Trust & compliance / Security
Security
Last reviewed: [month, year]
We handle client data that is commercially sensitive and frequently subject to regulatory and contractual restriction. Our controls reflect that.
Certification
ISO 27001: certification targeted for [year]. Our current control framework is aligned to the standard.
Testing
Independent penetration testing is conducted before any production deployment. The report is available to prospective clients under a non-disclosure agreement.
Data residency
We support in-country data residency where host government requirements or client policy require it.
Access control
Access follows the principle of least privilege, with multi-factor authentication required, and access reviewed quarterly.
Certification status is stated accurately. Where we say "targeted" or "aligned to," we mean exactly that — we do not imply a certification we do not yet hold.
