Trust & Security

How we protect your data

Cyber:GRC is operated by Erith to manage supplier information security risk assessments aligned to ISO/IEC 27001:2022. This page summarises the controls we apply to protect supplier and assessment data. It is maintained by us and is not an independent certification.

Encryption

All traffic to the platform is served over HTTPS/TLS. Data is encrypted at rest in the managed Postgres database and in object storage used for evidence and signed documents.

Access control

Reviewer accounts are gated behind authenticated sign-in. Application data is protected with row-level security policies so each request only returns data the caller is entitled to read. Supplier portals are accessed via single-use magic-link tokens that expire.

Data handling

We store the supplier information you provide, the responses captured during assessments, uploaded evidence, and the formal documents generated from them. Data is retained for as long as the assessment record is active and is deleted on request, subject to legal or contractual retention obligations.

Assurance practices

Our assessment methodology maps to Annex A of ISO/IEC 27001:2022. Templates, scoring, and approval steps are designed to produce auditable records. Changes to issued documents are versioned and locked once executed.

Vulnerability management

Dependencies and infrastructure are monitored continuously. Security findings raised by automated scanners are triaged and remediated through normal change control.

Contact

To report a security concern or request a data export or deletion, email cyberassurance@erith.com.

This page is editable project content and does not represent independent verification or certification by Lovable or any other third party.