Trust Centre
Trust is built with precision, not badges.
How Hamiltonn Cloud approaches security, isolation and operations — stated plainly. We publish what we do, and we do not claim certifications we do not hold.
Controls
How the platform is protected.
Tenant isolation
Customer environments are strictly separated; dedicated deployments add physical-level isolation of application, database and storage.
Access controls
Role-based permissions, least privilege by default, and maker-checker approval on sensitive operations.
Encryption in transit
TLS on every connection — customer traffic, API calls and internal service links.
Monitoring
Platform-level observability with alerting on anomalies and operational thresholds.
Backups
Routine automated backups with restoration testing.
Auditability
Staff, customer and API actions are logged and exportable for your compliance operations.
Certifications
What we claim — and what we don’t.
You will not find SOC 2, ISO 27001 or PCI badges on this site today, because we do not currently hold those certifications — and we think putting unearned badges on a website is exactly the kind of behaviour an infrastructure company should be judged for. As formal certifications are achieved they will be published here, with documentation.
Enterprise customers can request our current security documentation as part of a dedicated deployment conversation.
- Responsible disclosure — security researchers can report vulnerabilities via the contact page; we respond, fix and credit.
- Financial services boundary — Hamiltonn provides technology, not regulated financial services; customers hold their own authorisations.
- Data protection — personal data is processed per our Privacy Policy and applicable UK data protection law.
- Status page — status.cloud.hamiltonn.net will publish platform availability at general availability.
Ask us the hard questions.
Security reviews and procurement questionnaires welcome — bring them to a dedicated deployment conversation.