Skip to main content
    Security & data protection

    Your records are evidence. We treat them that way.

    Temperature logs, training records, incident reports — one day they may sit in front of an inspector. So Recordme is built evidence-first: encrypted in transit, hosted in the EU, isolated to your organisation and sealed into a tamper-evident trail. No badge wall, no borrowed logos — just what we actually do.

    Encrypted in transit
    Hosted in the EU
    Tamper-evident audit trail

    Launching 2026 · No badges we haven't earned · No claims we can't evidence

    The posture

    Six things that are true about your data.

    No vague promises, no borrowed badges. Here is what Recordme actually does with your venue's records — designed in from day one, on every plan, not bolted on or sold back to you as an add-on.

    01

    Encrypted in transit

    Every connection to Recordme is encrypted in transit — between your devices and our servers, on every plan. The same posture everywhere — security is never an upsell.

    02

    Hosted in the EU

    Recordme runs on EU infrastructure — your venue's data is stored in the EU. Our sub-processors are published openly on the legal page, not buried.

    03

    Tenant isolation

    Your organisation's records are yours alone. Isolation is enforced at the database layer — every query is scoped to your organisation — and automated cross-tenant tests guard that boundary on every change we ship.

    04

    Role-based access

    Everyone sees exactly what their role needs — no more. Managers see their site, head office sees the estate, and permissions follow the role, not the person. Multi-factor authentication is available on every account.

    05

    Tamper-evident audit trail

    Records are attributed — name, role, site, timestamp — and sealed into an append-only trail. Corrections are appended, never overwritten; the original always survives, and the history exports on demand.

    06

    GDPR-aligned by design

    Built to support your UK GDPR obligations: subject-access workflows with the statutory clock on screen, scheduled retention sweeps with a logged outcome, and a breach log that's a record — not a scramble.

    Our security practices

    Security is habits, not headlines.

    How we work on the system that keeps your records — the everyday engineering discipline behind the promises above. We'd rather show you the habits than hide behind a badge.

    Reviewed, tested, gated

    Every change is peer-reviewed and must pass an automated gate — type checks, linting, tests and builds — before it can merge. No green, no ship.

    Isolation proven on every change

    Cross-tenant tests run in that same gate: they assert that one organisation can never read another's records — on every single change, not once a year.

    Least privilege, everywhere

    Scoped credentials over master keys, role-scoped access over blanket admin — for our own systems and our own team, not just for yours.

    Fail safe, not fail open

    Misconfiguration should fail loudly at deploy time, not quietly in your kitchen. Defaults err to the locked state, and incomplete set-ups route to safe paths.

    Backups before schema changes

    Every database migration is preceded by a backup, as policy — and changes to your data's shape are made expand-first, so they stay reversible.

    Monitoring that minimises your data

    We monitor errors and performance with personal data scrubbed before it leaves the system. Debugging shouldn't mean hoovering up your team's details.

    What we don't claim (yet)HONESTY POLICY

    Recordme is a young company, and we'd rather under-claim than over-promise. We do not yet hold third-party security certifications or independent audit reports, and you won't find their logos here until we genuinely do. Our security testing today is internal and continuous. As we grow, independent verification is firmly on the roadmap — and when it lands, this page will say so plainly, with the paperwork to back it.

    Built to help you meet — and evidence
    • FSA Safer Food, Better Business
    • HACCP
    • Natasha's Law · PPDS
    • Working Time Regulations
    • RIDDOR
    • UK GDPR

    Recordme is the tool you run these frameworks with — and the evidence you produce when asked. Ratings and certification always remain with your business and your local authority.

    UK GDPR, in practice

    Data protection as a workflow, not a ring-binder.

    You remain the controller of your team's and your customers' data — Recordme processes it on your instructions. These workflows are built to help you meet, and evidence, your obligations; they don't replace your own policies or legal advice.

    Our data processing agreement and sub-processor list are published openly — see the legal page. Questions about how we'd handle your data? Ask us directly.

    Responsible disclosure

    Found something? Tell us — directly.

    If you believe you've found a vulnerability in Recordme, we want to hear from you before anyone else does. Reports go straight to the people who can act on them.

    • Act in good faith. Don't access data that isn't yours, don't degrade the service for others, and give us reasonable time to fix an issue before disclosing it publicly.
    • We'll take it seriously. We'll acknowledge your report, keep you informed while we investigate, and tell you when it's resolved.
    • Credit, gladly. We don't run a paid bounty programme today — we're honest about that — but with your permission we'll credit you once a fix has shipped.
    Security contactVULNERABILITY REPORTS
    [email protected]

    Please include

    • What you found, and where — the affected page, endpoint or flow
    • Steps to reproduce it, as specifically as you can
    • What you think the impact could be
    • How we can reach you with questions and updates

    This inbox is for vulnerability reports. For privacy matters and data requests, see the privacy policy; for everything else, use the contact page.

    Ask us the hard questions.

    Security pages are easy to write and harder to live by. If you're evaluating Recordme for your venues, bring your toughest questions — we'd rather be grilled now than trusted blindly.

    [email protected] · LAUNCHING 2026 · NO CLAIMS WE CAN'T EVIDENCE