Platform Security Policy

Version 3.0 | Last updated 18th June 2026

1. Introduction

1.1. This Platform Security Policy sets out the measures implemented by ArtAML™ Limited to safeguard personal data, ensure platform resilience and maintain compliance with applicable regulations. The policy is designed to provide assurance to clients and their customers regarding the security of personal data processed through the ArtAML platform.

1.2. If you have been asked to provide personal information through the ArtAML platform by an art business, this policy explains the security measures in place to protect your data. ArtAML is used by regulated art businesses to meet their legal obligations under the Money Laundering Regulations. Your information is stored securely, accessed only by authorised personnel, and handled in accordance with UK data protection law.

2. Data Security

2.1. ArtAML applies layered security measures to protect the confidentiality, integrity and availability of data. All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256. Keys are managed securely with appropriate rotation practices. Confidential information is segregated logically within the multi-tenant environment. ArtAML is designed to support the collection and retention of information required for AML compliance purposes while minimising unnecessary processing of personal data.

3. Security Controls Framework

3.1. The following categories of controls are applied across ArtAML systems and infrastructure:

3.1.1. Physical Access Controls

3.1.1.1. ArtAML’s hosting and storage sub-processors operate ISO/IEC 27001-certified and SOC 2-audited data centres. Current providers include DigitalOcean and Backblaze. The current list of sub-processors is set out in the Data Processing Agreement.

3.1.2. System Access Controls

3.1.2.1. Multi-factor authentication is required for administrative access. Strong password policies are enforced including minimum length, complexity and expiration. Unique user IDs are assigned to all users. Sessions are logged and monitored to detect unusual or unauthorised activity. Authentication mechanisms include secure tokens and role-based permissions.

3.1.3. Data Access Controls

3.1.3.1. Role-based access controls restrict data access to personnel with a legitimate business need. Access rights are reviewed regularly and revoked promptly when no longer required. All access to personal data is logged. Encryption at rest ensures data is protected against unauthorised disclosure.

3.1.4. Transmission Controls

3.1.4.1. All data transmitted between clients, their customers and ArtAML systems is protected using TLS 1.2 or higher. Secure APIs are used for third-party integrations. Key management practices prevent interception or misuse.

3.1.5. Input Controls

3.1.5.1. System logs maintain records of data creation, modification and deletion. Input validation prevents malformed or malicious data from being introduced. Audit trails are maintained to support investigations and demonstrate compliance with the Money Laundering Regulations 2017 (as amended).

3.1.6. Data Backups

3.1.6.1. Encrypted backups are taken regularly and stored in geographically separate facilities. Backups are tested periodically to verify integrity and recovery capability. Secondary encrypted storage is provided by ArtAML’s storage sub-processor in ISO/IEC 27001-certified data centres. The current provider is identified in the Data Processing Agreement.

3.1.7. Data Segregation

3.1.7.1. Client data is logically segregated within the ArtAML multi-tenant platform. Database-level controls prevent unauthorised cross-client access. Segregation is preserved across live systems, backups and archives.

3.1.8. Cybersecurity and Vulnerability Management

3.1.8.1. ArtAML applies regular vulnerability scanning and patch management. Penetration testing is conducted at least annually by an independent third party. Findings are assessed, prioritised and remediated according to risk. Security patches are applied promptly. Network segmentation and firewalls restrict unauthorised access. An incident response process is maintained including escalation paths, containment measures and client notification. Threat intelligence feeds and monitoring tools are used to detect potential attacks.

3.1.9. Secure Development Practices

3.1.9.1. ArtAML incorporates security throughout the software development lifecycle. Code changes are subject to review prior to deployment. Dependencies are monitored for known vulnerabilities and updated where appropriate. Security considerations form part of system design, testing and release processes. Development, testing and production environments are logically separated.

3.1.10. Personnel Security

3.1.10.1. Access to ArtAML systems is restricted to authorised personnel. Personnel receive appropriate security and data protection training relevant to their role. Access rights are granted on the basis of least privilege and reviewed periodically. Personnel are only granted administrative access to the ArtAML platform, direct access to customer due diligence information, or access to underlying databases following appropriate background screening. For UK-based personnel this includes a satisfactory Disclosure and Barring Service (DBS) check. Equivalent screening appropriate to the relevant jurisdiction is applied for personnel based outside the United Kingdom.

3.1.11. Supplier Security

3.1.11.1. ArtAML undertakes appropriate due diligence when selecting key technology providers and periodically reviews their security and compliance credentials. Material sub-processors are identified in the Data Processing Agreement.

3.1.12. System Monitoring and Logging

3.1.12.1. Systems are continuously monitored for availability, performance and security events. Automated alerting mechanisms support rapid investigation and response to anomalous activity. Logs are centralised, time-synchronised and retained in line with compliance obligations. Monitoring supports incident detection and forensic investigation.

3.1.13. Compliance and Certifications

3.1.13.1. ArtAML and its hosting partners implement controls designed to support compliance with applicable data protection and security requirements. Hosting and storage sub-processors maintain ISO/IEC 27001 certification and independent SOC 2 assurance reports. Current sub-processors are identified in the Data Processing Agreement. Controls are aligned with the requirements of UK GDPR, the Data Protection Act 2018 and the Money Laundering Regulations 2017 (as amended). Security measures are designed having regard to the requirements of Article 32 UK GDPR concerning the security of processing.

3.1.13.2. Where clients operate under the laws of jurisdictions outside the United Kingdom, they remain responsible for ensuring that their own use of the ArtAML platform complies with any applicable local requirements. ArtAML will work with clients to support compliance where reasonably practicable.

3.1.14. Business Continuity and Disaster Recovery

3.1.14.1. ArtAML maintains business continuity and disaster recovery plans to ensure resilience. These include failover strategies, regular backup testing and restoration exercises. Recovery time objectives and recovery point objectives are defined and tested to support service availability during disruption. Business continuity and disaster recovery arrangements are reviewed periodically to ensure they remain appropriate to the scale and nature of ArtAML’s operations.

3.1.15. Incident Response

3.1.15.1. An incident response framework is in place to identify, assess and resolve security incidents. The framework includes escalation procedures, root cause analysis and corrective actions. Clients will be notified without undue delay if a security incident affects their data, and in any event within the timeframes set out in the Data Processing Agreement. Notification will include, where known, the nature of the incident, the data affected and the steps being taken to address it. Lessons learned are incorporated into updated procedures. Where a security incident affects the personal data of individuals, ArtAML will support its clients in meeting their obligations to notify affected data subjects in accordance with applicable data protection law.

4. Review and Updates

4.1. This policy is reviewed at least annually and updated as necessary to reflect changes in technology, regulatory requirements and best practice. Where updates are material, clients will be notified directly. Security incidents, vulnerabilities and control effectiveness are reviewed periodically to support continual improvement of the platform’s security posture.

5. Company Policies

5.1. ArtAML’s current policies are published on the ArtAML website. All current policies are accessible via the footer at www.artaml.com.

5.2. Individuals whose personal data is processed through the ArtAML platform should refer to the ArtAML Privacy Policy, accessible via the footer at www.artaml.com, for information about their rights and how their data is handled.

6. Contact

6.1. For security queries relating to this policy, please contact ArtAML Limited at: [email protected].

6.2. ArtAML’s Data Protection Officer is Dr. Chris King, contactable at: [email protected].

6.3. ArtAML Limited, 27 Old Gloucester Street, London, UK WC1N 3AX, company number 11806741.