CLEAR ON HOSTING,
SUPPLIERS & DATA RESIDENCY.

FaiceTech believes organisations should understand how sensitive technology is hosted, supported and governed. This page summarises core hosting, data residency, sub-processor and supplier assurance information for the current platform.

HOSTING & DATA RESIDENCY

UK-FIRST BY DEFAULT.

FaiceTech follows a UK-first hosting and data residency approach, with limited third-party services governed through supplier assurance and data protection controls.

UK
Primary region

Hosted in the UK
by default

Core platform services are deployed in UK regions by default, so operational data stays in the UK unless a justified exception applies.

EU encrypted DR archives

Disaster recovery archives are stored in EU encrypted object storage where applicable.

Supplier-governed third parties

Limited third-party services are used for specific operational purposes, governed through supplier assurance and data protection controls.

CORE SUB-PROCESSORS

WHO SUPPORTS THE PLATFORM.

A limited set of third-party services support hosting, monitoring, transactional communications and technical messaging.

DigitalOcean
Purpose
Cloud infrastructure, compute, networking, managed databases, object storage and deployment services.
Public note
UK-first data residency. SOC 2 Type II audited infrastructure.
MailTrap
Purpose
Transactional email relay for essential service communications such as invitations, account recovery and security-related emails.
Public note
Not used for marketing. Email content is deliberately limited, and sensitive information is accessed through the secure platform.
Better Stack
Purpose
Monitoring and observability for operational monitoring, fault detection, security event investigation, performance and availability analysis.
Public note
Logs are designed to avoid personal data, raw request payloads, credentials and biometric data.
Mercure Rocks
Purpose
Low-latency, server-initiated notification mechanism.
Public note
Notifications are designed not to contain biometric data, personal identifiers, images, names, metadata, client identifiers or tenant identifiers.
SUPPLIER ASSURANCE

RISK-BASED SUPPLIER GOVERNANCE.

Third-party services are assessed using a risk-based supplier governance approach. FaiceTech considers the nature and scope of processing, data residency, international transfer considerations, technical and organisational measures, contractual obligations, ongoing suitability and proportionality of supplier use. Supplier assurance supports FaiceTech's wider approach to privacy, security and accountable service delivery.

FAQs

TRANSPARENCY FAQs

Yes. FaiceTech uses a limited number of third-party services to support hosting, monitoring, transactional communications and technical messaging. These providers are governed through supplier assurance and data protection controls.

No. FaiceTech provides public transparency about supplier roles, data residency and safeguards, but does not publish sensitive implementation details that could expose attack surfaces or proprietary platform design.

Yes. FaiceTech's core platform is hosted on DigitalOcean infrastructure, which maintains SOC 2 Type II assurance. FaiceTech itself is not currently presenting itself as SOC 2 certified.

SECURITY, PRIVACY OR GOVERNANCE QUESTIONS?