Security
Security Your Regulator Can Sign Off
Certified for Government Scale
Posts are critical national infrastructure, and we are held to that standard. Escher meets the certification, sovereignty and audit requirements of government procurement across the UK, EU and US, and evidences them in every tender.

Claims Without Evidence
Government procurement does not take security on trust. A Post must show how citizen data is protected, where it is held, who can reach it, and what happened at any counter on a given day. Adjectives do not pass that test.
As NIS2 designates postal operators as essential entities, the burden rises again: supply-chain transparency, breach-notification windows and audit rights that must be evidenced on demand, not asserted.

Evidence, Not Adjectives
Escher meets the standard because we can show it: named certifications with certificate numbers, a disclosed sub-processor list, data that stays in the jurisdiction your law requires, and transaction journals that reconstruct any event years after it happened.
Certified, Audited, Current
ISO 27001 with cloud and privacy extensions, Cyber Essentials Plus, SOC 2 Type II, PCI DSS v4 and ISO 22301, with certificate numbers, scopes and expiry dates in the Security Pack.
Data Where Your Law Requires
In-country and sovereign cloud deployment on AWS, Azure, private cloud or on-premise, with a disclosed sub-processor list and lawful transfer mechanisms wherever data crosses a border.
Evidential-Grade Auditability
Immutable transaction journals, complete audit trails and reconciliation by design, so when a regulator or official asks what happened at a counter, the platform answers with evidence, not estimates.

Escher runs the critical retail and delivery infrastructure of more than half of the world’s top 20 Posts, under the security scrutiny public operators face. Integrity is our first non-functional requirement, and our controls are independently assessed and refreshed every year.

Privacy, AI & Continuity
Privacy: GDPR-aligned processing with data minimisation, retention controls and a Data Privacy Impact Assessment for every deployment.
AI Governance: Your data never trains shared models, every AI component is disclosed, and all align with the EU AI Act.
Continuity: ISO 22301-aligned recovery objectives, geographically separated disaster recovery, and offline branch operation with automatic reconciliation.
Get the latest news direct to your mailbox.

