1. Cyber Essentials
- Scheme: Cyber Essentials, certified by The IASME Consortium Ltd
- Scope: Whole organisation
- Certified: September 2026
- Valid until: September 2027 (renewed annually)
Cyber Essentials covers five technical controls: firewalls, secure configuration, user access control, malware protection and security update management. A copy of our certificate is available on request.
2. Accounts and Access
- Multi-factor authentication (MFA) is enabled on every business and cloud service we use.
- Everyone has their own named account. Shared logins are not permitted.
- Access follows least privilege: people get only the systems their role needs.
- Administrator accounts are separate from day-to-day accounts and used only for admin tasks.
- Access is reviewed every quarter, and removed on or before a person's last day.
3. Updates and Supported Software
- High and critical security updates are applied within 14 days across devices, servers and containers.
- We only run operating systems, frameworks and packages that are still supported by their vendors.
- Project dependencies are checked for known vulnerabilities, and container images are rebuilt regularly from patched base images.
4. Hosting and Infrastructure
- Our servers run in UK cloud data centres in London.
- All websites and applications we host are served over HTTPS only, using TLS 1.2 or newer.
- Firewalls block all inbound traffic by default, and servers are not directly reachable from the internet.
- Administrative access is limited to approved network addresses and uses key-based authentication.
- Connections to our databases are encrypted.
5. Your Code and Data
- Client repositories are private, with access limited to the people working on the project.
- Passwords, API keys and other secrets are kept out of source code and stored in an encrypted password manager or secret store.
- Client information is kept confidential and used only to deliver the agreed work, as set out in our Terms and Conditions.
- Personal data is handled in line with UK GDPR, as described in our Privacy Policy.
6. Work Devices
- Laptops and phones used for work run supported operating systems with automatic updates turned on.
- Devices are protected by strong passwords or biometrics and lock automatically when idle.
- Built-in firewalls and malware protection are enabled.
- Only approved applications from official app stores are installed.
7. Reporting a Vulnerability
If you believe you have found a security issue in this website or in a product we have built, please report it through our Support Center and choose "Security Vulnerability Report". Reports go straight to the person responsible for security. Include enough detail for us to reproduce the issue, and please give us a reasonable amount of time to fix it before sharing it publicly. We will acknowledge your report and keep you updated.
We do not run a paid bug bounty programme. Our reporting details are also published in security.txt.
8. Contact
For security questionnaires, supplier assessments or a copy of our certificate, please use our contact page.