Technical and Organisational Measures (TOMs)
Dextro Compliance Operations
This document outlines the Technical and Organisational Measures (TOMs) implemented by Dextro to ensure the ongoing confidentiality, integrity, availability, and resilience of our processing systems, pursuant to Article 32 of the UK GDPR.
1. Technical Measures
1.1 Encryption & Data Security
- Data in Transit: All data transmitted between the Client, Dextro infrastructure, and operational staff is encrypted using TLS 1.2 or higher.
- Data at Rest: All databases and file storage are encrypted at rest using AES-256 encryption.
- Data Isolation: Dextro utilizes PostgreSQL Row Level Security (RLS) to ensure strict tenant isolation. Queries are strictly constrained by tenant IDs to ensure complete data isolation between accounts.
1.2 Access Control & Authentication
- Multi-Factor Authentication (MFA): MFA is strictly enforced for all administrative and operational access to the Dextro infrastructure.
- Secure Access Tokens: Candidate upload portals utilize 128-bit cryptographically secure identifiers (UUIDs) for magic links, protecting against enumeration and unauthorized access.
- Role-Based Access Control (RBAC): Access to Personal Data is granted strictly on a "least privilege" basis. Operators can only view data necessary to perform the specific verification task.
- Secure Identifiers: Dextro uses cryptographically secure UUIDs (v4) for all application resources.
1.3 Infrastructure & Resilience
- Cloud Hosting: Primary databases are hosted on ISO 27001-certified infrastructure (AWS London via Supabase).
- Edge Network: The application layer is hosted on Vercel's global edge network, providing automated DDoS mitigation and high availability.
- Backups: Automated, encrypted database backups are taken daily and stored in the UK region.
2. Organisational Measures
2.1 Personnel Security (Nigeria Operations)
- Background Checks: All remote operational staff undergo identity verification and reference checks prior to employment.
- Clean Desk Policy: Operational staff are required to adhere to a strict Clean Desk Policy. No physical copies of Personal Data are permitted.
- Device Security: Dextro operators work directly inside provisioned UK tenant environments via encrypted endpoints. We utilize strict operational workspace policies ensuring zero local file caching and prohibiting the downloading of any Client Personal Data to local hard drives or external media.
2.2 Vulnerability Management
- Automated Scanning: Dextro’s software dependencies are automatically scanned for known vulnerabilities prior to any deployment.
- Continuous Monitoring: All authentication events and database queries are continuously logged. Access logs are actively monitored to ensure only authorized personnel interact with client endpoints.
2.3 Data Retention
- Automated Document Lifecycle: Dextro does not indefinitely store candidate or client files. Documents are permanently purged from Dextro systems via automated routines 30 days after verification is completed or upon Client request.
Dextro Compliance Operations
Document Version: 1.0 (2026)