Security and governance

Security and governance for sensitive regulatory workflows.

Cerylis may handle sensitive internal policies, controls, assessments, remediation and regulatory evidence. Controlled access and data governance are therefore fundamental to how the platform is designed and operated.

A considered security posture

Designed for controlled regulatory work.

Data handling

Purposeful data handling

Customer data should be handled only for the operation and support of the assurance process.

Encryption

Protection in transit and at rest

Security controls are designed to protect sensitive information during storage and transfer.

Access control

Controlled access

Access is structured around user responsibility and the information needed to perform it.

Environments

Environment separation

Operational environments are managed with separation in mind.

Audit logging

Traceable activity

Platform activity can support accountability and the investigation of relevant changes.

Evidence handling

Evidence stays connected

Regulatory evidence belongs to the conclusion, control and review it supports.

AI governance

AI-assisted. Expert-controlled.

AI may assist drafting and review preparation. Accountable users remain responsible for regulatory conclusions, challenge and approval.

Hosting & subprocessors

Transparency supports due diligence.

Hosting arrangements and relevant subprocessors can be discussed in the context of your firm’s requirements.

Business continuity roadmap

Resilience is an ongoing discipline.

Service resilience, continuity planning and operating controls are maintained as part of the platform’s continuing development.

Security enquiries

Discuss your firm’s security requirements.

We welcome proportionate security, privacy and operational resilience enquiries as part of your evaluation.