

Posts are critical national infrastructure. They carry a country’s mail, its payments and its identity documents, and they answer to regulators, auditors and the public. Escher is held to that same standard. This page sets out how we protect the security, privacy and integrity of every operation that runs on our platform.
Four commitments, one standard.
Security
We protect postal operations and the data inside them across the whole lifecycle, from secure development to round-the-clock monitoring.
Privacy
We handle personal data lawfully and sparingly, by design, in line with the GDPR and the privacy laws of the markets we serve.
Environment
We manage our own impact to ISO 14001, and our platform helps Posts cut waste, failed deliveries and unnecessary miles.
Quality
We run a certified quality management system and a gated delivery lifecycle, refined over three decades of postal deployments.
Security your regulator can sign off.
Escher meets the security requirements of government postal procurement in the UK, EU and US, and proves it in every tender we win. Our information security management system is certified to ISO 27001. Beyond the certificate, security runs through how we build and operate.
Build
A secure development lifecycle, dependency scanning and independent penetration testing before every major release.
Run
Least privilege and segregation of duties, continuous vulnerability management, and round-the-clock monitoring with defined breach-notification windows.
Assure
Customer audit rights, independent assessments, and alignment with recognised national security frameworks.
At the core of the platform sits a journalled transaction engine: every counter and network event is written to an immutable record and replicated across the estate, so branches keep trading through outages and any transaction can be reconstructed and evidenced years later.
Privacy by design, not by disclaimer.
Citizens trust the Post with their identity, their money and their mail, and we are built to keep it that way. Escher processes personal data in line with the GDPR and the data-protection laws of the markets our customers operate in, on three principles.
- Minimise — we collect and retain only the data an operation genuinely needs.
- Localise — data residency and sovereign deployment options keep data where a customer’s law requires it, with lawful transfer mechanisms wherever it crosses a border.
- Disclose — a documented sub-processor list and a Data Privacy Impact Assessment for every deployment, so our customers can evidence their own compliance.
A lighter footprint, ours and yours.
We manage our environmental impact through a management system certified to ISO 14001. The larger contribution is in the platform itself. Postal operations are among the most carbon-intensive parts of the supply chain, and software that takes waste out of them matters more than office recycling.
- Fewer failed deliveries — delivery-experience and first-time-success tools cut repeat attempts, and every repeat attempt is a wasted journey.
- Fewer miles — route optimisation and walk sequencing shorten rounds and reduce fuel burn across the last mile.
- Less paper and hardware waste — digital counter, kiosk and self-service channels reduce printed forms, and a hardware-agnostic platform lets Posts keep the estate they already own rather than replacing it.
Quality proven over three decades.
Escher has built postal software since 1993 and today runs more than half of the world’s top 20 Posts. That record rests on a quality management system certified to ISO 9001 and a delivery lifecycle your PMO will recognise: discovery, solution design, build and integration, testing, pilot and national rollout, gated at every stage. Availability and performance are committed in service-level agreements and measured, not asserted.
Certified, and happy to prove it.
We publish only the certifications we currently hold. Certificate numbers, scopes and expiry dates are available in the Security Pack, because a claim without a certificate number is just marketing.
- ISO 27001 — Information security management
- ISO 9001 — Quality management
- ISO 14001 — Environmental management
- ISO 27701 — Privacy Information Management Systems (PIMS)
- UK Cyber Essentials
- UK Cyber Essentials Plus
Evidence, not adjectives.
Serious buyers do not take security on trust; they audit it. The Escher Security Pack gathers certificate details, sub-processor lists, an architecture security overview and our standard responses to government security questionnaires, so your teams can assess us properly.
Related Articles
Get the latest news direct to your mailbox.


