Technology
The technical answers
buyers actually need.
Better Outcomes, InsolVatrack and Partner Connect share the same technology foundations. Below are the questions security, compliance and platform teams usually ask us in a first review, together with our current answers. Anything not covered here is answered in a structured technical session on request.
Due-diligence questions
Eight questions, on the record.
Where is the service hosted?
Our platforms are hosted on UK infrastructure. Environments are region-locked with data residency configurable per customer where required.
How is customer data segregated?
Customer data is segregated at the organisation level, with role-based access control, MFA and named permissions inside each customer environment. Sensitive fields are further restricted by permission role.
See our full security summary →Is customer data used to train shared models?
No. Customer data is not used to train shared or cross-customer models. Any customer-specific tuning is opt-in, contractually scoped, and confined to that customer's environment.
What encryption and monitoring are used?
TLS in transit, at-rest encryption for stored data, key management aligned with industry practice, application-level monitoring, and a web application firewall in front of user-facing services. Third-party penetration testing is performed on a regular cadence.
What integrations and APIs are available?
Supported connectors for common telephony, CRM, email, calendaring and creditor-feed sources, plus a documented REST API for programmatic access. New integrations are scoped as part of implementation.
How are findings explained and challenged?
Every finding includes an inspectable evidence trail showing the relevant inputs, the assessment criteria applied, the supporting evidence and any recorded human decisions. Reviewers can inspect, calibrate and override, and their decisions are recorded alongside the original finding.
What remains subject to human approval?
Actions that materially affect a customer outcome, a regulated decision or the state of a case remain gated behind a named human approval step. Autonomy is scoped per capability rather than granted across the board.
What does implementation involve?
A phased engagement: scoping, configuration against your operating model, data mapping and migration, user acceptance testing and controlled cut-over. Timelines are set jointly with the customer and reviewed at each phase gate.
Engineering principles
How we build for complex and high-scrutiny operations.
Our technology foundations were shaped by the expectations of regulated and high-scrutiny environments. The same principles - security, segregation, evidence, human oversight and clear accountability - benefit organisations in every sector.
01
Evidence, not black boxes
Every finding includes an inspectable evidence trail showing the relevant inputs, assessment criteria, supporting evidence and recorded human decisions.
02
Humans keep the last word
Reviewers can inspect, calibrate and override any finding. Autonomy is scoped per capability and reviewed with the customer, not granted by default.
03
Segregated by default
Customer data stays inside the customer's environment. It is not used to train shared models and is not shared across tenants.
04
Measured against outcomes
Performance is reviewed against contracted thresholds and the customer's own outcome framework, not against internal vanity metrics.
Go deeper
Structured technical session with our engineering team.
A 30-minute technical review covering hosting, data segregation, integration model, human-in-the-loop boundaries and implementation approach - tailored to your due-diligence checklist. Or book a parallel Consumer Duty walkthrough.
