Compliance and frameworks
Compliance
The certifications and frameworks we measure ourselves against, and our current position for each.
ISO 27001 certification in progress
01Our information security management system is operating and documented. Policies, controls and supporting evidence are available under NDA.
GDPR and UK GDPR aligned data handling
02Lawful-basis mapping, records of processing activity and a Data Processing Agreement are available for customers.
Testing aligned to OWASP ASVS, MITRE ATT&CK and CREST
03Our methodology and reporting map to recognised industry standards so findings can support customer assurance processes.
Independent third-party penetration testing
04Our platform security testing programme includes independent assessment alongside continuous internal testing.
Cyber Essentials Plus controls maintained
05Baseline technical security controls are implemented and monitored across the organisation.
SOC 2 readiness assessment underway
06Control mapping towards a future SOC 2 Type II report is in progress alongside our ISO 27001 programme.