Home / Trust Centre

Trust Centre

How we secure this website, the partner portal and the data you share with us — and how that maps to recognised security standards.

Last updated: 19 July 2026

Our commitment

Vision Telematics designs security in rather than bolting it on. This page describes the controls protecting our website and partner portal, plainly and honestly: where we align with a recognised standard we say aligned — we do not claim certifications we don’t hold.

Infrastructure & encryption

  • All traffic is encrypted in transit with TLS 1.2/1.3 and HSTS; nothing is served over plain HTTP.
  • Hosted on AWS (London region) behind a hardened edge with strict security headers, a restrictive Content-Security-Policy and rate limiting on every sensitive endpoint.
  • Releases go out through an automated pipeline from version control — no hand-edited production servers and no long-lived deployment credentials.

Access control & authentication

  • Partner portal sign-in requires two-factor authentication — a one-time code by email or WhatsApp on top of the password.
  • Enterprise single sign-on is supported via OpenID Connect, OAuth 2.0 and SAML 2.0, including Microsoft Entra ID, AWS Cognito, Keycloak, WorkOS and Firebase.
  • Administrative access uses named accounts with authenticator-app two-factor; there are no shared passwords.
  • Sign-in attempts are rate-limited at both the network edge and the application layer.

Data protection & privacy

  • We collect the minimum: the enquiry details you choose to send us and partner account data. Browsing this site sets no cookies at all, and we use no analytics, advertising or tracking.
  • Designed to comply with UK GDPR and PECR — see our Privacy Policy and Cookie Policy.
  • Secrets and credentials live only in server-side configuration, never in source code or the browser.

Resilience & recovery

  • The database is backed up daily, with 14 days of retained snapshots and tested restore tooling.
  • The website is rebuilt from version control on every release and can be redeployed in minutes.

Responsible disclosure

Found a vulnerability? We want to hear about it. Email info@visiontelematics.com and we’ll acknowledge promptly — machine-readable details are published at /.well-known/security.txt. Please avoid accessing other people’s data or disrupting the service while researching.

Standards alignment

An honest summary: aligned means our technical controls follow the standard’s requirements at website scope — it does not mean certified.

StandardOur position
Cyber EssentialsTechnical controls in place; certification is on our roadmap.
UK GDPR / PECRDesigned to comply: minimal data, consent where required, published policies.
NIST CSF 2.0Aligned: strong protection and recovery controls; detection and response processes are being formalised.
CIS Controls v8.1Core safeguards implemented: secure configuration, multi-factor authentication, access management, data recovery and a vulnerability-disclosure channel.
ISO 27001 / ISO 27701Practices informed by both; not certified. Personal-data handling follows ISO 27701 principles.
NIS2 / DORA / HITRUST / FedRAMPNot in scope for our activities; we support customers’ own supply-chain security duties under these regimes.

Subprocessors

Third-party services that may process data when you use this site:

ServicePurpose
Amazon Web Services (London)Hosting
Twilio SendGridTransactional email — enquiries and sign-in codes
TwilioWhatsApp sign-in codes
Cloudflare TurnstileBot protection on forms
Google FontsTypeface delivery
postcodes.ioUK postcode lookup on order forms

Questions

Email info@visiontelematics.com or call 0800 020 9339 — we’re happy to complete security questionnaires for customers and prospective partners.