Security and trust

Built to be trusted with public-sector work.

You are accountable for what happens on your network. The system you use for it has to be able to show what it did.

The basics, done properly.

Named accounts

Everyone signs in as themselves, through your own identity provider where you have one. No shared logins.

Least privilege

People see what their role needs and nothing more. Access is granted and removed by your administrators.

Encrypted throughout

Data is encrypted in transit and at rest, on managed cloud infrastructure with backups.

If it cannot be shown, it did not happen.

Accountability is the point.

A record nobody can vouch for is not a record.

  • Consequential actions are attributed to the person who took them.
  • The account of a movement is written as the work happens, not reconstructed afterwards.
  • Records are kept for as long as your retention policy says, and no longer.
  • Your data is yours. You can get it out, in full, whenever you ask.

We will meet your assurance process.

Send us your security questionnaire, your DPIA template, or your supplier assessment. We would rather answer it early than at contract stage. Ask and we will send what we hold.

Ask us the difficult questions.

We would rather have that conversation first.