Skip to main content

Trust & security

How we look after your work.

A small firm with a serious posture: what operates today, what remains gated and which external marks we have not yet earned. No badge appears on this site before it is real.

The practices

01

Boundaries before work

Scope and data boundaries are agreed before an engagement begins. What we may see, touch and keep is written down first.

02

Approved tools only

We agree the approved tools and provider routes for each engagement before client material is processed. A planned integration is never treated as permission.

03

People keep authority

Capture, sharing and consequential actions require visible human authority. CURN does not silently turn observed work into a shared method or autonomous action.

04

Your data is not training data

We do not use client material to train models. A remote model route stays off until its purpose, provider, region, retention and contractual controls are approved.

Compliance and assurance status

Legal duties, internal preparation and independent examinations are different things. Here is exactly where we are.

UK GDPR · Data Protection Act 2018 Programme active

Data protection is an operating obligation, not a badge. Our current data flows are being documented, and real employee or workflow-data pilots remain gated behind an approved DPIA, written processing terms, and tested retention and deletion controls. No independent GDPR certification is claimed.

Cyber Essentials Preparing

Not yet certified. We are preparing against the current scheme requirements and will show the certificate number, scope and dates only after it is awarded.

Cyber Essentials Plus Planned

The independently tested tier. We will scope it after the baseline certificate if customer need or risk justifies the additional assurance.

SOC 2 Not audited

No SOC 2 report has been issued. We will begin readiness when the production service boundary is stable and customer need justifies a formal independent CPA examination.

ISO 27001 Not certified

We will scope certification once the production boundary and information-security management system are stable enough for the result to be meaningful.

The detail

Our privacy policy describes the principal current website and business providers and recipients. Product and engagement subprocessors are fixed in the written scope before relevant client material is processed. We can discuss current controls, evidence and open gaps during diligence.

Ask us anything about this

Security questionnaires welcome. You’ll speak directly with the people who can answer them.

30-minute conversation

Choose a time that works.

Tuesdays to Thursdays, UK time.