Heed is ISO 27001 certified, demonstrating an independently audited and verified approach to information security management. This certification covers the policies, processes, and controls that govern how data is protected across the platform.
Heed's cloud infrastructure runs on Amazon Web Services (AWS), which holds its own ISO 27001 certification alongside SOC 1, SOC 2, and SOC 3 accreditations — providing a further layer of independently verified security at the infrastructure level.




Heed is compliant with the General Data Protection Regulation (GDPR), demonstrating a committed and accountable approach to the handling of personal data. This covers how data is collected, processed, stored, and deleted across the platform in line with European data protection law.
For organisations operating across multiple jurisdictions, Heed's flexible deployment options — including regional AWS hosting and true on-premises deployment — support the data residency requirements that sit at the heart of GDPR compliance.
Heed is trusted by organisations in financial services, healthcare, government, and construction — sectors where security and compliance are non-negotiable. See how Heed meets the demands of your industry.
Explore Industry Solutions


Heed's cloud platform runs on Amazon Web Services (AWS), one of the most widely audited and certified cloud environments available. AWS data centres hold ISO 27001 certification alongside SOC 1, SOC 2, and SOC 3 accreditations, providing a robust and independently verified foundation for the Heed platform.
For organisations that need their data to remain within a specific region or jurisdiction, Heed supports flexible AWS region selection to meet data residency requirements.
For organisations operating in regulated industries, knowing where your data is physically stored is as important as how it is protected. Heed's cloud platform is hosted on Amazon Web Services (AWS), which operates data centres across multiple regions globally. This gives us the flexibility to host your data within a specific geographic region to meet your organisation's data residency obligations.
If regional hosting alone does not satisfy your compliance requirements, Heed's on-premises deployment option ensures your data never leaves your own infrastructure entirely — removing any dependency on external hosting providers.


For organisations where data must remain entirely within their own walls — common in financial services, healthcare, and government — Heed offers true on-premises deployment. The software is installed and runs entirely within your own infrastructure. No data is routed through external servers, and no cloud dependency is introduced.
This is a meaningful distinction from vendors who offer "private cloud" arrangements that still rely on third-party hosting.
Secure



Heed cloud services are backed by a 99% uptime guarantee. Daily backups are performed across all systems, with backup data retained for up to 30 days.
In the event of a security incident, Heed follows a structured response process to identify, contain, and resolve issues quickly. Affected customers are notified promptly.
All Heed employees sign a confidentiality agreement and receive regular security training. Access to production systems is restricted to essential personnel only.
Have a question about how Heed handles your data? Here are answers to the questions we hear most often from IT and security teams evaluating the platform. If you don't find what you're looking for, get in touch with our team directly.
Yes. Heed is ISO 27001 certified, meaning our information security management practices have been independently audited and verified against the international standard.
Heed's cloud platform is hosted on Amazon Web Services (AWS). We support flexible region selection to meet your organisation's data residency requirements.
Yes. Heed offers true on-premises deployment, where the software is installed and runs entirely within your own infrastructure. No data is routed through external servers and no cloud dependency is introduced. This makes Heed well suited to organisations in financial services, healthcare, and government where data sovereignty is a requirement. Read our complete guide to on-premises internal communications for a detailed breakdown of how it works and what to consider when evaluating deployment options.
Yes. Heed supports SSO via Active Directory, SAML 2.0, and Office 365, allowing users to authenticate through your existing identity provider across both the management console and client applications.
All data in transit is encrypted using HTTPS with TLS 1.2 and Perfect Forward Secrecy. Data exchanged with Heed applications is further protected with AES-256 encryption, and locally cached data is also encrypted at rest using AES-256.
Talk to use about keeping your employees informed, engaged and inspired - book a call today!
Book a Call
