Skip to main content

Security & Compliance

Security & Compliance

TakeNote is built to handle some of the most sensitive conversations in financial services — client meetings where pensions, investments, health conditions, and family finances are discussed openly and in detail.

Security architecture

Multi-layered protection designed for regulatory environments

UK-hosted core platform

Primary customer data and application hosting are located in the United Kingdom. Certain approved sub-processors perform transcription, AI processing and electronic signature services within the European Union. Full processing locations are listed in our Sub-Processor Register.

Encryption

Customer data is protected using AES-256 encryption at rest and TLS 1.3 in transit. Encryption keys are managed by our approved infrastructure providers under their key-management controls.

Network security

All traffic served over TLS with managed DDoS protection at the edge. Firm data is logically isolated at the database layer by row-level security policies scoped to each company.

Access controls

Role-based and team-scoped access controls are applied. Microsoft Entra ID SSO is available, allowing customers to enforce MFA and Conditional Access through their own identity provider. Administrative access is protected using enhanced authentication controls.

Audit logging

Administrative events are recorded in a tamper-resistant, append-only audit log and retained in accordance with approved operational, contractual and compliance requirements. Additional application and security events are monitored in accordance with our Security Audit & Monitoring Policy.

Compliance framework

Built to support FCA-regulated advisory firms

FCA-structured output

Meeting summaries structured around suitability requirements, risk profiles, capacity for loss, and vulnerable customer indicators.

MiFID II record-keeping support

Retention controls and administrative audit records to support your firm’s record-keeping obligations.

Consumer Duty evidence

Captures structured evidence of client understanding, value demonstration, and fair outcomes.

UK GDPR

Designed to support compliance with UK GDPR and the Data Protection Act 2018. A comprehensive Data Processing Agreement is available.

ICO Registration: ZB622400

Data protection

Your data, your control, your terms

No training on client data

Client data is never used to train, fine-tune, or improve AI models. This applies to all data without exception — contractually guaranteed.

Data isolation

Each firm’s data is logically isolated using row-level security. Users can access only data associated with their authorised firm and role; authorised support access is restricted and controlled.

Secure deletion

Industry-standard secure deletion methods at end of retention period. Written confirmation provided within 30 days.

Data portability

Export data at any time in structured, machine-readable formats. Full data return or secure deletion on service termination.

Operational security

Security practices embedded in our operations

Personnel security

Background checks including DBS, binding confidentiality obligations, mandatory annual training, immediate access revocation on departure.

Vulnerability management

Continuous automated vulnerability monitoring is performed using Intruder, alongside dependency monitoring and secure-development testing. Findings are prioritised and tracked to remediation. Independent third-party penetration testing is planned.

Incident response

Documented incident response procedure. Advisory firm notified within 24 hours of any breach.

Business continuity

Automated backups with point-in-time recovery enabled, giving a 1-hour recovery point objective. 99.9% uptime SLA.

Certifications and standards

CertificationStatus
Cyber EssentialsValid until 4 August 2027Certified
ISO 27001In progress
ICO registeredZB622400
GDPR compliantYes
Cyber Essentials certified under the IASME scheme. Valid until 4 August 2027.

Due diligence support

Documentation to support your vendor assessment

Cyber Essentials certificate

Data Processing Agreement (DPA)

Data Protection Impact Assessment (DPIA) summary

Sub-processor list with processing locations

Security whitepaper

Infrastructure architecture overview

Responses to vendor assessment questionnaires (SIG Lite, CAIQ, or bespoke formats)

To request documentation or arrange a security discussion, contact dpo@takenote.ai

Frequently asked questions

Questions about security?

We welcome security questions from prospective and existing clients. Whether you need documentation for a vendor assessment or want to discuss our architecture in detail, please get in touch.

ClientScan Limited

7 Bell Yard, London WC2A 2JR

Registered in England and Wales

Company number: 14828718

ICO registration: ZB622400

Need detailed FCA compliance information?

Our FCA Compliance page provides comprehensive guidance on regulatory obligations and how TakeNote meets each requirement.