Security-first, in writing.
How we handle your data, govern AI safely, and behave when something goes wrong — published openly, because regulated buyers should not have to ask.
Home » Security
Data protection
UK GDPR from day one — DPAs before any data is touched, minimum-necessary access, UK/EU residency.
AI governance
Your data never trains anyone’s AI — human checkpoints, audit trails, guardrails per agent.
Engineering practice
Encryption, role-based access, monitoring, rollback and tested backups — shipped with every build.
When something goes wrong
Plain-English post-mortems, UK GDPR timescales — and you hear it from us first.
Four layers on every engagement — the detail behind each is below.
Data protection
- All work is conducted under UK GDPR, with a data-processing agreement in place before any client data is touched.
- Minimum-necessary access: we ask for the narrowest access that lets the work proceed, and we log what we access.
- Data residency: UK/EU regions wherever possible, always disclosed, and agreed in scoping — never discovered afterwards.
- NDAs signed routinely — before the first detailed conversation if you prefer.
AI governance
- Your data does not train anyone’s AI. We configure services so client data is excluded from provider training, and we put that commitment in writing.
- Human checkpoints: we do not put unreviewed AI decisions into business-critical paths. Confidence thresholds, review queues and fallbacks are standard.
- Audit trails: every automated action is logged, so you can always answer “what did the system do, and why?”
- Guardrails per agent: what an assistant may answer, must escalate, and may never touch is agreed before go-live — and enforced technically, not just by policy.
Engineering practice
- Encryption in transit and at rest; role-based access control; secrets managed properly, never in code.
- Monitoring, alerting and rollback ship with every build.
- Backups with tested restores and agreed recovery targets.
- Regulated-sector safeguards — healthcare data caution, professional privilege awareness — are scoped explicitly in the assessment.
When something goes wrong
Incidents get a plain-English post-mortem: what happened, what we did, what changed. You hear it from us first. Anything reportable is handled within UK GDPR timescales, in coordination with your data-protection lead.
Formal certifications (e.g. Cyber Essentials) will be listed here once attained — we will not claim badges we do not hold.
Have a compliance question we haven’t answered?
Ask it before any commercial conversation — that is the right order.