How Performalise FZ LLC protects your data — TLS 1.3 encryption, AWS infrastructure, ISO 27001 alignment, annual pen tests, and 99.88% uptime.
Summary: Performalise FZ LLC is built on AWS infrastructure, encrypted end-to-end with TLS 1.3, aligned to ISO 27001, and independently pen-tested. We maintain 99.88% uptime and respond to security incidents within defined SLAs. This policy forms part of our Terms of Service.
The security of your data is fundamental to everything we build at Performalise. This page describes our technical and organisational security measures, our obligations to you, and your responsibilities as a customer. This Security Policy is incorporated by reference into our Terms of Service and Data Processing Agreement.
Our security programme is aligned with the ISO/IEC 27001:2013 framework for information security management.
For questions relating to data protection and privacy, please see our Privacy Policy and Data Processing Agreement.
All Performalise data and platform services are hosted on Amazon Web Services (AWS), utilising multiple availability zones to provide redundancy and resilience. AWS maintains ISO 27001, SOC 1/2/3, and PCI-DSS certifications.
For information on AWS security practices, see aws.amazon.com/security
All data transmitted between your browser or API client and Performalise is encrypted using TLS 1.3, providing:
TLS 1.0 and 1.1 are disabled. Our TLS configuration is graded A+ by Qualys SSL Labs.
All stored data — including Customer Data, database backups, and file storage — is encrypted at rest using AES-256 via AWS Key Management Service (KMS) with regular automated key rotation.
Penetration test executive summaries are available to enterprise customers under NDA upon written request to [email protected].
We maintain a documented Security Incident Response Plan (SIRP). In the event of a confirmed Personal Data Breach:
To report a suspected security incident: [email protected]
Uptime target: We aim for 99.8% monthly availability, excluding scheduled maintenance windows (10:00 pm to 2:00 am UK time on Business Days) and events beyond our reasonable control. This is a target, not a contractual guarantee unless expressly stated in your Order Form.
Achieved uptime: 99.88% over the last 12 months.
On termination, Customer Data is available for export for 30 days, after which it is securely deleted. Written confirmation of deletion is available on request.
Shared responsibility: Performalise FZ LLC secures the platform infrastructure. You are responsible for the security of your own network, endpoints, user credentials, and configuration choices within the platform. We are not liable for data breaches that originate from compromised customer-side credentials, devices, or misconfigurations.
| Standard / Regulation | Status |
|---|---|
| ISO/IEC 27001:2013 | Aligned — formal certification in progress |
| UK GDPR & Data Protection Act 2018 | Compliant |
| EU GDPR (Regulation 2016/679) | Compliant |
| PECR 2003 | Compliant |
| AWS Shared Responsibility Model | Adopted |
| OWASP Top 10 | Mitigated — tested annually |
We operate a responsible disclosure programme. If you discover a potential security vulnerability:
This Data Security Policy is governed by and construed in accordance with the laws of England and Wales. It forms part of the Terms of Service between Performalise FZ LLC and its customers. Any disputes arising in connection with this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Performalise FZ LLC
Email: [email protected]
Platform: www.performalise.com