Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
Legal

Privacy

Last updated: January 2026

InfraEdge takes a deliberately minimal approach to data. We collect what we need to operate the website, communicate with customers and deliver agreed services. Our assessments are designed to avoid collecting application data, credentials or secrets wherever possible.

Who we are

InfraEdge provides cloud infrastructure assessment, remediation, continuous assurance and technical diligence services across AWS, Azure and Google Cloud, with AWS as our deepest specialism.

Our products are EdgeReady, EdgeResolve, EdgeAssure and EdgeSignal.

For questions about privacy or the information we hold, contact support@infraedge.org.

Information you provide to us

We may receive information when you contact InfraEdge, request an assessment, book a call, enter into an engagement or otherwise communicate with us. This may include:

  • your name;
  • work email address;
  • company and job title;
  • telephone number where provided;
  • correspondence with us;
  • billing and contractual information; and
  • information you provide when describing your infrastructure or requirements.

We only ask for information that is reasonably necessary for the relevant purpose.

Website enquiries

When you send the form on our contact page, request a sample report, or complete the questionnaire on Find your path, the details you typed are posted to /api/lead on this domain and arrive as an email in our inbox. There is no database behind the form and no tracking pixels.

What is sent: your name, work email address, company where given, what prompted the enquiry, your message, and the address of the page you sent it from. From the questionnaire we also receive the answers you selected — as identifiers such as situation=production-unclear, not free text — and the recommendation those answers produced, so we can see whether the routing was sensible before we reply.

The questionnaire's recommendation is shown to you on the page. We also email you a copy of it from kas@infraedge.org, because a recommendation you cannot forward to a colleague is not much use. That email is the report and a reply address; it is not a marketing message.

How it travels: our own endpoint on this domain, served by Amazon CloudFront, handled by an AWS Lambda function and delivered by Amazon SES in the eu-west-1 (Ireland) region, to a mailbox hosted by Titan. Diagnostic logs for that function are kept for 30 days and deliberately exclude your address and the body of your message.

If the request fails for any reason, your own email client is opened with the same details so nothing you typed is lost. Nothing is sent in that case until you press send.

We use an enquiry to reply to you and, if it becomes an engagement, to scope it. Sending an enquiry does not add you to a marketing list.

Optional emails about our writing

The questionnaire offers a separate, optional tick box for occasional InfraEdge writing on platform engineering. It is unticked by default, it is not required to receive your result, and nothing else on this site subscribes you to anything.

If you tick it, we record that consent alongside your enquiry and use it as the lawful basis for sending you that occasional writing. You can withdraw it at any time by replying to any email from us or writing to support@infraedge.org, and we will stop.

We hold no list of anybody who has not ticked that box.

Infrastructure information

Delivering an InfraEdge engagement may require us to analyse technical information about your cloud environment and associated engineering systems. Depending on the agreed scope, this may include:

  • account, subscription and organisation structure;
  • resource configuration and metadata;
  • identity roles, policies and permission configuration;
  • network configuration;
  • security and logging configuration;
  • backup and resilience configuration;
  • infrastructure-as-code configuration;
  • Terraform metadata and state information where explicitly provided;
  • repository and CI/CD configuration;
  • infrastructure change history;
  • monitoring and observability configuration;
  • infrastructure findings and assessment results; and
  • technical ownership and operational documentation.

Our assessments are intended to examine infrastructure configuration, not the customer or end-user data processed by your applications.

Where technically possible, our collectors are designed to avoid retrieving the contents of databases, object storage, application payloads, secret values, credentials and private keys.

Credentials and secrets

InfraEdge does not intentionally collect or store your passwords, secret access keys, private keys or application secrets as assessment evidence.

Our preferred access model is temporary access through role assumption and least-privilege permissions rather than long-lived credentials.

Where remediation requires additional permissions, those permissions should be separately scoped to the agreed work.

If a credential or secret is accidentally included in information provided to us, please contact us so that it can be handled appropriately.

Repository access

Where repository access is required, we aim to access only the repositories and information necessary for the agreed engagement.

This may include infrastructure-as-code, CI/CD configuration, infrastructure documentation and relevant change history.

We do not intentionally collect unrelated application source code where it is not required for the service.

Where InfraEdge creates infrastructure changes, our preferred model is for those changes to be proposed through your existing version-control and review process. Your repositories remain under your control.

