Readiness posture, not a certification claim
How we secure your information
We operate a documented control set aligned to SOC 2 trust services criteria, ISO 27001 Annex A, and the NIST SP 800-171 practices that CMMC Level 2 assesses. We hold no SOC 2 report and no CMMC certification, because those come from an independent auditor or an authorised assessor. What we do hold is a register of controls, named owners, and dated evidence, which we review every quarter and will walk a client or their auditor through on request.
What we do and do not claim
- We operate a documented control set aligned to the SOC 2 trust services criteria, ISO 27001 Annex A, the NIST SP 800-171 practices that CMMC Level 2 assesses, and GDPR accountability requirements.
- We do not hold a SOC 2 Type 1 or Type 2 report, and we are not CMMC certified or ISO 27001 certified. Those come from an independent auditor or an authorised assessor, and we will never imply otherwise on this website or in a proposal.
- Every control below has a named owner, a defined procedure, and dated evidence we will walk you or your auditor through on request.
The controls we operate
22 controls are operating today, 4 are being strengthened, and 1 are planned for the point a contract requires them. Our full internal register covers 27 controls, and the ones relevant to a client engagement are listed here.
- GOV-01Operating
Leadership sets the security direction and holds someone accountable for it.
The CEO holds accountability for security. The compliance lane owns this register and reports it at the quarterly management review.
- Evidence available
- Quarterly management review record with the register attached.
- Framework references
- SOC 2 CC1.1, ISO 27001 A.5.1, CMMC CA.L2
- ACC-01Operating
Access is granted on least privilege and approved before it exists.
Every account, ours or in a client environment, is requested and approved on the access form, granted at the lowest level that works, and recorded with a removal date where it is time boxed.
- Evidence available
- Access register with approvals, grant dates, and removal confirmations.
- Framework references
- SOC 2 CC6.1, ISO 27001 A.5.15, CMMC AC.L2
- ACC-02Operating
Strong authentication protects every account.
Multi factor authentication is enforced on all company accounts and on every client system where the client permits it. Exceptions are recorded with a reason and a date.
- Evidence available
- Authentication policy enforcement report and the exception list.
- Framework references
- SOC 2 CC6.1, ISO 27001 A.8.5, CMMC IA.L2
- ACC-03Operating
Access is reviewed periodically and removed promptly when it is no longer needed.
We review access to our own systems quarterly, and we remove client access at engagement close and on the day a team member departs, with timestamps recorded.
- Evidence available
- Quarterly access review records and dated exit records.
- Framework references
- SOC 2 CC6.2, ISO 27001 A.5.18, CMMC AC.L2
- DAT-01Operating
Client information is protected in transit and at rest and kept separated by client.
Client material lives only in the approved store, in a folder restricted to assigned staff, with named expiring shares. Confidential and restricted material never travels as an email attachment.
- Evidence available
- Store configuration record, share settings, and the engagement folder access list.
- Framework references
- SOC 2 CC6.7, ISO 27001 A.8.12, CMMC MP.L2
- DAT-02Operating
Information is retained only as long as needed, then returned or destroyed.
Retention is agreed at kickoff, applied at close out, and evidenced by a destruction or return record verified by a second person.
- Evidence available
- Data return and destruction records, kept for seven years.
- Framework references
- SOC 2 CC6.5, ISO 27001 A.8.10, CMMC MP.L2
- DAT-03Operating
Personal data processing is recorded, lawful, and assessed where it is high risk.
We maintain our own processing record, screen new processing activities before they go live, and run a full impact assessment when screening calls for one.
- Evidence available
- Processing record and dated screening decisions, including the not required ones.
- Framework references
- SOC 2 P1, GDPR Article 30, ISO 27001 A.5.34
- VUL-01Operating
Weaknesses are found and fixed within a defined timescale.
Our own platform and dependencies are scanned, findings are triaged by exposure, and closure requires a clean re-scan rather than a statement that it is fixed.
- Evidence available
- Scan records, remediation dates, and verification re-scans.
