Pocket PMO
Trust Centre

Enterprise-ready by design and default

Pocket PMO is a UK project management platform built for internal PMs and small PMOs. This Trust Centre sets out how we secure your data, what we process, how our AI works, and who we work with. Contractual detail (DPA, SLA, insurance) is available on request from admin@pocketpmo.co.uk.

A note from the team

We are not SOC 2 or ISO 27001 certified today. We would rather earn trust with honest architecture than a badge we do not have. We publish a public trust roadmap of everything we have deliberately parked, so procurement teams can see exactly where we are — and where we plan to get to.

Security

AES-256 · TLS 1.3

Encryption, authentication, MFA, session policy, audit trail, tenant isolation.

Read more

Privacy

ICO ZC137312

UK GDPR-aligned. ICO-registered controller. Self-serve rights at /data-privacy.

Read more

AI

No training on your data

Approval-first AI. Human commit required for every state change and external message.

Read more

Sub-processors

10 processors

Every third party that touches customer data, kept current.

Read more

Managed Postgres

Row Level Security on every business table, with explicit GRANTs per migration.

EU hosting

Managed Postgres, static hosting and edge functions. Primary region confirmed on request.

Approval-first AI

AI never edits data or communicates externally without an explicit human commit.

Public status

Live health checks at /api-status. Release history at /changelog.

Enterprise Readiness Pack

18 documents. Viewable online, downloadable as PDF, versioned.

Open document library

Working through procurement?

Ask for a DPA, sub-processor list, penetration test summary (under NDA), or a completed security questionnaire. We turn most requests around in a few working days.