Security & Compliance
Circit has achieved both SOC 1 and SOC 2 Type II compliance. This reflects our strong commitment to maintaining industry recognised standards in security, reliability, and control assurance.
SOC 1 is an independent audit standard that validates the internal controls that support financial reporting. SOC 2 is a compliance standard developed by the American Institute of CPAs (AICPA) that focuses on the security and privacy of customer data. Together, these certifications provide customers with greater confidence in the strength and consistency of Circit's control environment.
Circit and its staff are governed by robust procedures and administrative controls which are certified to the highest international security certification standards. Our focus on security protects your clients’ highly sensitive data in the most robust way.

Circit creates a comprehensive and immutable audit trail between all parties, embedding a timestamp, digital certificate, IP address and end-user information.

All content is encrypted in transit and at rest. Cryptographic keys are safeguarded using Hardware Security Modules (HSM’s) which are FIPS 140-2 Level 2 validated.

Circit has been built with security at its foundation and leverages Microsoft Azure to ensure multi-layered security is in place. Physical datacentres, infrastructure, firewalls and operations all have active monitoring ongoing everyday to protect your clients' assets and financial data.
Circit is proud to be a certified carbon neutral business. We have met all Carbon Neutral Britain Certification™ standards, ensuring that our organisational carbon emissions, including those within Scope 1, 2, and 3 GHG emissions, are fully measured, calculated, and offset.

GDPR
Circit is the only directly regulated platform focused on audit technology. Meeting the EBA and FCA standards as a Regulated Account Information Services Provider provides additional assurance over the security and control of your clients' data. There is no requirement for you to be regulated or become an agent when using the platform as a firm.
We are fully compliant with EU General Data Protection Regulations. All data and sub-processors in the platform remain in the EU. Our strict adherence to GDPR and our data security helps customers to ensure their own compliance.
We are fully compliant with the International Standards on Auditing ISA 505 external confirmations.
Circit uses eIDAS digital certificates to ensure documents signed within the platform are highly secure and legally binding.
