Trust & compliance
Trust & compliance
Assurance you can check, not just claims you're asked to believe.
01 Approach
How we approach assurance
We work to the principles of the frameworks our clients are held to, and we design so those frameworks are easier to satisfy — because the evidence is generated by construction: version-controlled configuration, an auditable CMDB, explainable detection.
02 Frameworks we align to
Frameworks we align to and operate toward
01
ISO/IEC 27001
Information security management aligned to the standard’s controls.
02
Cyber Essentials Plus
Operating to the scheme’s technical controls.
03
NCSC Cyber Assessment Framework
Readiness and objective-based assurance for essential services.
04
NIS Regulations
Supporting operators of essential services and their obligations.
03 Government
Government engagements
- Clearance
- SC and DV-cleared personnel available for classified and sensitive work.
- Residency
- UK-based operations; data residency to your requirements.
- Procurement
- G-Cloud / Digital Marketplace: listing in progress.
04 Commitments
What we will never do
- Store your data outside the jurisdiction you require without your explicit decision.
- Hide how a control works behind “commercial confidentiality”.
- Lock you into a platform you cannot take in-house.