Legal
Security
Version 1 · Last updated: 18 September 2026
This page is information, not a contract. What we undertake is in Security, of the Data Processing Terms; a measure named here may be replaced by a stronger one without that undertaking changing.
Encryption. Data is encrypted in transit and at rest. Credentials and provider keys are held in a managed secrets store, not in configuration files.
Hosting. The Service runs on managed cloud infrastructure in the United Kingdom that its provider patches and certifies. Our own software is rebuilt and redeployed to take security fixes.
Separation. Every record belongs to one customer organisation, and a signed-in person reaches only their own organisation’s records.
Access. Hosts sign in through our own authentication service, and what a host may do is decided by the role they hold in their organisation. Guests do not have accounts: a guest reaches a session with the code issued for it, so who holds the code decides who can read it.
Monitoring, backup and restore. Operational logs and alerts tell us when the Service fails or behaves unusually; how long they are kept is in Retention, of the Privacy Policy. Account and configuration data is backed up to storage separate from the Service, and copies age out on the rotation stated on How Parlabase handles data.
A fuller description of our measures is available to customers on request. Report a vulnerability to hello@parlabase.com.
Version 1 · Last updated 18 September 2026
- 18 September 2026 — First published.