- Framework references
- SOC 2 CC7.1, ISO 27001 A.8.8, CMMC RA.L2, CMMC SI.L2
- IRP-01Operating
Incidents are detected, recorded, escalated, and learned from.
We run the same incident procedure internally that we run for clients: a timestamped record from the first minute, a named lead, and a lessons review within ten working days.
- Evidence available
- Incident records with timelines, and lessons reviews with owned actions.
- Framework references
- SOC 2 CC7.3, ISO 27001 A.5.24, CMMC IR.L2
- BRE-01Operating
Notification obligations are met within the applicable deadline.
A regime matrix drives who must be told and by when. The clock starts at awareness and is recorded to the hour. A decision not to notify is documented with the reason.
- Evidence available
- Obligation assessments and a submission log with timestamps.
- Framework references
- GDPR Article 33, SOC 2 CC2.3, State breach laws
- AUT-01Operating
Testing activity is authorised in writing before it happens.
No scanning, enumeration, or exploitation happens without a signed authorisation letter, signed rules of engagement, and a completed go or no go checklist on the morning of testing.
- Evidence available
- Signed authorisation file and completed go or no go checklists.
- Framework references
- ISO 27001 A.5.31, Computer misuse and equivalent laws
- AUT-02Operating
Test findings and evidence are held securely and minimally.
Findings and captured evidence live in the restricted findings store only, with the minimum data needed, personal data redacted, and no live customer records copied out.
- Evidence available
- Store access list and the evidence handling note on each finding record.
- Framework references
- SOC 2 CC6.7, ISO 27001 A.8.12
- BD-01Operating
Statements made to buyers are accurate.
Every company fact, code, certification, and past performance item in a proposal comes from the company facts register. Nothing is written from memory, and anything we do not hold is raised rather than filled in.
- Evidence available
- Company facts register, compliance checklists, and submission records.
- Framework references
- FAR representations, SOC 2 CC1.1
- CLI-01Operating
Clients receive accurate, timely information about the service they buy.
Each client has a portal holding their pack, their briefings, and the security commitments that apply to them, plus a weekly status report during active delivery.
- Evidence available
- Portal records and filed status reports.
- Framework references
- SOC 2 CC2.3, ISO 27001 A.5.14
- CLI-02Operating
Service quality is measured and complaints are acted on.
Satisfaction surveys run at close out and at each quarterly review. Scores below the threshold get contact from the engagement lead within two business days and a written corrective action.
- Evidence available
- Survey records with corrective actions and closure dates.
- Framework references
- SOC 2 CC4.2, ISO 27001 Clause 9.1
- PUB-01Operating
Public claims about the organisation are accurate and supportable.
The quarterly internal review checks every public claim on the website against this register. Where they disagree, the website wording is corrected the same day. We never state or imply a certification we do not hold.
- Evidence available
- Quarterly review record noting the website check and any corrections made.
- Framework references
- SOC 2 CC2.3, FTC advertising standards
- PUB-02Operating
Client confidentiality is preserved in all marketing and reference material.
Testimonials and case studies are anonymised by role, organisation type, size, and region. A client is named only with separate written permission.
- Evidence available
- Anonymised content on the public site and permission records where a client is named.
- Framework references
- SOC 2 CC2.3, Client confidentiality terms
Where we stand on each framework
Each page below sets out the scope, what we can evidence today, the open gaps, and the planned work. We publish the gaps as well as the strengths, because a buyer finding them later is worse for both of us.
Answering your vendor diligence
Client security questionnaires and vendor diligence requests are answered from this register only. Nobody answers a diligence question from memory. If you send a security questionnaire, we complete it from this register, mark anything we do not hold as not held rather than leaving it blank, and return it with the supporting evidence attached. Review cadence: Every quarter, with three controls tested in depth each cycle so every control is tested at least once a year.
Ask us for the evidence
We will walk your security or procurement team through the register, the controls that apply to your engagement, and the evidence behind them before you sign anything.