Ahmad & Partners← Back home
Trust & security

Built to keep your data safe.

Last updated: June 14, 2026

You trust us with sensitive things: org charts, comp data, succession plans, board materials, the conversations that decide who runs what. We treat that responsibility seriously. Here is exactly how.

Built on certified infrastructure

  • Stripe (PCI-DSS Level 1): all card payments are processed by Stripe; we never see or store card numbers.
  • Cloud database & storage (SOC 2 Type 2 · ISO 27001): managed by our backend infrastructure provider in EU regions.
  • Edge & DDoS protection (SOC 2 Type 2 · ISO 27001): web application firewall, rate limiting, and DDoS mitigation at the edge.
  • UK & EU GDPR aligned: lawful basis, access, and deletion rights honoured.

Ahmad & Partners inherits these certifications from our payment, cloud, and edge providers. We are not independently SOC 2 or ISO 27001 certified, and we will say so plainly rather than display badges we have not earned.

How we protect you

Security is a default, not a feature. These controls are always on, for every client, on every engagement.

Encrypted by default

All traffic is served over HTTPS with modern TLS. Data is encrypted at rest in our managed cloud database and storage layers. Secrets and API credentials are stored in an encrypted vault, scoped per environment, and never exposed in client code or logs.

Row-level access control

Every table that stores client data is protected by row-level security policies enforced server-side. Users can only read and write their own records. Admin-only data is gated behind a separate roles table and verified through security-definer functions, so privileges cannot be escalated from the client.

Authentication you control

Sign-in is handled by a battle-tested auth provider with hashed credentials, secure session tokens, optional Google sign-in, and password reset via verified email links. We never see or store your password in plaintext.

Your data stays yours

We do not sell your data and we do not use your private content, uploads, or conversations to train third-party AI models. Where AI providers are involved, contractual terms restrict retention and training on customer data.

Private files stay private

Client documents, recordings and uploads live in private storage buckets. Access is granted only through short-lived signed URLs tied to your authenticated session, not public links.

Hardened infrastructure

Our platform runs behind a web application firewall with DDoS protection, adaptive rate limiting, and network isolation between services. Background jobs and webhooks run inside isolated serverless functions with least-privilege credentials.

Continuous security scanning

Automated scans run against our database policies, storage buckets, and dependencies on every deploy. Critical findings block release. We patch high-severity dependency vulnerabilities on a rolling basis.

Payments handled by Stripe

We never touch your card details. All payments are processed by Stripe (PCI-DSS Level 1), and webhooks are signature-verified and idempotent so a single charge can never be applied twice.

Our principles

Least privilege, everywhere

Every service, function, and team member gets the minimum access they need to do their job, and nothing more. That includes our own admin tools.

Server-side trust, never client-side

Access decisions are made on our servers, not in your browser. Roles, permissions, and entitlements cannot be flipped by inspecting the page or tampering with local storage.

Defaults that fail closed

When a policy is missing, we lock the door rather than leave it open. New features ship with access rules first, UI second.

Privacy is the product

Your private notes, working documents, and engagement materials are yours. We will never sell them, share them, or feed them into someone else's training set.

Frequently asked questions

Where is my data stored?

Client data is stored in our managed cloud database in the EU region by default. Backups are encrypted and retained on a rolling schedule. Data does not move across regions without an explicit reason.

Do you use my private content to train AI?

No. Your engagement notes, documents, and conversations are not used to train any AI model. When we call third-party AI providers to power features for you, we use contracts that prohibit training on your inputs.

Who on your team can see my information?

Access to production data is restricted to a small number of authorised staff and only used to support you, fix bugs, or investigate abuse. Admin actions are logged and reviewable.

How do you handle passwords and sessions?

Passwords are hashed using industry-standard algorithms and never stored in plaintext. Sessions use secure tokens with expiry and rotation, and you can sign out of all sessions at any time by resetting your password.

What happens if you detect a breach?

We monitor for suspicious activity continuously. In the unlikely event of a confirmed incident affecting your data, we will notify affected clients without undue delay, in line with UK GDPR and applicable laws.

Can I delete my account and data?

Yes. You can request deletion of your account and personal data at any time by emailing the address below. We will remove or anonymise your records, subject to legal retention requirements (for example, tax records for completed payments).

Found something? Tell us.

If you believe you have found a security vulnerability, please report it responsibly to security@ahmad.partners. We investigate every report and will work with you in good faith to resolve any genuine issue quickly. See also our Privacy Policy.

© 2026 Ahmad & Partners Ltd.
PrivacyCookiesSecurityTerms