Trust Centre · Live

Trust is engineered.
Transparency is earned.

One source of truth for how GYM protects customer information, supports advisers and satisfies partner compliance. Every policy is versioned, owned and published.

0
Governance documents
UK / EU
Data residency
Jul 2026
Last reviewed
ICO RegisteredUK GDPR alignedFCA-aware designResponsible AIVulnerability disclosureDPA available
Product Trust

Trust is part of how GYM evolves

Building trust isn't a one-time exercise. These are the always-on product commitments that shape every release.

Customer Privacy
Active
AI Governance
Active
Security
Operational
Accessibility
Continuously Improving
Customer Consent
Required
Platform Governance
Reviewed
Security

Defence in depth

Every layer is designed with the assumption that the previous one could fail.

Encryption

TLS in transit. At-rest encryption for databases, backups and object storage — with keys managed by our cloud KMS.

Full detail lives in the Information Security Policy.
Compliance

One framework. Four commitments.

Privacy, AI, financial services and partner obligations — held to the same standard.

Your data, your control

GYM acts as controller for personal information customers provide directly and processes it only to deliver the Mortgage Fitness service. UK GDPR rights — access, rectification, erasure, portability — are actioned within statutory timeframes.

  • Explicit, granular consent — no bundled or pre-ticked boxes
  • UK/EU residency. No routine transfers outside adequacy regions
  • Retention aligned to FCA record-keeping; nothing kept 'just in case'
  • Deletion via privacy@ or account settings — confirmed on completion
Documents

Every governance document, always current

One list. Version-controlled, owned by name, reviewed on cadence. This is the only place documents live.

Activity

What we've shipped — and what's next

A single, honest record. Nothing that hasn't happened appears here as complete.

  1. July 2026Releasev1.0

    Trust Centre launched

    Public Trust Centre goes live with the full governance pack, security documentation and compliance FAQ.

  2. July 2026Policyv1.0

    Responsible AI Principles published

    First public version of GYM's AI governance framework — what our AI does, and what it will never do.

  3. July 2026Policyv1.0

    Information Security Policy published

    Full detail on encryption, access, audit and infrastructure controls.

  4. July 2026Policyv1.0

    Vulnerability Disclosure Policy published

    How to report a security issue responsibly and what to expect from us in return.

  5. NextRoadmap

    Multi-factor authentication rollout

    Enforced MFA for broker and internal accounts, followed by customer opt-in.

  6. NextRoadmap

    Independent penetration testing

    Annual third-party assessment with findings tracked publicly at a summary level.

  7. NextRoadmap

    Public status page

    Real-time availability and incident history for the GYM platform.

Enterprise Due Diligence

Need the full governance pack?

Security overview, DPA, subprocessor list, AI governance and the partner compliance guide — collated and shared under NDA during commercial conversations.

Request Governance Pack
Target response · 2 business days
Compliance FAQ

Answers for compliance and procurement teams

The questions we hear most from lender risk teams, network compliance and enterprise procurement.

Consent is explicit and granular. Customers see who they're being introduced to and exactly what data will be shared before confirming. Every consent event is timestamped, versioned against the consent wording, and available for audit.
Letter from the Founder
"Trust isn't something you claim. It's something you earn every day. Every decision at GYM starts with one question: does this genuinely improve the customer experience while protecting customer information? If the answer is no, we don't build it."
Lee Brewer, founder of Getting Your Mortgage
Lee Brewer
Founder
Talk to us

Questions about trust, privacy or compliance?

Customers, advisers, compliance teams and investors are all welcome to get in touch — we'll route you to the right team.

Ready for compliance, procurement and investor conversations

Company details: Getting Your Mortgage Ltd. Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom. ICO registration: ZC177396.

Regulatory status: GYM provides Mortgage Fitness guidance only and is not itself authorised by the Financial Conduct Authority to give regulated mortgage advice. Any regulated mortgage advice is provided by FCA-authorised advisers we introduce you to, after a full fact-find. The Mortgage Fitness Score is for guidance only and is not a mortgage offer, decision in principle or guarantee of approval.

Your home may be repossessed if you do not keep up repayments on your mortgage.

Think carefully before securing other debts against your home. Buy-to-let mortgages and some forms of commercial or overseas lending are not regulated by the Financial Conduct Authority.

© 2026 Getting Your Mortgage Ltd. All rights reserved.

Follow GYM