Mediation Hub

Security, support and data protection

Built to be trusted with the most sensitive information a family will share.

This page sets out, in plain terms, where your clients' information lives, who can see it, how it is protected, what support you get, and what happens if you ever leave. Where something is still being finalised, we say so rather than round it up.

Professional control

The mediator stays in control.

Nothing is issued without approval

Drafts, summaries and updates are prepared for the mediator to review, amend or reject. The mediator decides what is sent, and when.

Role-appropriate visibility

Parties, solicitors and referrers see only what the practice chooses to share with them about a case.

Judgement stays with the mediator

Mediation Hub does not provide legal advice, does not assess fairness or adequacy, and does not determine outcomes.

One record behind every output

Documents, claims and reports are assembled from information already recorded on the case, so the practice can trace where each figure came from.

Mediation Hub supports case administration and drafting. Professional judgement, review and approval always remain with the mediator.

Data protection

Your clients' data, on your instructions.

Who is responsible for what.

Your practice is the data controller for your clients' information. Mediation Hub processes it only on your documented instructions, as a processor under Article 28 of the UK GDPR. A data processing agreement is provided before you sign anything.

Where your data lives.

Hosted on Microsoft's cloud platform, with case data stored and processed in the UK or EEA.

Who else touches it.

A list of sub-processors, with what each one does and where it operates, is provided with the data processing agreement.

How long we keep it.

Case data is retained for as long as your practice instructs, and deleted on your instruction.

Your data is yours.

You can export your practice's data at any time, and in full when you leave.

Security

Specific commitments, not general reassurances.

Tested throughout.

Penetration tested throughout development and before launch, with findings fixed before release.

Encrypted throughout.

Data is encrypted in transit and at rest.

Access.

Role-based access enforced from day one, with multi-factor authentication for every user.

Audit trail.

Every action, drafted, edited, approved or issued, is logged against the user and the time, and can be exported.

Your clients' data does not train anyone's model.

Client data is contractually barred from training any public AI model. The processing that prepares drafts runs in a private environment in the UK or EEA.

Certification.

We are working towards Cyber Essentials Plus and ISO 27001 certification.

The FMSB guidance

The FMSB guidance on AI, point by point.

In February 2026 the Family Mediation Council published guidance for family mediators on the use of AI. It is written for mediators, not for software, and it asks six things of you. This is how Mediation Hub answers each.

Your judgement is always required.

Every draft, summary and record is prepared for you to review, amend or reject. Nothing is issued without your approval.

Verify outputs before use.

Every figure and statement in a draft shows where it came from in the case record.

Client consent to tools and data storage.

Onboarding includes a plain-language notice and consent step that you control.

Know where data is stored and who can see it.

Case data is stored and processed in the UK or EEA, and role-based access means each person sees only what their role allows.

Know whether your data trains the tool.

Client data is contractually barred from training any public AI model.

Test before you rely on it.

That is what the walkthrough is for.

Support

A named person, not a ticket queue.

A named contact.

Every practice has a named contact for onboarding and for questions after it.

Onboarding and training.

Set-up of your branding, users and templates, and training for mediators and administrators.

Response times.

Support hours, response times and the escalation route for anything affecting a live case are set out in the service level agreement you receive before you sign.

Changes and improvements.

Releases are announced in advance with notes on what has changed, and practices can request changes through their named contact.

Continuity

What happens if something goes wrong, or if you leave.

Backups and availability.

Backed up and monitored, with the availability and recovery commitments set out in the service level agreement.

If something goes wrong.

You are told without undue delay of any incident affecting your data, with what happened, what it affects and what we are doing about it, so that you can meet your own obligations. The process is automated so that nothing waits for someone to notice.

If you leave.

Full export on request and prompt deletion of your data, confirmed in writing.

Full security documentation and the data processing agreement are provided before you sign anything.