How we handle your systems and your data
For the IT director or security officer who has to approve a firm touching a production environment. What we commit to architecturally, what we get asked on the first call, and what we do not claim.
What we commit to
These are architecture and practice commitments: they describe how the work is set up, and the ones that bear on your data are written into the engagement agreement. Each can be checked against what we do once we are in your environment.
Your cloud, by default
Managed hosting runs by default inside your own cloud tenancy rather than ours. The environment, the data, the logs, and the audit trail stay under your account and your agreements, while we operate the system in it.
The least data necessary
Assessments and design work run on system documentation and metadata, not case data. Where a build genuinely needs production records, we work in your environment against your access controls rather than taking a copy.
Your identity system, your access rules
Staff access runs through your single sign-on with your roles. We hold named accounts, individually attributable, revoked on your instruction and on engagement close.
Data is returned and deleted, on a published timetable
At the end of an engagement, data is returned in an agreed format and our copies are deleted, with written confirmation. There is no exit fee.
AI is used on our side of the work, under a written rule
We use AI in our own delivery, and we say where. Agency data does not enter a third-party model without a written agreement covering it, and a person reviews what AI produces before it reaches you.
Accessibility is tested before handover
WCAG 2.2 AA is an acceptance criterion on every interface we build, tested with assistive technology before handover rather than audited afterwards.
Attestations and audits
This page lists no SOC 2 report, no StateRAMP or FedRAMP authorization, and no accessibility conformance report. Where an attestation is not listed here, we either do not hold it or cannot yet confirm its status, and we will tell you which of the two it is, in writing, if you ask. An audit that is under way publishes here as under way, never as complete.
WCAG 2.2 AA is the exception, because it is tested rather than attested: it is an acceptance criterion on every interface we build, checked with assistive technology before handover, and your team can repeat the test.
Questions we get on the first call
Will you sign our security addendum?
Send it. Where an engagement touches criminal justice information, the relevant security addendum and personnel screening requirements apply to our people the same way they apply to yours, and we complete them before access is granted rather than after.
Where does our data live?
By default, in your own cloud tenancy, in the region you choose. If an engagement genuinely requires something else, that is a decision we put in front of you in writing before the work starts.
What happens to our data when we stop working with you?
It is returned in an agreed format, our copies are deleted, and you receive written confirmation. This commitment is written into the contract.
Who on your team can see our systems?
Named individuals, on your access controls, with the list published to you and kept current. Access ends when the engagement does.
What is your incident response commitment?
Notification timelines and escalation contacts are written into the engagement agreement rather than published as a general promise, because the right timeline depends on what we operate for you.
Who runs it after handover
Three options, priced in advance, with no exit fee and no penalty for moving between them. If your security review ends with your own team running the system, that is a normal outcome and it costs you nothing extra.
See engagements and pricingSelf-host, with transition support
A one-time engagement. We hand over the system, the infrastructure code, and the runbook, then work with your team until it is deployed in your environment.
Self-host, with an ongoing agreement
Your team operates the system. We remain available for patches, dependency upgrades, and incident support under an ongoing agreement.
Managed, in your cloud tenancy
We operate the system for you, by default inside your agency’s own cloud account, so the environment, the data, and the audit logs remain under your control.
Bring us your security review
Send the addendum, the questionnaire, or the hosting requirements you have to satisfy. We answer in writing, and we tell you plainly where the answer is no.