What we use information for

We may process information to:

  • respond to enquiries;
  • provide proposals and scope engagements;
  • deliver InfraEdge services;
  • perform infrastructure assessments;
  • produce findings and reports;
  • propose and verify remediation work;
  • provide ongoing infrastructure assurance;
  • maintain engagement records;
  • provide customer support;
  • maintain the security and integrity of our services;
  • meet legal, accounting and contractual obligations; and
  • improve our internal methodologies and tooling.

We do not use one customer’s confidential infrastructure information to expose or disclose that customer’s environment to another customer.

EdgeSignal

EdgeSignal may process infrastructure information relating to a company being assessed as part of technical diligence.

The scope of the assessment and the parties authorised to receive its outputs will be agreed as part of the engagement.

EdgeSignal reports may contain sensitive technical and operational information and are treated accordingly.

How we use customer information to improve InfraEdge

We may use general experience gained from engagements to improve our methodologies, controls, automation and reusable infrastructure patterns.

We will not intentionally use customer credentials, confidential architecture information, proprietary source code or identifiable customer data to create reusable public materials.

Where we use examples for demonstrations, testing or marketing, they should be synthetic or appropriately anonymised unless the customer has agreed otherwise.

Legal basis

Where UK data protection law applies, the legal basis on which we process personal data will depend on the circumstances. This may include processing that is necessary:

  • to perform a contract or take steps before entering into one;
  • for our legitimate interests in operating and securing InfraEdge and providing our services;
  • to comply with legal obligations; or
  • where appropriate, on the basis of your consent.

Where InfraEdge processes personal data on behalf of a customer as part of delivering a service, the respective responsibilities of the parties may also be addressed through the applicable commercial agreement or data processing agreement.

Sharing information

We do not sell personal data.

Two providers process information on our behalf for this website. Amazon Web Services hosts the site, runs the enquiry endpoint and sends enquiry email — S3, CloudFront, Lambda, API Gateway and SES, in eu-west-1 (Ireland) with static delivery from CloudFront edge locations. Titan hosts the mailbox that receives enquiries and carries ordinary correspondence. Other providers may be used for business administration, and any engagement-specific processing — where evidence is stored, which of your systems are in scope — is agreed in the engagement documents rather than here.

Those providers should receive only the information necessary to perform their function and process it subject to appropriate contractual and security arrangements.

We may also disclose information where required by law or where reasonably necessary to protect InfraEdge, our customers or others.

International transfers

Some technology providers used by InfraEdge may process information outside the United Kingdom.

Where personal data is transferred internationally, we will seek to use appropriate safeguards where required by applicable data protection law.

How long we keep information

We aim to retain information only for as long as it has a legitimate purpose. Different information may require different retention periods.

For customer engagements, retention may depend on the service provided, contractual requirements, security requirements and whether the information forms part of an agreed audit or assurance history.

Where practical, raw infrastructure evidence should be retained for a shorter period than the findings, decisions and audit records derived from it.

Specific retention arrangements may be agreed with customers as part of an engagement. The current retention table is on our security page.

Deleting engagement data

When an engagement ends, customer access should be removed in accordance with the agreed offboarding process.

Customers may also request deletion of eligible engagement information.

Some records may need to be retained where required for legal, accounting, security or contractual purposes.

Security

We apply technical and organisational measures intended to protect information handled by InfraEdge. Our approach includes principles such as least privilege, temporary access, separation of assessment and remediation permissions, encryption, auditability and minimal collection.

More detail about how InfraEdge approaches customer infrastructure access and evidence is on our security page.

Cookies and website analytics

InfraEdge may use cookies or similar technologies that are necessary for the operation and security of the website.

If we introduce optional analytics, advertising or other non-essential tracking technologies, we will update this notice and provide any choices or consent mechanisms required by applicable law.

We do not want the InfraEdge website to collect unnecessary information about visitors.

Your rights

Depending on where you live and the applicable law, you may have rights relating to your personal data, including the right to:

  • request access to information we hold about you;
  • ask us to correct inaccurate information;
  • request deletion in certain circumstances;
  • object to or restrict certain processing;
  • request transfer of certain information; and
  • withdraw consent where processing relies on consent.

You may contact us at support@infraedge.org to exercise an applicable right.

If UK data protection law applies, you may also have the right to complain to the UK Information Commissioner’s Office.

Changes to this notice

InfraEdge and our services will evolve, so we may update this privacy notice from time to time.

The latest version will be published on this page together with its last-updated date.

Contact

Questions about privacy or how InfraEdge handles information can be sent to support@infraedge.org.

Security-related enquiries should be directed to the contact listed on our security page.