Trust infrastructure has to earn trust first.
From the contracting entity to responsible disclosure.
Each layer has public evidence on this page or controlled evidence in the security & procurement pack.
- L1Legal entity & contracting
- L2ISO management systems
- L3Secure engineering
- L4Privacy / data protection
- L5Hosting / residency
- L6Platform release lifecycle
- L7Service operations / BCDR
- L8Responsible disclosure
ISO management systems.
ISO/IEC 27001
Information security management
Current certificate and scope are provided in the security & procurement pack.
ISO/IEC 27701
Privacy information management
Current certificate and scope are provided in the security & procurement pack.
ISO 9001
Quality management
Current certificate and scope are provided in the security & procurement pack.
Privacy controls are designed per programme.
- 01
Purpose
- 02
Minimum data
- 03
Lawful basis
- 04
Access
- 05
Residency
- 06
Retention
- 07
Deletion
- 08
Evidence
Hosting and residency
Available hosting patterns are agreed per programme. Residency must match the architecture and the contract — it is never a universal promise.
Secure engineering
Secure engineering practices are documented in the security & procurement pack.
A maintained product with controlled releases.
Request the security & procurement pack.
A controlled request path for questionnaires, policies and supporting evidence. A named security or procurement contact follows up.
Responsible disclosure
To report a potential vulnerability, use the responsible disclosure route rather than a sales form.
Request received.