Skip to main content

Trust & security

How we look after your work.

A small firm with a serious posture: the practices we hold today and the marks we are earning, stated plainly. No badge appears on this site before it is real.

The practices

01

Boundaries before work

Scope and data boundaries are agreed before an engagement begins. What we may see, touch and keep is written down first.

02

Your tools, not ours

We work inside the tools your teams already run and your IT has already approved. We do not route your work through consumer AI accounts.

03

Nothing leaves without approval

Approval gates are built into every method we capture: supervised, never autonomous. A person signs off before anything ships.

04

Your data is not training data

We do not use your data to train models, and model access runs through business APIs, not consumer tools. Product data is protected in transit and at rest.

Certifications, honestly

Certification theatre helps nobody. Here is exactly where we are.

Cyber Essentials Planned

The UK government-backed baseline, certified through IASME. Registration is next on our list; this line will read "In progress" the day it is submitted, and "Held" when it is passed.

Cyber Essentials Plus Planned

The independently tested tier. We will take it once the baseline certificate is held.

ISO 27001 · SOC 2 Against demand

When an engagement requires it, we will certify. We would rather earn a badge for a client than for a brochure.

The detail

Full details of our infrastructure and subprocessors are shared during scoping, under NDA where needed. Product data handling is set out in our privacy policy.

Security questionnaires welcome. Your call is with a founder.