PowerView UK

Security & sub-processors

This page describes the controls we operate today. It is a statement by PowerView UK (Annalu Pomarico, sole trader) and is not an independent certification or audit opinion.

Tenant isolation

Every table carries an org_id and row level security is enforced in the database. A query can only return rows belonging to the signed-in user's organisation, regardless of application code.

Immutable audit trail

Audit records are append-only. Database triggers reject UPDATE and DELETE, each record is SHA-256 hash-chained to the previous one, and a daily anchor seals the chain head so tampering is detectable.

Role-based access

Roles (Supplier Admin, Manager, Compliance, Viewer) are stored in a dedicated table and evaluated server-side. Privileged actions are re-checked on the server, not only in the interface.

Encryption in transit and at rest

All traffic is served over TLS. Database storage and uploaded files are encrypted at rest by our infrastructure providers listed below.

Sub-processors

Complete register, last reviewed 17 August 2026. Controllers are notified of any intended change with a reasonable opportunity to object.

ProviderPurposeRegionTransfer safeguard
Supabase Inc. (managed Postgres, authentication, file storage)Stores compliance data, user accounts, uploaded CSV files and the audit trail.United Kingdom (London, eu-west-2)UK hosting — no international transfer for stored data.
Resend (Plus Five Five, Inc.) — transactional email deliveryDelivers report notifications, deadline alerts and account emails from @powerviewuk.co.uk.European Union (Ireland, eu-west-1)UK GDPR adequacy decision for the EEA; DPA in place.
Stripe Payments Europe, Ltd. / Stripe, Inc.Subscription checkout, invoicing and payment records. Card data never reaches our systems.European Union / United StatesStripe DPA with UK IDTA and Standard Contractual Clauses.
Cloudflare, Inc. (application hosting and edge delivery)Serves the application and API endpoints; provides the caller IP used for rate limiting.Global edge network, UK/EU points of presenceCloudflare DPA with UK IDTA and Standard Contractual Clauses.

Certifications

Cyber EssentialsIn progress — not yet certified
ISO/IEC 27001Not certified

PowerView UK is operated by Annalu Pomarico (sole trader). The controls described are self-assessed and are not an independent audit opinion.

Retention schedule

Free Risk Check CSVs and generated reports12 months, then deleted and the request anonymised
Leads and demo requests24 months of inactivity
Payment delivery and idempotency logs24 months
Audit trail and compliance evidence6 years (regulatory obligation), purged after 7 years

Retention is enforced by an automated daily purge job, not by manual housekeeping.

Service availability

A public health endpoint is available at /api/public/health for monitoring tools. It reports application and database availability only and exposes no customer data.

Reporting a vulnerability

Email annalupomarico@powerviewuk.co.uk with details. We acknowledge reports within 5 working days and ask that you do not access or modify data belonging to other organisations while testing.

Data protection details, lawful bases and data subject rights are set out in our Privacy Policy and Data Processing Agreement.