SECURITY & PLATFORM ASSURANCE

Trust should be specific and verifiable.

Understand what DC Core protects, where managed tenancy data resides, how the platform recovers, and which controls remain with your application team. This public summary is based on our Supplier and Platform Assurance Pack v1.2, dated .

SECURITY PRINCIPLES

Layered controls, not one sweeping promise.

The platform combines technical and operational controls across identity, connectivity, infrastructure and monitoring. The exact assurance boundary depends on which systems DC Core directly operates.

01 / ACCESS

Least privilege

Administrative and service access is limited to defined operational purposes. Role-based controls separate platform, tenant, device, support and privileged responsibilities.

02 / IDENTITY

Strong authentication

WebAuthn/passkeys support high-trust access flows. Multi-factor authentication is used where applicable to protect administrative and sensitive functions.

03 / NETWORK

Reduced exposure

Customer-side agents normally connect outwards through encrypted paths, avoiding inbound management ports and direct publication of private systems.

04 / ENCRYPTION

Protection by default

External access uses TLS, with TLS 1.3 where supported. AES-256-GCM protects applicable platform-managed data and protected services.

05 / AUDIT

Auditability

Operational and security-relevant events are logged where appropriate. Hash-chain and immutable storage controls protect audit-log integrity.

06 / DEFENCE

Defence in depth

Network restrictions, segmentation, encrypted communication, monitoring, service isolation and operational review reduce reliance on any single safeguard.

07 / PATCHING

Risk-based maintenance

Critical security updates with active known-exploited-vulnerability risk are prioritised. Routine operating-system, dependency and platform updates use planned maintenance or controlled deployment windows.

08 / PROVIDERS

Supplier governance

Infrastructure and network providers vary by deployment. Applicable locations are confirmed during onboarding, and material providers or processing changes are assessed before use and communicated where required.

DATA PROCESSING

What the platform processes—and why.

Customers determine the purpose and lawful basis for personal data in their applications. DC Core acts as a processor for agreed platform or infrastructure services, or as a sub-processor where the customer serves its own client.

ACCOUNT & IDENTITY

Access to the right tenant

Organisation details, names, email addresses, roles and permissions support customer administration, authentication and authorised platform use.

DEVICE & INFRASTRUCTURE

Operational context

Hostnames, IP addresses, operating-system information, service state and performance telemetry support monitoring and management of in-scope systems.

LOGS & SUPPORT

Security and diagnosis

Access, audit, security and operational logs—and information supplied in support requests—support troubleshooting, incident response and service assurance.

CUSTOMER WORKLOADS

Only within the agreed service

Workload data is processed where it is hosted, transmitted, backed up or otherwise managed through DC Core. Customers remain responsible for content, classification and lawful use.

PURPOSEDC Core processes these categories to deliver, secure, support and improve the agreed services. Workload scope, retention and customer responsibilities are defined by the service and contractual terms.

DATA PROTECTION & RESIDENCY

Where data lives—and where traffic may travel.

DC Core distinguishes primary tenancy storage from the global relay and edge services used to improve secure connectivity, performance and availability.

PRIMARY LOCATIONLondon,
United Kingdom
DISASTER RECOVERYFrance,
European Union
MANAGED DATA DESIGNUK/EU
unless agreed
GLOBAL RELAY ROLERouting, availability
& latency
IMPORTANTGlobal relay, DNS, edge-security and traffic-protection services can process encrypted traffic or limited metadata in other regions as part of normal delivery. They are not intended to be the primary storage location for customer tenancy data. Workloads outside DC Core-managed infrastructure follow the residency of the customer’s chosen environment.

ENCRYPTION & KEYS

Clear boundaries from transport to application.

DC Core protects platform-managed communication, infrastructure and key access. Encryption inside customer-developed applications remains a workload-level responsibility unless separately managed.

LayerDC Core controlBoundary
TransportTLS protects external access and applicable internal communication; TLS 1.3 is used where supported.Customer integrations outside DC Core control must also use appropriate secure transport.
Platform dataAES-256-GCM is used where applicable for sensitive platform-managed and protected service data.The implementation depends on the service and data layer being operated.
Owner keysA customer-owned key and virtual keychain model protects device and workload access, with WebAuthn-backed unlocking.Key-controlled operations do not rely on ordinary account passwords alone.
Customer workloadDC Core provides managed transport, infrastructure and platform protections within scope.Application databases, files, scripts and custom data handling remain with the customer or application owner unless agreed otherwise.

