Trust & security
We ask clients to hold themselves to a high bar, so here is how we hold ourselves to one.
We run the controls we advise on
Our own environment is managed to the standards we help clients meet — access control, MFA everywhere, least privilege, logging and review.
Client data handling
Client information is processed only for the engagement, under NDA and a data processing addendum, with defined retention and secure deletion at the end.
Engagement security
Findings and evidence are handled as confidential, shared through controlled channels, and destroyed or returned on request.
Our certifications & reports
We can share our current security posture documentation, including our approach to the controls above and any third-party attestations we hold, under NDA on request.
Request security documentationReport a vulnerability
If you believe you have found a security issue in this website or our systems, email [email protected] with the subject “Security disclosure”. We will acknowledge within two business days.
Want to see how we'd approach your environment?
A 30-minute call with a security architect to map where you are against the framework you need and agree the next step. No obligation, no sales sequence.
