Security & compliance

Built for Irish data rules, not bolted on after

Company-scoped data, EU hosting, an audit trail on every change, and an AI that is barred from ever deciding an application. Here’s exactly how it’s built underneath.

  • Hosted in Ireland, inside the EU
  • Encrypted in transit and at rest
  • Role-based access with a full audit trail
  • Policy-driven GDPR retention, with a preview before deletion

At a glance

  • Ireland, inside the EU
  • Encrypted in transit & at rest
  • Every change audited
  • Checks cached, never scraped on open
  • AI barred from protected-ground reasoning
  • Company-scoped encrypted backups

How data is actually protected

Hosted in Ireland, inside the EU

Every company’s data lives in the EU. Everything is encrypted in transit and at rest, with company-scoped encrypted backups — one company’s data recovery is never mixed with another’s.

Role-based access, fully audited

Permissions are scoped by role, so a team member only sees what their role allows. Every change — who saw what, who changed what, when — is recorded in an audit trail.

Documents, never a public link

Uploaded payslips, bank statements and IDs are never served from a permanent public URL. Every download goes through a short-lived, signed link generated on request.

GDPR retention, on a schedule

Stale applications are purged per company and per status, on a schedule each company controls — with a deletion preview before anything is actually removed, never an instant bulk delete.

Background checks, cached — not scraped

RTB and bankruptcy checks are cached for a day and reused. Opening an application never triggers a live outbound lookup unless the result has actually gone stale.

Few dependencies, on purpose

A smaller dependency chain is a smaller attack surface. Real Enquiries is built in-house wherever that trade-off makes sense, instead of assembling a long chain of third-party packages.

The AI’s boundaries

The AI advises. It is never the decision-maker.

Application screening touches GDPR Article 22 and the Equal Status Acts, so the review is engineered to stay on the right side of both:

  • Never scores, ranks, or recommends an approve/decline on an application
  • Barred from mentioning or reasoning about any protected ground — even inside an uploaded document
  • Sensitive fields — nationality, date of birth, children, HAP status, PPS number — are never sent to the model
  • The AI’s own findings are purged on your company’s retention schedule, same as everything else
See how screening works end to end

Where we stand, honestly

What we have: EU hosting, encryption in transit and at rest, an audit trail on every change, policy-driven retention, and an AI that is technically barred from deciding anything.

What we don’t have yet: a formal SOC 2 or ISO 27001 certification. Real Enquiries is a small, actively-developed product — if that’s a hard requirement for your organisation, talk to us about where we’re headed.

Questions about a specific requirement? Ask us directly — a straight answer beats a vague one.

Ready to make Real Enquiries your operating system?

Join the waiting list for pilot pricing, onboarding support and the launch-partner roadmap.

Privacy Policy Disclosures

We partner with Microsoft Clarity and Meta Pixel to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft and Meta Pixel collect and use your data, visit the Microsoft Privacy Statement and the Meta Privacy Policy.