Security & data protection

Security built around your regulatory data.

REGREP handles supervisory filings, so security is not an add-on. Data residency, encryption, access control and honest assurance reporting are part of how the platform is built and run.

Independent software provider. No affiliation with any supervisor or authority.

The essentials

Serious infrastructure for serious filings

Four principles the platform is held to, and a scoped, honest account of what each one covers.

EU data residency

Your regulatory filing data on the platform is held in the EU.

GDPR by design

Data minimisation, retention limits and a documented data processing agreement.

Encryption & access

Encryption in transit and at rest, multi-factor authentication and least-privilege roles.

Independent

We are not affiliated with any supervisor or authority.

What "EU data residency" means here

Your regulatory filing data on the platform is held in the EU. Supporting services — analytics, payments, consent management, email and status monitoring — may process limited operational data elsewhere. Each is named in our privacy notice and subprocessor list, so the scope of the claim is clear rather than blanket.

Controls

How the platform is protected

The measures that stand between your data and everything else — described in plain terms, not badges.

Access & authentication

  • Multi-factor authentication is required for administrator accounts.
  • Least-privilege roles: people receive only the access their work needs.
  • Encryption in transit and at rest across the platform.

Platform hardening

  • A Cloudflare web application firewall, rate limiting and login-attempt protection sit in front of the origin.
  • File-upload restrictions and input validation on submitted data.
  • The XML-RPC interface is disabled and administrative endpoints are locked down.

Patching & monitoring

  • Critical security patches applied within 48 hours.
  • Malware and file-integrity monitoring with alerting.
  • Audit logging of administrative and configuration changes.
  • Scheduled dependency review against an allowlist.

Backups & recovery

  • Automated daily backups with an off-site copy.
  • Restores tested every quarter, not merely taken.
  • Documented incident escalation with a named decision owner.

Staging & isolation

  • The staging environment carries no production personal data.
  • Separate cookie and content-security scope from production.
  • Secrets handled through a documented procedure, never placed in code.

Network & transport

  • Transport Layer Security 1.2 or higher, with Cloudflare Full (Strict) to the origin.
  • HTTP Strict Transport Security enabled.
  • DNSSEC and CAA records set at the DNS layer.
Assurance & compliance

Where we stand, stated plainly

We show our status honestly, including what is still in progress. We do not display certifications we do not yet hold.

Current status

GDPR programme — Operational ISO 27001 — In progress SOC 2 — In progress
GDPR programme Operational. Privacy programme, data processing agreement and a working data-subject request process are in place.
ISO 27001 In progress. The information security management system is being scoped; certification is targeted and not yet held.
SOC 2 In progress. Control design is under way; a report is not yet available.

Status wording is maintained in our claims register with a review date, so it stays current.

REGREP is an independent software provider and is not affiliated with, endorsed by, or acting on behalf of the EBA, ESMA, EIOPA, ECB, OECD, IRS, FCA, PRA, Bank of England or any national competent authority.

See how your filings are handled.

Walk through the security model with us, or create a free account and test on your own data.