TRUST & SECURITY
Built to be
trusted.
Security, privacy and responsible engineering are not features we add at the end. They are principles we apply from the first line of architecture.
SECURITY BY DESIGN
Engineering security in, not on.
Every system we design starts with a security review. These are the principles we apply consistently across all projects.
Security by Design
Security requirements are defined at the architecture stage — not added as an afterthought. Every system boundary, data flow and access path is reviewed before implementation begins.
Privacy by Design
Data minimisation, purpose limitation and access control are built into system design from the start. We collect only what is necessary and protect it throughout its lifecycle.
Least Privilege
Every component, service and user account receives only the permissions required for its specific function. Privilege escalation paths are identified and controlled.
Encrypted Transport
All data in transit is encrypted using current TLS standards. Internal service communication follows the same principle. Unencrypted channels are not used for sensitive data.
Controlled Access
Authentication, role-based authorisation and session management are implemented consistently. Administrative access requires strong authentication and is logged.
Secure Development
Code is reviewed before deployment. Dependencies are monitored for known vulnerabilities. Open-source licences are reviewed. AI-generated code is reviewed by engineers before use.
Data Protection Controls
Sensitive data is stored with appropriate encryption, access controls and audit logging. Retention periods are defined. Deletion workflows are prepared.
Backup & Recovery
Backup strategies and recovery procedures are defined for production systems. Recovery capability is verified before systems go live.
Vulnerability Management
Dependencies are monitored for security advisories. Critical vulnerabilities are addressed promptly. A responsible disclosure contact will be published when the company is operational.
Audit Logging
Security-relevant events — authentication, authorisation decisions, data access, administrative actions and status changes — are logged with sufficient detail for investigation.
RESPONSIBLE AI
AI as a tool, not a replacement for engineering judgement.
We use AI tools to accelerate engineering work. Human engineers remain accountable for every production system.
- Human engineers review all AI-generated code before it enters production
- Material use of AI tools in client deliverables is disclosed
- AI outputs are tested before deployment — not trusted blindly
- Confidential client data is not submitted to external AI services without explicit agreement
- Open-source licences and third-party assets in AI-generated code are reviewed
- Security implications of AI-generated code are assessed
- Assumptions and limitations of AI-assisted work are documented
- Important decisions remain traceable to human engineers
- Production systems have clear human accountability
- Candidates are required to disclose AI tools used in assessments
OUR POSITION
AI tools can accelerate research, drafting, code generation and analysis. They can also introduce errors, security vulnerabilities, licence issues and incorrect assumptions.
We treat AI-generated output as a starting point that requires engineering review — not as a finished product. The engineer who deploys the code is responsible for it, regardless of how it was generated.
This principle applies equally to our own engineering work and to the candidates we assess.
CANDIDATE DATA PROTECTION
Candidate information is handled with care.
We apply the same security and privacy principles to candidate data that we apply to client systems.
- Candidate data is stored separately from corporate and client data
- Access to candidate records is restricted to authorised personnel
- Application references are non-guessable and non-sequential
- Consent is recorded with timestamp and policy version
- Candidates are informed of their data rights
- Sensitive documents — passports, bank details, health records — are not collected through public forms
- CV files are stored privately and not publicly accessible
- Retention periods and deletion workflows are defined
- Cross-border data transfer position is reviewed before production launch
- The Applicant Privacy Notice is kept current and version-controlled
Applicant Privacy Notice
Full details of how we collect, use, store and protect candidate data.
Read the Applicant Privacy NoticeCandidate Terms
Terms governing participation in the recruitment process and engineering assessments.
Read the Candidate TermsTRANSPARENCY
What we do not claim.
We believe transparency about what we have not yet achieved is as important as describing what we do.
NOT CURRENTLY CLAIMED
- ISO 27001 or SOC 2 certification (not yet obtained)
- A certified Security Operations Centre
- Completed independent penetration testing
- Completed independent security audit
- Guaranteed security against all threats
- Regulatory approval for any specific jurisdiction
We will update this page as certifications, audits and verifications are completed.