automated daily backups, retained for at least seven days, provided by our hosting infrastructure. If your business has specific regulatory or contractual retention requirements, we'll confirm the exact figure against your plan as part of your specification, rather than assume a number applies.

Uptime and support response

We target 99.5% availability each calendar month from Go-Live, measured at our service boundary. If we fall short for reasons within our control, you're entitled to a service credit — 5% of that month's subscription fee for every full 1% below target, capped at 30%. Support response is tiered by severity: a critical fault (the Graft down, or a core function materially broken with no workaround) gets a 1-hour initial response; lower-severity issues get 4 hours to 2 business days depending on impact. The complete table, and what counts as each severity, is in Schedule 2 of our Master Terms.

Incident response

Unresolved critical incidents escalate automatically to our engineering lead if there's no substantive update within 2 support hours. At our current size that escalation path is short — often the engineering lead is the person who picked up the incident in the first place — but it is a defined, documented process, not an ad hoc one.

Data Processing Agreement

In place, and provided as part of every signed agreement as a matter of course. Read it in full at Schedule 1 of our Master Terms — Sysgraft processes personal data only on your documented instructions, under a defined set of security measures, with sub-processors disclosed per specification.

Who else touches your data

Which third parties process data on your behalf depends on your specific solution, and is confirmed as part of your specification — the same principle set out on our AI & data principles page. Supabase is the one constant across every build; anything beyond that is named explicitly before it's ever in play.

What's in progress

Naming this plainly matters more to us than it looks impressive. This is a real gap, not an oversight, and this page will be updated the moment it closes.

Certifications

We don't currently hold Cyber Essentials, Cyber Essentials Plus, or ISO 27001. Cyber Essentials is planned — not yet underway — and we won't claim it, or imply it, until it's actually certified.

Why we've written it this way

The same conviction that shapes our published exit terms shapes this page: you should know exactly what you're getting before you commit, not discover it later. A young firm claiming certifications it doesn't hold would be exactly the kind of thing this site is built to stand against.

More on what we can claim, and what we can't →

Get your AI Exposure snapshot

Ask us anything this page hasn't covered.

We'd rather answer a direct question than have you guess. The snapshot is a free, no-commitment place to start finding out where your business actually stands.

Get your AI Exposure snapshot

Or see what we can claim, and what we can't →