Security & Privacy
How we handle data and what we commit to in an engagement.
Data handling in engagements
Where an engagement involves access to client data, the terms are agreed in writing before any data moves — what is shared, where it is held, how long it is retained, and what happens to it when the engagement ends. Specific controls are set per engagement rather than assumed, because requirements differ and a generic commitment is not a useful one.
Practices we apply
Least-privilege access. Encrypted transport for data in transit. Documented handling of any credentials or access granted for the duration of an engagement, and revocation on completion.
We do not hold certifications such as SOC 2 or ISO 27001. Where a client's assessment process requires evidence at that level, we will say so rather than imply otherwise.
Website privacy
We collect only the business contact details submitted through the contact form, and use them solely to respond to the enquiry. We do not sell personal data and do not use the information for unrelated marketing.
Terms
Engagements are governed by mutually executed statements of work and, where appropriate, a master services agreement.