Security & trust

Policies

An information security management system that guides the way we work.

Information security

Our information security policy sets the direction for protecting information across the platform, consultancy and support. It defines management responsibilities and staff duties within our certified information security management system.

The policy is supported by procedures covering risk, access, assets, information handling, suppliers, incidents and continuity. Together they provide a consistent framework for how security decisions are made and reviewed.

  • Senior management approves the policy and sets responsibilities.
  • Staff confidentiality and policy-adherence duties support daily work.
  • Regular review helps keep requirements aligned with organisational changes.
Explore independent certification

Access management

Access-management procedures govern how people receive and retain access to organisational systems. Role requirements, joiner/leaver processes and authentication controls help ensure access follows a defined responsibility.

Within the product, library permissions and MFA provide controls your organisation can configure for its own teams. Review organisational and product access together when planning who will design, release and operate your services.

  • Assign access around the work a person needs to perform.
  • Review access when responsibilities or employment change.
  • Use library roles and MFA to support your own operating policy.
Explore product access controls

Remote working and devices

Remote-working and device procedures cover encryption, screen locking, secure connections, approved software and information handling. They set expectations for protecting organisational information wherever staff work.

The remote-working policy also requires secure device storage and limits how sensitive information is handled locally or transferred using removable media. Lost or compromised equipment follows the incident and recovery procedures.

  • Protect equipment with encryption and automatic screen locking.
  • Use protected Wi-Fi and the required secure connection arrangements.
  • Keep sensitive information in approved systems and report device concerns.
Explore endpoint safeguards

Incident management

Documented incident procedures guide reporting, severity assessment, escalation, containment, investigation and recovery. They provide clear ownership for coordinating the technical response and relevant communication.

Customer and regulatory notification requirements are considered within the incident process and applicable service arrangements. Recording incidents and follow-up actions helps improve controls after the immediate issue has been addressed.

  • A defined reporting route brings concerns to the response team.
  • Severity and affected information guide response priorities.
  • Recovery verification and follow-up reviews support accountable closure.
Explore the response process

Policy review

Policies are approved by senior management, made available to staff and reviewed through our management system. A review schedule and policy acknowledgements help turn documented requirements into consistent working expectations.

Reviews consider changes in the organisation, its services and the risks it faces. Training, internal assessment, incidents and continuity exercises can all inform updates to policies or the procedures that support them.

  • Named responsibilities support policy maintenance and review.
  • Staff access and acknowledgement support awareness of the requirements.
  • Corrective actions and changing risks feed into policy improvement.
Explore staff awareness and training
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.