Security & Certification

Your data is safe with Rosslyn

Your business data is critical, and protecting it is fundamental to how we operate.

Rosslyn applies technical and organisational security measures designed to protect the confidentiality, integrity and availability of customer information throughout its lifecycle.

 

Security & Trust

ISO 27001:2022

Security is about more than technology. It requires effective governance, processes and people.

Rosslyn maintains an Information Security Management System certified to ISO/IEC 27001:2022, providing independent assurance of our structured approach to managing information security risks.

Our security framework helps us continually assess risk, maintain appropriate controls and improve the way we protect our systems and customer information. 

  → ISO 27001 2022 Certification
   NQA_ISO27001_CMYK_UKAS_1

 

Protecting your information

Security is embedded into the way we operate and deliver the Rosslyn Platform.

Our information security framework combines governance, policies, processes and technical controls designed to protect customer information and the services we provide.

GDPR

We are committed to responsible handling of personal and business information and maintaining processes that support applicable data protection and privacy requirements, including the UK GDPR.

→ Read our GDPR Commitment

Secure Cloud Infrastructure

The Rosslyn Platform is hosted on Microsoft Azure, providing a secure, scalable and resilient cloud foundation for our services.

Rosslyn combines Microsoft's cloud infrastructure capabilities with our own information security, governance and operational controls to protect customer information and the services we provide.​‌

Continuity & Resilience

We recognise the importance of maintaining the availability and resilience of the services our customers depend upon.

Business continuity and disaster recovery arrangements form part of our approach to managing operational risk and supporting the continued delivery of our services.

Monitoring & Risk Management

Our security programme includes ongoing security monitoring, vulnerability management and risk management processes designed to help identify, assess and respond to security risks.

Our people are supported by information security policies, defined responsibilities and ongoing security awareness activities designed to promote responsible handling of information and effective security practices.

 

Operational Resilience

Supporting customers in regulated industries

Rosslyn understands the importance of operational resilience, information security and technology risk management, particularly for customers operating in regulated and security-conscious industries.

Our approach to security, business continuity, supplier management and technology risk management is designed to provide customers with information and assurance to support their own supplier and operational resilience assessments.

Digital Operational Resilience Act (DORA)

For customers operating within the European financial services sector, we provide information about our approach to supporting customer requirements associated with the Digital Operational Resilience Act (DORA).

→ Read our DORA Statement

 

Security Assurance

Need more information?

We understand that customers and partners need to assess the security, privacy and operational resilience of the organisations they work with.

Rosslyn can provide additional security and compliance information through our customer assurance and due diligence processes where appropriate.

Whether you're assessing Rosslyn as a new supplier or reviewing an existing relationship, our team can help with your security and compliance enquiries.

→ Contact us