Trust Center. What your security team will ask.

How AwardScience protects your programme data, where it is hosted, who processes it, and what we do and do not hold. Written for the security, privacy and procurement teams who review us.

Request our security pack
3Hosting geographies
30 daysSubprocessor notice
24hBreach notification

Security at a glance

The controls that protect every programme on AwardScience, on every plan.

01

Encrypted everywhere

All data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Encryption keys are held in a managed key service in your own hosting region.

AES-256TLS 1.2+Regional Keys
02

Controlled access

Multi-factor authentication and role-based, least-privilege permissions throughout. Administrative access is limited to named staff and every session is logged.

MFALeast PrivilegeAccess Logging
03

Tested resilience

Deployed across multiple availability zones, with a recovery copy in a second region of the same geography. Our disaster recovery exercise includes a full region failover, with recovery measured inside our targets.

Multi-AZCross-Region RecoveryDR Tested
04

Safe file uploads

Every uploaded file is quarantined and scanned for malware before anyone can open it, including judges and administrators. Clean files are served only through time-limited links.

Malware ScanningQuarantineSigned Links

Documents and policies

Public pages you can read now, and the documents we share with enterprise customers during evaluation.

Subprocessor register

Every third party that processes customer data, what it does, where, and under which safeguard, with a map of hosting regions.

Read the register →
Public

Responsible AI

Every AI feature and the data it sees, mandatory human review, and our commitment that no customer data trains any model.

Read our AI principles →
Public

Privacy notice

How personal data is collected, used and protected across AwardScience.

Read the notice →
Public

Data Processing Agreement

A DPA incorporating the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss amendments, for enterprise customers.

On request

Security documentation

Our information security policy set, disaster recovery and business continuity test results, and a completed security questionnaire.

On request, under NDA

Terms and conditions

The terms that govern use of AwardScience.

Read the terms →
Public

Certifications

What we are working towards, and what we inherit from our infrastructure. We would rather be precise than impressive.

Our certification programme

KYWH Limited is working towards ISO/IEC 27001 certification, targeting May 2027. Our information security programme is documented across a full policy set and built around the ISO/IEC 27001 control domains.

In progress

Our infrastructure

AwardScience runs on Amazon Web Services, which holds ISO/IEC 27001 and PCI DSS certifications for the infrastructure we use.

Inherited from AWS

Privacy law

Built for GDPR and UK GDPR obligations through our DPA and transfer safeguards, and operated in line with the Hong Kong Personal Data (Privacy) Ordinance.

GDPR-ready

Security questions

The questions security and procurement teams ask us most.

Is AwardScience ISO 27001 certified?
Not yet. KYWH Limited, which operates AwardScience, is working towards ISO/IEC 27001 certification with a target of May 2027. The infrastructure AwardScience runs on is provided by Amazon Web Services, which holds ISO/IEC 27001 and PCI DSS certifications.
Where is our data hosted?
In the geography you choose at provisioning: the EU (Frankfurt), the US (N. Virginia) or Asia-Pacific (Singapore), each with a recovery copy in a second region of the same geography. The region is fixed by contract. Our team supports the platform from Hong Kong under documented access safeguards.
Do you sign a Data Processing Agreement?
Yes. Enterprise customers receive a DPA incorporating the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss amendments.
Is our data used to train AI models?
No. Customer data is never used to train, fine-tune or improve any AI model, ours or a provider’s. Every AI feature can be switched off, and people make every decision that affects an applicant.
How quickly will you tell us about a breach?
Enterprise customers are notified without undue delay and in any event within 24 hours of our becoming aware of a personal data breach affecting their data.
Is AwardScience independently tested?
Yes. The platform underwent an independent security assessment in 2024 covering the web application, infrastructure and API, with findings verified as resolved. Annual independent penetration testing begins in February 2027.
How do we request documents or report a vulnerability?
Email support@kyand.co. We share our policy set, disaster recovery test results and security questionnaire under NDA, and we take every vulnerability report seriously.

Reviewing us for your organisation?
Ask for the security pack.

Our policy set, disaster recovery test results and security questionnaire are available under NDA for enterprise evaluations.

DPA with SCCsHosted in EU, US or APACNo AI training on your data
Scroll to Top