How we work
Security and compliance
Every entry below is either confirmed in writing or marked as unconfirmed. We do not display certification badges, and we will not state that we hold a certification until the certificate and its scope statement can be sent to you.
A supplier who overstates a certification in a procurement response creates a contractual and regulatory problem for the buyer as well as themselves. Ask us for the certificate; if there is not one, this page will say so.
Certification
Certification
- ISO 27001
- Information security management system
- Available on request during due diligence
- ISO 9001
- Quality management system
- Available on request during due diligence
- Cyber Essentials Plus
- UK government-backed technical controls scheme
- Available on request during due diligence
- SOC 2
- Type I or Type II service organisation report
- Available on request during due diligence
Insurance and continuity
Insurance and continuity
- Professional indemnity
- Cover level per claim and in aggregate
- Available on request during due diligence
- Public liability
- Cover level
- Available on request during due diligence
- Employer's liability
- Cover level
- Available on request during due diligence
- Source code escrow
- Provider and agreement type
- Available on request during due diligence
Data protection
Data protection
- UK GDPR position
- Controller/processor role, ICO registration, DPO or lead contact
- Available on request during due diligence
- EU GDPR position
- EU representative and lawful transfer mechanism
- Available on request during due diligence
- International transfers
- IDTA or UK Addendum plus Transfer Risk Assessment
- Available on request during due diligence
Sector-specific
Sector-specific
- HIPAA readiness
- Business associate agreement position
- Available on request during due diligence
- NHS DTAC
- Digital Technology Assessment Criteria completion
- Available on request during due diligence
- DCB0129 / DCB0160
- Clinical risk management standards for health IT
- Available on request during due diligence
- DSPT
- NHS Data Security and Protection Toolkit submission
- Available on request during due diligence
Engineering practice
Controls we apply on every engagement
Independently of certification status, the following apply to all delivery work: least-privilege access issued through your identity provider with multi-factor authentication; monthly access review and revocation within one business day of a person leaving a pod; mandatory peer review before merge; automated dependency and secret scanning in the pipeline; no production personal data in development or test environments; encryption in transit and at rest; and audit logging of privileged actions.
Penetration testing by an independent CREST-registered provider can be arranged before release and is priced as a line item rather than assumed. Findings are remediated and retested before go-live, and the report goes to you unedited.
Send us your security questionnaire.
We will complete it with evidence attached, and mark anything we cannot evidence as not held.
Talk to us