SECURITY
Operational discipline.
Full review packs are shared under engagement — this page is the short form. Company details.
Production workloads run on major cloud providers in UK/EU regions where agreed. TLS for transport; encryption at rest for persisted data. API access is keyed and scoped. Blackglass collection is agentless SSH metadata — no customer secrets stored in our console copy. Charon Gate verifies inbound signatures (HMAC / Stripe / GitHub) with constant-time comparisons, encrypts destination auth at rest, and isolates every tenant.
UK GDPR / DPA 2018 — see Privacy. Product-specific security pages: blackglasssec.com/security.