Our approach
Security by design: access controls, encryption, and auditability are built into core workflows
Privacy by default: we collect only what is needed to run the service
Continuous improvement: routine reviews and updates to policies, controls, and infrastructure
Data security
Encryption in transit and at rest using modern standards (TLS 1.2+)
UK/EU hosting in professionally managed data centres aligned to ISO 27001 practices
Encrypted backups and tested recovery procedures
โ
Access and authentication
Role-based access ensures users only see information relevant to their organisation
Admin-only controls for sensitive actions like inviting users and linking facilities
Session management to prevent unauthorised reuse of credentials
Infrastructure and availability
Proactive monitoring for uptime and unusual activity
Maintenance windows planned to minimise disruption
Fault-tolerant architecture with backup and restore capabilities
Payments and billing security
Payments handled by Stripe (PCI DSS Level 1)
ShiftNest never stores raw card details
Compliance and assurance
Operates in line with UK GDPR and the Data Protection Act 2018
ShiftNest is Cyber Security Certified
Third-party providers are vetted for security and compliance
Shared responsibility tips
Use strong, unique passwords for each account
Remove old user accounts promptly when staff leave
Review organisation details and permissions regularly