Security-first, in writing.

How we handle your data, govern AI safely, and behave when something goes wrong — published openly, because regulated buyers should not have to ask.

Data protection

UK GDPR from day one — DPAs before any data is touched, minimum-necessary access, UK/EU residency.

AI governance

Your data never trains anyone’s AI — human checkpoints, audit trails, guardrails per agent.

Engineering practice

Encryption, role-based access, monitoring, rollback and tested backups — shipped with every build.

When something goes wrong

Plain-English post-mortems, UK GDPR timescales — and you hear it from us first.

Four layers on every engagement — the detail behind each is below.

Data protection

AI governance

Engineering practice

When something goes wrong

Incidents get a plain-English post-mortem: what happened, what we did, what changed. You hear it from us first. Anything reportable is handled within UK GDPR timescales, in coordination with your data-protection lead.

Formal certifications (e.g. Cyber Essentials) will be listed here once attained — we will not claim badges we do not hold.

Have a compliance question we haven’t answered?

Ask it before any commercial conversation — that is the right order.