security

Build on a Secure Foundation

Enterprise-grade security from your first environment to production, whether you’re launching your first platform or running one across a regulated industry. Dedicated infrastructure, role-based access, and compliance built in from the start.

verification

Compliant and Certified

Full reports are available under a signed NDA. Get in touch and we’ll organise it.

Architecture

The Infrastructure Behind Every Platform Built With GraniteStack

Five things that hold as you grow, not just on day one.

01

Dedicated, Not Shared

Run your platform on private cloud infrastructure dedicated to your business. It auto-scales as you grow, hosted in the region you choose, with 99.9% uptime.

02

Access Control From Day One

Multi-tenancy is standard from day one: tenant portals, data segregation, and role-based access apply across every platform, whether you're running one user type or several.

03

Tested Before It's Real

Development, staging, and production stay separate as standard, so changes get validated before real users see them. Release management keeps every launch controlled.

04

Compliance by Architecture

Audit trails and role-based access are built into every platform's architecture from the start. The infrastructure underneath is PEN-tested.

05

Data Engineered to Scale, Not Just Configure

Defining your data structures is easy on purpose. What's harder, and less visible, is keeping that data fast, accessible, and reliable as it grows: indexing, query performance, storage architecture. GraniteStack manages all of that as standard, so what works on day one still performs when it's carrying years of operational history.

Compliance

Beyond the Badge

The badges are shorthand. Here’s what each one actually means.

AWS Partner & Qualified Software

GraniteStack is an AWS Partner and an AWS Qualified Software provider, supporting evidence for the quality of the infrastructure everything else on this page is built on.

ISO 27001

GraniteStack is ISO 27001 certified for our information security management system. Not self-declared. Not "working towards it." A milestone on a road we intend to keep walking.

SOC 2

GraniteStack has completed System and Organization Controls (SOC) 2® Type I and Type II examinations, covering the security of our platform and infrastructure. Full reports are shared under a signed NDA on request.

Direct Answers

Frequently Asked Questions

Answers to the questions a security review typically asks.

Can we see the ISO 27001 or SOC 2 reports directly?

Yes. Full reports are shared under a signed NDA. Get in touch and we'll organise it directly.

Dedicated. Every platform runs on its own private cloud infrastructure, hosted in the region you choose.

Yes, as standard on every platform. Changes are built in development, validated in staging, and only promoted to production once they've passed review.

Yes. Every action, across every user, workflow, and AI-driven process, is logged with a timestamp and always available, not something you need to request or reconstruct after the fact. Whether an action is taken by a person or by agentic AI, it runs through the same role-based access controls and lands in the same audit trail.

The platform is built with compliance-sensitive industries in mind: audit trails, role-based access, and data segregation are standard, and the infrastructure is PEN-tested. Specific regulatory requirements vary by industry, so we work through those in detail during discovery.

Ongoing, not one-and-done. Both certifications are maintained and reviewed on a continuing basis, not earned once and left on a slide.

Have a Compliance Question Specific to Your Business?

Talk it through directly with the team, and we’ll share whatever documentation your review needs.