Skip to content

Trust centre

Every claim here is testable.Most of them, you can test yourself.

UK-hosted in London, data resident in the UK, AES-256 at rest, TLS 1.2+ in transit, DPA on request. Operated by 99 Developers Ltd (company number 17257492), registered in England and Wales. This page collects what we do, who our providers are, what we hold, and - plainly - what we do not hold yet.

Company
17257492
Hosting
London, UK
At rest
AES-256
In transit
TLS 1.2+

What we operate

Controls you can check, not badges to take on faith.

01

Two-factor authentication, enforced in the database

TOTP two-factor authentication with recovery codes; once enrolled, a password-only session cannot read your documents - enforced in Postgres row-level security, not in the app. How our controls work

02

Per-tenant access control

per-tenant row-level security in Postgres, with a dedicated test suite that gates every change before merge. Row-level security explained

03

Monitored, encrypted backups

nightly encrypted database backups to separate offsite storage, 30-day retention, monitored by a dead-man's-switch. Backups and recovery

04

Hardened response headers

HSTS with preload, Content-Security-Policy, frame-ancestors 'none', nosniff and referrer controls on every response. Check any response yourself

05

Supply-chain scanning

dependencies scanned on every build and patched weekly; an automated security review runs on every pull request. Our release gates

06

Lawful international transfers

international transfers covered by Standard Contractual Clauses and the UK International Data Transfer Addendum. Read the DPA

07

Vulnerability disclosure

a published vulnerability disclosure route at /.well-known/security.txt. security.txt

These are not marketing sentences that drift: every factual claim on our public pages is registered and tied to an automated test that fails our build if the product stops making it true. And you do not have to take this page's word for anything the product does - point your AI assistant at our public MCP server and ask it directly; it answers from the source.

Certifications

Whose certificates these are.

We run on independently audited platforms: Supabase: SOC 2 Type II, ISO 27001; Cloudflare: SOC 2 Type II, ISO 27001/27018/27701, PCI DSS Level 1.

SOC 2 / ISO are held by our infrastructure providers, not by 99 Data Rooms; we run on their audited platforms and do not claim their audits as our own. 99 Developers Ltd does not currently hold its own certification. When we complete one, it will appear here with its certificate number and a link to the issuing register, and not a day before. The full provider detail is on the security page.

Data protection

The paperwork, published.

01

Data Processing Agreement

The full DPA text is published at /legal/dpa, including Standard Contractual Clauses and the UK International Data Transfer Addendum. A countersigned copy is available on request below.

02

Sub-processor register

Every third party that processes customer data is named in the sub-processor register, with what it does, where it runs, and how transfers are covered.

04

Where data lives

international transfers covered by Standard Contractual Clauses and the UK International Data Transfer Addendum. Primary data is resident in the UK (London); encrypted backups are held in an EU region. The detail is on the security page.

For your security review

Ask us for the documents.

Running vendor due diligence? Request a countersigned DPA, ask us to complete your security questionnaire, or request a written security overview. Tell us which you need and we reply within one business day.