Security & governance

Designed for UK GDPR-aligned processing.

A security-first product posture suited for councils, housing associations, insurers and procurement teams. Recommendations are advisory only.

Human oversight

The platform recommends only. Authorised officers make every final allocation decision.

Audit logging

Append-only audit records for every recommendation, override and decision.

Role-based access

Six roles from System Admin to Read-only Auditor. Designed to integrate with Microsoft 365 / Azure AD.

Encryption

Designed for encryption in transit and at rest in production deployments.

Data minimisation

Only fields required for matching are processed. No free-text personal data is required by the engine.

DPIA support

Documentation, model card and field-level descriptions are provided to support the Controller’s DPIA.

Incident response

Documented incident response and notification process for production deployments.

Designed for ISO-aligned controls

Built with procurement-ready security principles. No ISO27001 or SOC2 certification is claimed unless evidenced.

Controller / processor model

Local authorities and housing associations are normally the Controller for resident data. Jigsaw normally acts as Processor where processing resident data on documented instructions. Accommodation providers may sometimes act as independent controllers depending on the arrangement.

UK GDPR Article 22 positioning

This platform does not make solely automated decisions producing legal effects on the individual. Every recommendation is reviewed by an authorised officer who makes the final decision. Officers can override or reject any recommendation and must log a reason.

Careful language

We do not claim ISO27001 or SOC2 certification, nor do we claim 100% UK sovereign cloud, unless those claims are evidenced in writing for your specific deployment. We say: designed to support ISO-aligned security controls, and built with procurement-ready security principles.

See the working demo — with synthetic data.

Open the officer console and try the matching workflow.