We use essential cookies to run our website and optional cookies to improve your experience. Please accept optional cookies or choose to continue with essential only. See our Cookie Policy for more details.
We understand that your data is sensitive, particularly product information and customer documents. Ensuring that you can use our platform with confidence is our number one priority.
As a UK-registered company, we comply with the UK Data Protection Act 2018 and UK GDPR, aligning with applicable EU GDPR requirements where relevant. Metron Labs supports GDPR compliance as a secure data processor with documented processing activities.
Cyber Essentials is a UK government-backed scheme that helps organisations protect against common cyber threats. This reinforces our commitment to maintaining a secure IT environment and implementing fundamental security controls across our systems and operations.
We are certified against the requirements of ISO 27001, the world’s leading information security standard. This reflects our ongoing commitment to maintaining strong information security controls and best practices.
For security or compliance questions, contact us at [email protected]. We’re happy to provide further documentation and discuss enterprise requirements.
All data transmitted to and from Metron Labs is encrypted using TLS 1.2 or higher. Data stored on our platform—including uploaded documents and extracted outputs—is encrypted at rest using AES-256.
Role-based access control lets administrators define who can upload documents, run workflows, view outputs, and manage integrations. Permissions are scoped at the organisation, project, and resource level.
API authentication uses short-lived tokens scoped to specific operations. Rate limiting and abuse detection are applied at the API gateway. All API traffic is logged and observable.
Metron Labs is hosted on Microsoft Azure. We follow vendor-recommended security baselines and apply updates and patches on a regular cycle.
Our user data is never used by 3rd parties to train foundational models. Data is processed only to deliver responses, meaning providers do not reuse it for training.
We use cloud-native monitoring and service telemetry to track platform health, detect issues early, and support reliable day-to-day operations.
Our team is happy to provide documentation, answer compliance questions, or discuss enterprise security requirements.