Security statement.
A short, honest summary. We hold ICO registration. Other accreditations are in progress and stated honestly elsewhere. Procurement-grade detail is available under NDA via the contact form.
Last updated: 21 May 2026
1. UK data residency
Operator data, smart device data and evidence chains are hosted in UK regions. Where any sub-processor sits outside the UK, the transfer is governed by an appropriate Article 46 mechanism (UK Standard Contractual Clauses, UK IDTA, or an adequacy decision).
2. Encryption
TLS in transit; encryption at rest at the storage layer. Evidence-chain records are additionally hash-chained for tamper-evidence — see the data integrity page.
3. Access control
Multi-factor authentication is enforced on every human BlueMetric OS account by default. Inspector and insurer tokens are scoped, read-only and time-bounded, with every access logged.
4. Vulnerability disclosure
Report a suspected vulnerability via the contact form with "Security disclosure" in the message. We acknowledge within one working day, update within five, and will not pursue good-faith researchers.
5. Sub-processors and procurement detail
Available under NDA via the contact form: full sub-processor list with locations and transfer mechanisms, Data Processing Agreement, DPIA, insurance schedules, and security questionnaire pre-fills.
6. Accreditation status
Held: ICO registration. In progress: LCA accreditation, SafeContractor application, NHS framework alignment and healthcare-specific accreditations. Via partners: ISO 11731 laboratory sampling via accredited partner laboratories. We do not currently claim any UK government cyber-security scheme certification; when we are awarded one, we will publish it the day it lands.
© 2026 BlueMetric OpCo Limited · Co. No. 17165530 · A Montclair Capital company.
