Security
Green Compliance Intelligence is built entirely on Google Cloud Platform and inherits Google Cloud's infrastructure security by design. This page summarises how the service is hosted, accessed, and operated.
Hosting and infrastructure
The entire pipeline — ingestion, data transformation, AI enrichment, and delivery — runs on Google Cloud Platform in the europe-west2 (London) region. There is no other infrastructure provider in the stack. Data at rest (Cloud Storage, BigQuery) and data in transit are encrypted using Google Cloud's standard, always-on encryption.
Access control
Internal service accounts are scoped under the principle of least privilege: each Cloud Function and Cloud Run service is granted only the specific permissions it needs to perform its role, not broad project-level access. Deployments run through Workload Identity Federation rather than long-lived service account keys. Data-processing services accept traffic only from Google's internal infrastructure (Cloud Tasks, Cloud Scheduler), not the open internet, wherever the workload allows it.
Subscriber access to the Linked Dataset is read-only and scoped to your own GCP project. Data Endeavour has no access to, and does not require access to, subscriber GCP projects.
Automated quality and change control
All changes to the data pipeline are deployed through a version-controlled CI/CD pipeline (GitHub Actions), with no manual production changes. Automated data quality tests run after every weekly refresh, covering schema integrity, null-value checks, and referential consistency across the dataset.
Sub-processors
Data Endeavour uses the following sub-processors to deliver the service:
- Google Cloud Platform — hosting, data storage, BigQuery, Analytics Hub delivery, and AI inference (Vertex AI / Gemini). Governed by Google's Cloud Platform Terms of Service and a Data Processing Agreement.
See the Privacy Policy for the full data-sharing and international-transfer picture.
Incident response
In the event of a security incident materially affecting the confidentiality, integrity, or availability of subscriber data, affected subscribers are notified without undue delay and in any event within 72 hours of us becoming aware of it, in line with UK GDPR breach notification obligations. Full commitment: Terms of Service §6.4.
To report a suspected vulnerability or security concern, contact help@dataendeavour.co.uk.
Data protection
Data Endeavour Ltd is the data controller for subscriber account data and complies with UK GDPR and the Data Protection Act 2018. A Data Processing Agreement is available on request to legal@dataendeavour.co.uk. Full detail: Privacy Policy.
Roadmap
Data Endeavour is an early-stage vendor. Formal third-party security certification (e.g. SOC 2 / ISO 27001) is on the roadmap as the subscriber base grows, and will be reflected on this page once achieved.