What reaches our servers
Browser encryption and local SDKs run on your machine. Hosted crypto APIs receive plaintext and passwords during processing. Cloud vault storage uploads encrypted data.
Surface-by-surface disclosure ↗Inspect certifications, engineering controls and the documented limits. An independent cryptographic audit is on the roadmap, not complete. Cyber Essentials does not validate the cryptographic construction.
Browser encryption and local SDKs run on your machine. Hosted crypto APIs receive plaintext and passwords during processing. Cloud vault storage uploads encrypted data.
Surface-by-surface disclosure ↗deny.sh is operated by Treehouse in Valhalla Ltd, registered in England and Wales. Read the processing, legal and operational documents for the applicable boundaries.
Compliance and control evidence ↗// pillar 1
What we hold today, verifiable independently. We do not list certifications we have not earned.
IASME, valid 15 May 2026 through 15 May 2027. Includes £25k cyber liability insurance via Sutcliffe & Co.
Verify on BlockMark →Treehouse in Valhalla Ltd is the UK data controller. Privacy policy and DPA published, DPA incorporable into commercial contracts on request.
/dpa →Controls documented and operating against TSC 2017 (with 2022 Points of Focus). Independent examination on the post-launch funding window. Firm and audit window announced once engaged.
Controls map →Annex A controls mapped against operational policies. Formal certification on the post-launch roadmap, parallel track ~6 months behind SOC 2.
Controls map →// pillar 2
Six controls backing the compliance posture above. Every claim lands in code you can read and a dashboard you can open.
01 · live
Tamper-evident hash chain over every operation, RFC 3161 trusted timestamps from an independent TSA, signed receipts you can hand to a regulator.
03 · live
Per-tier daily metering with headers, dashboards, and 80 / 95 / 100 percent email alerts. Quota events join the audit chain.
04 · live
Server-stored ciphertext wrapped with a per-record AES-256-GCM DEK, the DEK itself encrypted under your AWS KMS CMK. Revoke is dark.
05 · live
AWS Secrets Manager custodian, signed outbound webhooks (Datadog, PagerDuty, Slack), and SAML SSO (Okta-compatible, JIT provisioning).
06 · live
This trust center, the controls map (SOC 2 TSC and ISO 27001 Annex A), the lightweight status page, and the honest roadmap blog post.
// pillar 3
Every SOC 2 Trust Services Criterion and every ISO 27001:2022 Annex A control mapped to the moat or operational control that evidences it. Public index, with the deeper policy pack assembled under NDA on procurement engagement.
SOC 2 TSC 2017 with 2022 Points of Focus. CC1 governance · CC2 communication · CC3 risk assessment · CC4 monitoring · CC5 control activities · CC6 logical access (audit-chain, BYOK, integrations controls) · CC7 system operations (audit-chain, metering, integrations controls) · CC8 change management · CC9 risk mitigation · A1 availability · C1 confidentiality (BYOK, integrations controls) · PI1 processing integrity (audit-chain control).
ISO/IEC 27001:2022 Annex A. A.5 organisational · A.6 people · A.7 physical · A.8 technological (mapped against the same engineering controls and policies).
UK GDPR. Lawful basis, retention, rights, international transfers documented at /privacy and /dpa.
Out of scope today. HIPAA, PCI DSS, FedRAMP. Talk to us if your use case requires a specific posture.
// pillar 4
Everything you can pull down right now, no NDA required.
// pillar 5
Read the code, check the build, ping the health endpoint, examine the audit chain.
Write to hello@deny.sh. Under NDA we share the full controls pack: SOC 2 control documentation, ISO 27001 Annex A mapping, vulnerability management policy, vendor list with locations and roles, incident response runbook, business continuity plan, and the data residency matrix per plan tier. Five business day turnaround standard, faster on request.
For security findings, see /disclosure.