Trust

Security & data protection

Reglo handles compliance data for regulated firms, so protecting it is core to the product. Here's how we host, secure, and process your data — in plain terms.

Last updated: 23 July 2026·UK GDPR / Data Protection Act 2018

UK data residency

Your data is hosted in the UK — AWS London (eu-west-2).

UK AI inference

AI runs in the UK via Amazon Bedrock. No training on your content.

Encrypted

Encryption in transit (TLS 1.2+) and at rest.

Human approval

AI assists; your team reviews and approves every change.

Hosting & data residency

The Reglo platform is hosted on Amazon Web Services in the UK (London region, eu-west-2). Your account content, uploaded documents, and any files processed for reviews are stored in the UK. Data at rest is encrypted, and all data in transit is protected with TLS 1.2 or higher.

AI & your data

  • UK inference. AI inference runs within our UK region via Amazon Bedrock. The models we use (from Anthropic and OpenAI) are accessed in-region through Bedrock.
  • No training on your content. We do not allow AI providers to use the content you submit to train their models.
  • Human approval. AI outputs are advisory. A person on your team reviews and approves before anything is finalised.
  • File reviews. When you connect LEAP, Clio or Actionstep, we access only the files and matters you scope, process them to provide the review, and do not retain them beyond that purpose. See our Data Processing Agreement.

Access controls

  • Role-based access controls within the product
  • Least-privilege access and multi-factor authentication for staff access
  • Network segmentation, secrets management, and audit logging
  • Regular patching, dependency monitoring, and vulnerability management

Sub-processors

We keep the list of third parties who help us provide the Services, along with their purpose and location, on a dedicated page. We give at least 30 days' notice before adding a new sub-processor that processes customer personal data.

View our sub-processor list

Availability

We aim for 99.9% monthly availability and design the platform for resilience, with regular backups and documented recovery procedures. We're an early-stage product and do not currently offer contractual service credits; where a signed agreement includes specific availability commitments, those terms apply. We'll keep customers informed of any significant service disruption.

Certifications & assurance

We're building toward SOC 2 and designing our controls against recognised standards as we grow. We don't claim certifications we don't yet hold. If your firm's due diligence needs more detail, we're happy to share security documentation and complete a security questionnaire — contact us and we'll help.

Incident response

We maintain documented incident-response and business-continuity procedures. If we become aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours where required, and affected customers without undue delay.

Reporting a vulnerability

Found a security issue? Please tell us at security@useReglo.com. We investigate every report and will work with you on responsible disclosure.