Telha design partner programme is now open. Learn more →

Security and governance

Investigate without
creating God mode.

Sensitive evidence stays inside the customer environment and is released only through an approved, case-specific mandate.

Security-first. GDPR-first. Self-hosted.

Controlled by design

Defence in depth, drawn.

Four enforcement layers stand between an investigator and the evidence, and an audit spine records every action across all of them. An investigator cannot search the company because they hold a platform role.

Your environment · self-hosted
IdentityLayer 01
SSO / OIDCMFADeny-by-default roles
Mandate authorisationLayer 02
Documented purposeNamed approversExplicit scopeExpiry
Case workspaceLayer 03
Named team onlyAdmitted evidence onlyIn-boundary AI
Evidence vaultLayer 04
Field-level encryptionContent hashesVersioned custody
Audit spine · every action recorded
Never crosses the line No vendor access No external AI APIs No data egress

GDPR-first,
by architecture.

You stay the controller: Telha runs inside your environment, so there is no vendor processing and no data leaves your jurisdiction. The regulation's principles aren't a compliance layer; they are the platform's mechanics.

Art. 5 · Minimisation

Only the approved slice

Investigators see mandate-scoped data: named custodians, systems and dates. Never open search across the company.

Art. 5 · Purpose limitation

A documented purpose per case

Every mandate records why the data is processed and who approved it, before any access opens.

Art. 5 · Storage limitation

Access that expires

Cases end, and access ends with them, automatically, under retention and legal-hold rules you control.

Ch. V · Residency

Your region, your servers

Self-hosted deployment keeps evidence in your jurisdiction. Third-country transfer never enters the picture.

Art. 30 · Records

The audit spine is the record

Who accessed what, when, under which mandate, exportable as your record of processing for investigations.

Art. 15 · Access requests

DSAR-ready archive

Answer subject access requests from the same indexed, versioned memory, without a company-wide fire drill.

Security is part of the investigation model.

Not a separate settings page added after the workflow.

01

Case-scoped access

Investigators receive access to the approved case, not unrestricted discovery across the organisation.

02

Auditable change

Scope additions, extensions, approvals, evidence admission and revocation remain part of the record.

03

An append-only record

The record is a ledger, not a database: entries are added, never edited or deleted. Source identifiers, versions, timestamps, hashes and custody events travel with the evidence, so nothing can be quietly changed.

Identity

Enterprise authentication and role mapping.

  • SSO and OIDC integration
  • Deny-by-default role assignment
  • Named case membership
  • Time-limited authority
Data control

Designed for sensitive and regulated evidence.

  • Customer-controlled deployment
  • Field-level encryption
  • Retention and legal-hold controls
  • Verified backup and restore

The security posture, in one line

Field-level encryptionDeny-by-default accessTamper-evident custodyImmutable auditZero external callsCase-scoped AI

Security review

Map Telha to your control environment.

Review deployment, identity, evidence boundaries, retention and audit requirements with the team.