Skip to content
Menu

Security

What is published on security, and what is not yet.

This website processes no personal data. Where odel-labs holds client data is not published yet, and this page says what that needs. Certifications first, then residency.

Last reviewed

Certifications

Held, or not held

Item Status Detail
Cyber Essentials Not published Needs held or not held, and the expiry date if held
ISO 27001 Not held
ICO registration Not published Needs the registration number and its renewal date

Where a certification is not held, that is stated plainly rather than implied, and no path to one is promised here.

2 of these 3 are not published yet. Rather than a figure nobody has checked, this page says so. Ask security@hellofixi.com and it is answered within 2 working days.

Data residency

Not published yet

The answer a questionnaire wants

Where client data is held is not published on this page yet, and that is deliberate rather than an oversight. It is the statement a reviewer is most likely to rely on, so it goes up when it has been checked against the running platform and not before.

What Fixi commits to is a process. Where client data will be held is stated in writing, per engagement, before work begins. Any transfer of personal data outside the United Kingdom uses a lawful transfer mechanism under UK GDPR: adequacy regulations where they apply, otherwise the IDTA or the UK Addendum to the EU SCCs.

What can be said today: this website itself processes no personal data, sets no cookies, runs no analytics and makes no third-party request, so nothing a visitor does here reaches a third party. The one exception is the host's own request log, which /data-protection covers and which is listed there as unconfirmed. The network panel in any browser shows the rest in about 10 seconds. The one thing kept locally is the colour scheme, if you set one, and local storage is never attached to a request, so no server sees it.

For the platform above it, ask security@hellofixi.com and it is answered within 2 working days, in writing, with the region named.

Sub-processors

The list is published and versioned at /legal/sub-processors. A customer may object in writing to a new sub-processor during the notice period.

Item Status Detail
Notice before a new sub-processor is added Not published Needs the notice period in days, which the customer terms must match

The one item above is not published yet. Rather than a figure nobody has checked, this page says so. Ask security@hellofixi.com and it is answered within 2 working days.

Access and authentication

Item Status Detail
Encryption in transit Published TLS 1.2 or above This site is served over TLS 1.3 with HSTS. The figure for the platform above it is the contractual floor rather than a measurement.
Encryption at rest Stated intent Stated intent, not yet independently verified: client data encrypted at rest using the cloud provider's managed encryption, with the keys held by the provider rather than in the application.
Administrative access Stated intent Stated intent, not yet independently verified: named accounts only, multi-factor authentication on every administrative account, and access limited to what the role needs.
Production access Not published Needs who, how, logged how, reviewed how often
Key management Stated intent Stated intent, not yet independently verified: keys live in the cloud provider's managed key store, never in the codebase or its configuration.

1 of these 5 is not published yet. Rather than a figure nobody has checked, this page says so. Ask security@hellofixi.com and it is answered within 2 working days.

Backup and restore

Including the restore test

Item Status Detail
Backup frequency Stated intent Stated intent, not yet independently verified: backups are automated and run at least daily.
Retention Not published Needs the period
Last restore test Stated intent Stated intent, not yet independently verified: a restore is tested before the platform holds its first client data, and the date of that test is published here.
Recovery objectives Not published Needs RPO and RTO

The restore test date is on this table rather than left off it, because a backup nobody has restored is a hope rather than a control.

2 of these 4 are not published yet. Rather than a figure nobody has checked, this page says so. Ask security@hellofixi.com and it is answered within 2 working days.

Incidents

Article 33

A personal data breach is reported to the ICO within 72 hours of Fixi becoming aware of it, where the threshold in UK GDPR Article 33 is met. That is the statutory period rather than a target.

The window for telling an affected customer is a commitment rather than a statutory figure, and it is not published until it matches what the customer terms say. Asking for it in writing is the reliable route.

Response times

Item Status Detail
Security questionnaire Published Acknowledged in 2 working days. The acknowledgement gives the date the completed questionnaire comes back by.
Vulnerability report Published Acknowledged in 2 working days
Critical incident update Not published Needs the interval while an incident is open

1 of these 3 is not published yet. Rather than a figure nobody has checked, this page says so. Ask security@hellofixi.com and it is answered within 2 working days.

Reporting a vulnerability

No bounty, no legal threat

Send it to security@hellofixi.com. It is acknowledged within 2 working days. Fixi Group Limited does not pay a bounty and will not take action against anyone who reports in good faith and does not access or alter data that is not theirs.

Full terms at /legal/vulnerability-disclosure, and machine-readable contact details at /.well-known/security.txt.

What this page is not

9 items above are not published yet, and each says what it needs rather than carrying a figure nobody has checked. A row marked as a stated intent describes the position Fixi means to hold and has not been independently verified, and it must not be quoted as though it had been. A reviewer who needs any of them today should ask, and a reviewer who needs a warranty should ask for it in the agreement rather than rely on a website.