AVAILABILITY & RECOVERY

Designed to recover, monitored to respond.

Controls for high availability, backup and disaster recovery apply to services directly operated by DC Core. Customer-hosted and transitional environments can have different arrangements.

01 / AVAILABILITY

Multi-node services

Core application, relay and supporting services are separated to reduce single-instance dependency. Relay pools provide alternative capacity where the deployment supports it.

02 / RECOVERY

Automated restoration

Monitoring, process supervision, restart policies and traffic routing support automatic recovery where technically appropriate, with operator intervention for complex incidents.

03 / BACKUP

Daily managed backups

Platform-managed systems are backed up daily. Backups are encrypted in transit and at rest, with retention defined by service and customer agreement.

04 / TESTING

Periodic restore checks

Backup and restore processes are tested periodically, including availability verification and operational review after significant platform changes.

05 / MONITORING

Health and anomaly detection

Telemetry covers service health, relay availability, agent connectivity and infrastructure indicators. Anomaly detection compares workload behaviour with prior operational baselines.

06 / OBJECTIVES

Service-specific RPO/RTO

Recovery objectives depend on the service, incident and contracted recovery design. Specific commitments or dedicated standby arrangements must be agreed contractually.

COMPLIANCE ROADMAP

Progress stated without certification theatre.

These frameworks are a work programme, not completed certifications. Certificates, attestations and third-party reports will be shared when available, subject to confidentiality and commercial terms.

FrameworkCurrent statusProgramme focus
ISO 27001In progressInformation security governance, risk management, supplier management, incident response, access control and operational security.
SOC 2In progressReadiness activity focused on security, availability, confidentiality and operational control evidence.
Cyber EssentialsPlannedBaseline assurance around endpoint security, access control, patching, malware protection and secure configuration.

SHARED RESPONSIBILITY

Know which team owns each control.

DC Core secures the platform and managed infrastructure. Customers retain responsibility for their users, applications, business data and systems outside the agreed operational scope.

Shared responsibility summary
AreaDC CoreCustomer
InfrastructureHardening, network controls, monitoring and patching for infrastructure managed by DC Core.Servers, services and networks not hosted or managed by DC Core.
IdentityPlatform authentication, role-based access and privileged administrative controls.Customer user lifecycle, appropriate permissions, MFA adoption and removal of leavers.
ApplicationsSecure configuration of DC Core platform services and supporting components.Application code, databases, roles, business logic, integrations and workload-level encryption.
Backup & recoveryProcesses for DC Core-managed platform services and infrastructure.Requirements and recovery validation for customer-managed application data or out-of-scope workloads.
DataSecure processing of data handled to deliver the agreed managed service.Ownership, accuracy, classification, lawful basis and lifecycle of customer data.

SUPPORT & DISCLOSURE

A clear path for service and security issues.

Operational support

Standard support is Monday–Friday, 08:00–17:00 UK time, excluding UK public holidays. Critical incident handling outside these hours is available where covered by a managed support arrangement.

[email protected]

Responsible disclosure

Report suspected vulnerabilities with the affected component, a clear description, reproduction steps and relevant evidence. Reports are reviewed and prioritised by potential impact.

[email protected]
Indicative target initial response for the applicable support arrangement
SeverityExampleTarget initial response
CriticalPlatform outage or customer production unavailableImmediate emergency handling
HighMajor degradation or security concernSame business day
MediumNon-urgent fault or configuration issue1–2 business days
LowGeneral query or requestBest effort / planned queue
DOCUMENT OWNERDC Core Security & Operations · Public assurance summary v1.2 · Last reviewed .
BUYER ROUTEReviewing DC Core for procurement or customer due diligence? Follow the security and compliance route.

CUSTOMER DUE DILIGENCE

Need the detailed assurance pack?

Tell us which service or deployment you are assessing. We can provide the appropriate assurance material and clarify the controls that apply to your environment, subject to confidentiality requirements.

Request assurance material