Information Security & Data Governance

A plain-English overview of how we protect our systems, your project and your data.

Last updated: 30 September 2026 — reviewed annually.

Overview

Security is part of how we build, not an add-on. This page summarises the internal controls we apply to our own systems and to client work. It is intended to answer the questions most commonly asked in supplier due-diligence questionnaires; if your assessment needs more detail, please contact us.

Access control

  • Multi-factor authentication is required on all business-critical accounts, including email, source control, hosting and administrative consoles.
  • Access follows least-privilege: each system and account has only the permissions needed for its role.
  • Accounts are individual and named — no shared logins.

Code and repositories

  • Client code lives in private repositories with access limited to those who need it.
  • Changes are committed with clear history; production deployments come from the main branch.
  • Dependencies are kept up to date and known-vulnerable packages are patched promptly.

Secure development

  • We build to mainstream web-security practice — input validation, output encoding, parameterised queries, CSRF protection, rate limiting and TLS everywhere.
  • Sites we ship are configured with sensible security headers and HTTPS enforced.
  • Third-party components are chosen conservatively and reviewed before adoption.

Data handling

  • We are registered with the Information Commissioner’s Office (ZB939242) and handle personal data in line with UK GDPR — see our privacy policy.
  • We collect and retain the minimum data needed to deliver the work, and we delete or return client data at the end of an engagement on request.
  • Backups and hosted data use reputable providers with encryption in transit and at rest.

Devices and working practices

  • Work devices run supported operating systems with full-disk encryption and prompt security updates.
  • We work from controlled environments — no client credentials on shared or public machines.

Assurance

Our controls are aligned with the five technical themes of the National Cyber Security Centre’s Cyber Essentials scheme — firewalls, secure configuration, access control, malware protection and patch management — applied proportionately to a small consultancy. If you need a completed Cyber Essentials questionnaire or a bespoke risk assessment for your procurement process, get in touch.

If you believe you have found a security issue in anything we operate, please see our vulnerability disclosure page.

Ready to talk about your project?

Tell Brad what you're building — you'll get a reply the same working day, plus a clear plan and a fixed quote in writing.