How we keep your data safe

Compliance frameworks — evidence walkthroughs

Every framework below ships with an evidence-walkthrough document mapping PatchPilot features to specific control IDs — the exact thing an auditor or insurer asks for.

UK Government Backed

Cyber Essentials & CE+

Patch management, secure configuration, malware protection, and access control mapped to all five Cyber Essentials controls.

ISO/IEC

ISO 27001:2022

Annex A controls 5.x — 8.x covered with audit-log evidence and policy attestations.

AICPA

SOC 2 (Type II ready)

Trust Service Criteria evidence pack — CC6.x (Logical Access), CC7.x (System Operations), CC8.x (Change Management).

UK Data Protection

UK GDPR

Article 32 technical measures, Article 28 processor obligations, DSAR-ready data export & delete.

Healthcare

HIPAA Security Rule

Administrative, physical, and technical safeguards mapped to PatchPilot controls.

Payment Card

PCI-DSS v4

Patching, vulnerability scanning, audit-log retention, and access-review evidence.

Evidence walkthroughs (markdown, customer-redactable) are bundled with every paid plan. Your CISO, auditor, or cyber-insurance underwriter can pull the exact evidence they need from the audit log without going through us.

Responsible disclosure

If you believe you have found a security vulnerability in PatchPilot, please report it privately to security@patchpilot.co.uk. We commit to:

Out of scope

Encrypted reports

For sensitive reports, please request our PGP public key by emailing security@ and we will respond with the key fingerprint and a current key file.

Security controls in production

What we do not collect

The agent intentionally collects the minimum signal needed to do its job. We do not collect:

Incident response

In the event of a security incident affecting customer data:

Our backup-restore runbook is exercised at least quarterly; restore-to-clean-DB is timed and recorded in the launch-readiness compliance pack.

Talk to security

Disclosure
security@patchpilot.co.uk — private; PGP available on request
Compliance
compliance@patchpilot.co.uk — auditor & insurer evidence requests