Search

Security

We take cyber security seriously. Learn how we keep your data safe, including identity management, service hosting and data encryption.

Our Approach to Security

Prescience considers cyber security to be one of the most important responsibilities we have to our customers. We take a proactive approach — continuously reviewing and improving how we address security across our platform, our internal operations, and our supply chain. This page gives an overview of the key measures we have in place. If you have a specific security question that is not answered here, please contact us at info@prescience.io.

Policies and Internal Standards

Security Policy Framework

Prescience maintains a comprehensive set of internal security policies that all employees and contractors are required to read, accept, and follow as a condition of their engagement. Our policy framework covers:
  • Cyber Security Policy — requirements for the protection of company systems, data, devices, and credentials
  • Information Security Policy — classification and handling of information throughout its lifecycle
  • Acceptable Use Policy — permitted and prohibited use of company IT systems and resources
  • Cyber Incident Response Policy — detection, escalation, containment, and resolution of security incidents
  • AI Usage Policy — approved AI tools and controls to prevent unauthorised use of customer or confidential data with AI services
  • Employee Offboarding Policy — immediate revocation of all system access upon departure

Security Awareness

All Prescience employees complete annual cyber security awareness training. We regularly test awareness through simulated phishing exercises and use the results to continuously improve our training programme.

Incident Response

Prescience has a documented incident response plan with defined roles, severity levels, and escalation procedures. In the event of a confirmed incident, a dedicated response team is activated immediately. We aim to contain, investigate, and remediate incidents as quickly as possible, and communicate transparently with affected customers throughout the process.

Identity and Access Management

Authentication

All access to Prescience — via the API, web application, or Progressive Web App (PWA) — requires authentication. Prescience supports Single Sign-On (SSO) via industry-standard identity protocols, allowing enterprise customers to integrate with their own identity provider. Multi-factor authentication (MFA) is enforced for all Prescience staff and is available to customers.

Password Requirements

Where password-based authentication is used, Prescience enforces strong password requirements including a minimum length, and a combination of uppercase and lowercase letters, numbers, and special characters. Passwords are stored in a securely hashed format and are never transmitted or stored in plain text.

User Access Management

Account owners and administrators can manage users and roles within the platform. Access controls enforce least-privilege principles — users can only access the data and functionality appropriate to their role. All access to account data passes through our API, which enforces authentication and authorisation on every request.

Internal Access Controls

Prescience staff access to production systems is strictly controlled on a need-to-know basis. Access rights are reviewed regularly and revoked immediately when no longer required. All staff activity on production systems is logged and monitored.

Third-Party Access

Where Prescience shares information with third-party service providers acting on our behalf, we share only the minimum information necessary to deliver the service, subject to appropriate data protection agreements.

Data Storage and Infrastructure

Cloud Infrastructure

Prescience is hosted entirely on Microsoft Azure, one of the world’s leading enterprise cloud platforms. We do not operate our own physical data centres. By building on Azure, we inherit a platform that is independently certified to ISO 27001, SOC 2, and a wide range of other international security standards. For more information about Microsoft Azure’s security and compliance certifications, please visit the Microsoft Service Trust Portal.

Where Is Data Stored

All customer data is stored within the European Economic Area (EEA). Our primary data centre is in Western Europe, with geographic redundancy provided by a secondary data centre in Northern Europe. This means your data benefits from high availability and resilience without leaving the EEA. Certain specialist services may be hosted in other Azure regions where the relevant capability is not available in our primary regions. All such regions are located within the European Union and are subject to the same GDPR protections and security standards as our primary infrastructure. Prescience does not offer on-premise or private server hosting.

Data Deletion

Customer data is never copied outside the production environment except as part of our governed backup processes. Upon account termination or upon customer request, Prescience removes all customer data and content from the production environment. Encrypted backup copies are retained for a defined period in accordance with our data retention policy, after which they are permanently purged.

Data Encryption

Encryption in Transit

All data transmitted between Prescience servers and our web application and PWA clients is encrypted using industry-standard Transport Layer Security (TLS). We enforce encryption on all connections — there is no unencrypted way to exchange data with Prescience.

Encryption at Rest

All customer data stored within Prescience is encrypted at rest using strong, industry-standard encryption. This applies to all storage types used by the platform — structured databases, document databases, and file storage. Encryption is applied and managed at the platform level, ensuring consistent protection across all data.

Key Management

Encryption keys and application secrets are managed using a dedicated secrets management service, with access restricted to authorised processes only. No credentials or secrets are stored in source code.

Monitoring and Vulnerability Management

Continuous Monitoring

Prescience uses Microsoft Defender for Cloud to continuously assess our security posture, monitor for threats, and maintain compliance with security benchmarks. Infrastructure and application events are logged and monitored, with alerting in place for anomalous activity.

Vulnerability Management

We monitor security advisories for all components and dependencies used in the platform and apply patches within defined timescales. Azure-managed platform services are kept up to date by Microsoft as part of the managed service.

Event Logging

Actions that create, modify, or delete data within Prescience are logged with reference to the account, user, and timestamp. API calls and outbound webhooks are logged and retained for a minimum of 30 days. Logs are accessible to authorised members of the Prescience technical team for troubleshooting, monitoring, and security investigations.

GDPR and Data Protection

Prescience is committed to compliance with the General Data Protection Regulation (GDPR) and applicable Danish data protection law. Key commitments include:
  • Customer data is stored within the EEA and does not leave the EEA under normal operating conditions
  • Prescience acts as a data processor with respect to customer data submitted to the platform, processing data only on the instructions of the customer as data controller
  • In the event of a personal data breach, Prescience will notify affected customers and, where required, the relevant supervisory authority within the timeframes specified by GDPR
  • Data Processing Agreements (DPAs) are available upon request for customers who require them
For full details, please refer to our Privacy Policy.

Change Log

3 January 2018 — Rev1 (v1.0): Document created.
25 June 2026 — Rev2 (v2.0): Comprehensive update. Key changes: SSO and MFA added; password requirements updated to reflect current policy; SSL updated to TLS; data centre information updated to include Ireland geo-replication; Google Analytics reference removed; full policy suite updated; continuous security monitoring via Defender for Cloud added; GDPR section added; general language refreshed throughout.

Book a Free Demo