Security, reliability, and responsible AI - all in one place.

Breathe is ISO 27001 and ISO 42001 accredited, so you can have peace of mind that your data is safe and secure

GDPR-logo pci-dss-compliant stripe real-ex-payments ICO_Logo_Blue mark-of-trust-certified-ISOIEC-27001-information-security-management-black-logo-En-GB-1019_Breathe_Aug_2021

Data protection & server up-time are our top priorities

As a Breathe customer, you'll trust us to look after your employee data – a responsibility we take incredibly seriously.

This page explains the steps we take to protect your data, as well as how we ensure you have access to your data whenever and wherever you need it.

100% of Breathe users agree - Breathe’s security and data protection standards give us confidence in handling sensitive employee information. 

- Breathe HR 2025 customer survey. 

 

What is ISO 42001 and why does it matter?

ISO/IEC 42001:2023 is the world's first international standard dedicated to Artificial Intelligence Management Systems (AIMS). Published by the International Organization for Standardization (ISO), it provides a structured framework for how organisations develop, deploy, and govern AI responsibly - addressing everything from ethical considerations and transparency to risk management and ongoing accountability.

Unlike general data or security standards, ISO 42001 is built specifically for the age of AI. It helps organisations prove, not just promise that their use of AI is fair, safe, and well-managed.

Why is ISO 42001 important for tech companies?

AI is being embedded into software products at pace, and with that comes real responsibility. ISO 42001 accreditation matters for tech companies for three core reasons:

  • Trust: It signals to customers, regulators, and partners that AI is being used responsibly, backed by independent, third-party validation, not just internal policy documents.

  • Risk reduction: The standard requires organisations to identify, assess, and control AI-related risks throughout the full lifecycle of any AI system — from design to deployment.

  • Future-readiness: With frameworks like the EU AI Act shaping global regulation, ISO 42001 positions certified companies ahead of the curve rather than scrambling to comply after the fact.

For businesses choosing HR software, it means you can trust that any AI-powered features in Breathe - whether those are analytics, automation, or intelligent workflows - are governed by a certified, independently audited standard.

Breathe's ISO 42001 accreditation

We're delighted to have been awarded ISO 42001 accreditation, making Breathe one of a small number of HR software providers to hold this certification. This builds directly on our existing ISO 27001 information security certification, reinforcing our commitment to keeping your people's data safe, your systems reliable, and our use of technology ethical and transparent.

Breathe is ISO 42001 and ISO 27001 certified - independently audited and rigorously maintained.

MFP-Breathe-181012-0280-full-min

Who are Breathe?

Breathe is the trading name of Centurion Management Systems Ltd, a UK-based company that has been designing and implementing HR systems for over 21 years.

Read more about us here.

Server width=

Uptime and performance

We know how important it is for you to have access to your HR systems whenever and wherever you need them. That’s why our servers are configured to provide an exceptionally high level of reliability.

Visit status.breathehr.com to see the live status of our servers at any time.

Locked width=

Credit card details

We don't hold or process any credit card information on our servers.

From the very moment you enter your card details, they’re managed and protected by the most trusted credit card processors in the industry: Stripe and Global Payments

Case width=

T&Cs

All Breathe accounts operate under the same terms and conditions.

We hate boring legal stuff, but it’s important you know how we operate. Read full T&Cs

Two-factor authentication (2FA)

Add an extra layer of security to yours and your team's Breathe accounts with our two-factor authentication (2FA) feature.

Choose who you'd like to switch 2FA on for - whether that's just your HR users, line managers or everyone. They'll then need to provide a code - as well as their password - each time they log in. 

Laptop showing Breathe's login screen interface with a pop up showing a 2FA code from Google Authenticator app

Frequently asked questions

Who owns Breathe?

Where is my data held with Breathe?

How secure is my data with Breathe?

How is my Breathe account backed up?

How do I import my data into Breathe?

Can I export my data from Breathe if I decide to leave?

Does Breathe offer two-factor authentication?

Is Breathe ISO 42001 certified?

Join over 17,000 SMEs that choose Breathe as their #1 HR software provider

Group 29 Group 29 (1)