Skip to content

Security & assurance

Security is built in, not bolted on

When you trust us with your software – and often your data – security isn’t an afterthought. We’re independently certified, we’re an approved government supplier, and secure practice is built into how we develop.

Certifications

What we’re accredited for

Cyber Essentials Plus

Certified to Cyber Essentials Plus, the UK government-backed standard that includes hands-on technical verification of our security controls (a step beyond basic Cyber Essentials).

Crown Commercial Service supplier

An approved supplier to UK government through the Crown Commercial Service, including to the Medicines & