Last updated: 30 September 2026 — reviewed annually.
Overview
Security is part of how we build, not an add-on. This page summarises the internal controls we apply to our own systems and to client work. It is intended to answer the questions most commonly asked in supplier due-diligence questionnaires; if your assessment needs more detail, please contact us.
Access control
- Multi-factor authentication is required on all business-critical accounts, including email, source control, hosting and administrative consoles.
- Access follows least-privilege: each system and account has only the permissions needed for its role.
- Accounts are individual and named — no shared logins.
Code and repositories
- Client code lives in private repositories with access limited to those who need it.
- Changes are committed with clear history; production deployments come from the main branch.
- Dependencies are kept up to date and known-vulnerable packages are patched promptly.
Secure development
- We build to mainstream web-security practice — input validation, output encoding, parameterised queries, CSRF protection, rate limiting and TLS everywhere.
- Sites we ship are configured with sensible security headers and HTTPS enforced.
- Third-party components are chosen conservatively and reviewed before adoption.
Data handling
- We are registered with the Information Commissioner’s Office (ZB939242) and handle personal data in line with UK GDPR — see our privacy policy.
- We collect and retain the minimum data needed to deliver the work, and we delete or return client data at the end of an engagement on request.
- Backups and hosted data use reputable providers with encryption in transit and at rest.
Devices and working practices
- Work devices run supported operating systems with full-disk encryption and prompt security updates.
- We work from controlled environments — no client credentials on shared or public machines.
Assurance
Our controls are aligned with the five technical themes of the National Cyber Security Centre’s Cyber Essentials scheme — firewalls, secure configuration, access control, malware protection and patch management — applied proportionately to a small consultancy. If you need a completed Cyber Essentials questionnaire or a bespoke risk assessment for your procurement process, get in touch.
If you believe you have found a security issue in anything we operate, please see our vulnerability disclosure page.
