Trust
What we commit to on security, data handling and contracts. Written for your legal and procurement review.
Last updated 30 Sep 2026
Our clients control the contact data they submit. We process it as their processor, on their documented instructions only.
The measures in force today, as set out in Annex B of our DPA.
Role-based access on a need-to-know basis. Unique credentials, multi-factor authentication for admin access, and prompt revocation on role change.
TLS 1.2 or higher on all API and web traffic. Stored payloads, logs and backups are encrypted at rest.
Query payloads are processed in memory or short-lived storage. They are purged within 24 hours.
Firewalls, network segregation, hardened hosts and timely security patches.
Security event logging, monitoring for unauthorized access attempts and alerts on unusual activity.
Periodic vulnerability scans. Fixes are prioritized by severity.
Confidentiality undertakings and security training for everyone with access. Background screening where the law permits.
A documented procedure that supports the 48-hour breach notice.
Encrypted backups with rolling deletion, and documented recovery procedures.
We run lookups through vetted telecom and data intelligence partners. Their identities are commercially confidential.
Our standard documents, summarized. Request the full set and we will send it to your work email.
Signed first
The framework
Before any processing
These summaries are for convenience. The signed agreements govern.
We will send the documents to .
Legal and privacy
legal@scoremachine.aiTechnical and support
support@scoremachine.aiRegistered office
Scoremachine Software FZ-LLC, HD42B, First Floor, In5 Tech, Dubai Internet City, Dubai, UAE