Trust & compliance / Security

Security

Last reviewed: [month, year]

We handle client data that is commercially sensitive and frequently subject to regulatory and contractual restriction. Our controls reflect that.

Certification

ISO 27001: certification targeted for [year]. Our current control framework is aligned to the standard.

Testing

Independent penetration testing is conducted before any production deployment. The report is available to prospective clients under a non-disclosure agreement.

Data residency

We support in-country data residency where host government requirements or client policy require it.

Access control

Access follows the principle of least privilege, with multi-factor authentication required, and access reviewed quarterly.

Certification status is stated accurately. Where we say "targeted" or "aligned to," we mean exactly that — we do not imply a certification we do not yet hold.