Security & Compliance · For Procurement Teams

We take data security seriously. Here is everything you need to know.

MetriqOS is built for the development sector, where data protection is non-negotiable. This page answers every procurement question.

H Hosting & Infrastructure
Primary hosting region
Coventry, United Kingdom — UK data residency
US region
Available on request for Pro and Enterprise tiers
Uptime SLA
99.9% uptime for Core tier and above
Backups
Daily automated backups · 30-day retention
Data at rest
AES-256 encryption
Data in transit
TLS 1.3
D Data Protection
UK GDPR
Data processed and stored in the United Kingdom, subject to UK GDPR and the Data Protection Act 2018
Tanzania law
Tanzania Data Protection Act 2022 compliant
Tenant isolation
Each organisation's data is logically separated. No cross-tenant data access — enforced at query level.
Personal data categories
Names, email addresses, project operational data. No sensitive personal data categories unless explicitly entered by the tenant.
O Data Ownership
Who owns the data
Your organisation does — unconditionally. MetriqOS is a processor, not an owner. We never claim rights over your programme data, beneficiary data, or reports.
Export
Full export to Excel/PDF (IPTT, logframe, DIP, audit packs, DATIM, IATI) at any time — not just on cancellation. No lock-in, no waiting period, no fee.
Delete
Tenant administrators can delete individual records, projects, or the entire organisation's data on request. This is your decision to make, not ours.
We do not sell your data
Not to donors, not to advertisers, not to anyone. Ever. Your data is used only to run the platform for you — not monetised, not shared, not repurposed.
Impartiality
MetriqOS is not a donor, evaluator, or auditor. We built the infrastructure — what your data says, and who you choose to share it with, stays entirely in your control.
A Access Controls
Role-based access (RBAC)
tenant_admin · project_manager · meal_officer · field_officer · viewer · safeguarding_focal
Impersonation
Super-admin can impersonate tenant users for support. All impersonation actions are flagged in the audit log with the acting admin's ID.
Audit log
Every data change, login, and user action is logged with timestamp, IP address, and user agent.
API authentication
Token-based (JWT) · 24-hour token expiry
Donor portal access
Time-limited token links · 90-day rolling expiry · hard 365-day cutoff · revocable at any time by tenant_admin
S Security Posture
SOC 2
Not yet certifiedRoadmap item for Q1 2027
ISO 27001
Not yet certifiedSecurity controls implemented · Certification planned Q2 2027
Penetration testing
Scheduled for Q3 2026
Vulnerability disclosure
E Enterprise SLA Commitments
Plan Uptime commitment Support response Additional
Seed Best effort Best effort
Core 99.5% 24-hour response
Pro 99.9% 4-hour response Named support contact
Enterprise Custom SLA Custom Dedicated account manager · Custom hosting region available

Have a procurement question?

Reach out to our security team directly. We respond within one business day.security@metriqos.net

Contact security team →