Encryption
TLS in transit. At-rest encryption for databases, backups and object storage — with keys managed by our cloud KMS.
One source of truth for how GYM protects customer information, supports advisers and satisfies partner compliance. Every policy is versioned, owned and published.
Building trust isn't a one-time exercise. These are the always-on product commitments that shape every release.
Every layer is designed with the assumption that the previous one could fail.
TLS in transit. At-rest encryption for databases, backups and object storage — with keys managed by our cloud KMS.
Privacy, AI, financial services and partner obligations — held to the same standard.
GYM acts as controller for personal information customers provide directly and processes it only to deliver the Mortgage Fitness service. UK GDPR rights — access, rectification, erasure, portability — are actioned within statutory timeframes.
One list. Version-controlled, owned by name, reviewed on cadence. This is the only place documents live.
How we collect, use and protect personal data.
Cookies, analytics and your choices.
The terms that govern use of GYM.
Our commitment to inclusive design and continuous accessibility improvement.
The principles that guide how AI is designed, used and governed at GYM.
How to responsibly report a security issue to GYM.
Technical and organisational security measures.
How GYM and its partners handle personal data — roles, safeguards and responsibilities in plain English.
Everything a partner compliance team needs, in one pack.
A single, honest record. Nothing that hasn't happened appears here as complete.
Public Trust Centre goes live with the full governance pack, security documentation and compliance FAQ.
First public version of GYM's AI governance framework — what our AI does, and what it will never do.
Full detail on encryption, access, audit and infrastructure controls.
How to report a security issue responsibly and what to expect from us in return.
Enforced MFA for broker and internal accounts, followed by customer opt-in.
Annual third-party assessment with findings tracked publicly at a summary level.
Real-time availability and incident history for the GYM platform.
Security overview, DPA, subprocessor list, AI governance and the partner compliance guide — collated and shared under NDA during commercial conversations.
The questions we hear most from lender risk teams, network compliance and enterprise procurement.
Three inboxes. Each monitored by the team best placed to help.
Subject Access Requests, data deletion and privacy questions.
Partner and procurement enquiries — questionnaires, DPAs, due diligence.
Responsible disclosure of vulnerabilities and security concerns.
"Trust isn't something you claim. It's something you earn every day. Every decision at GYM starts with one question: does this genuinely improve the customer experience while protecting customer information? If the answer is no, we don't build it."
Customers, advisers, compliance teams and investors are all welcome to get in touch — we'll route you to the right team.