Security, breach & audit
Security, breach & audit
Breach notification
Emergent notifies you without undue delay and within 72 hours of becoming aware of a personal data breach (DPA Section 10.1). The notification includes the nature of the breach, the categories and approximate numbers of data subjects and records affected, our contact point, the likely consequences, and the measures taken.
Technical & organisational measures
Annex 2 of the DPA sets out our technical and organisational measures, including:
- Information-security policies and standards
- Physical security
- Incident response
- Network security
- Access control with periodic access reviews and offboarding deprovisioning
- Anti-virus and malware controls
- Personnel security training and a security-awareness programme
- Subcontractor security no less onerous than the DPA's own safeguards
- Business continuity and disaster-recovery planning
Note
Annex 2 describes examples of safeguards and is not a representation that every control applies to every component of the Services. The full text is at app.emergent.sh/dpa.
Audit & certification reports
On written request, no more than once every twelve months, Emergent makes available the information necessary to demonstrate compliance with the DPA, which can include certification reports or summaries (DPA Section 6.1). We also maintain an Article 30(2) record of processing.
Tip
Route audit and due-diligence requests to privacy@emergent.sh.
Encryption
Your data is encrypted in transit, and your secrets (API keys and environment variables) are encrypted at rest.

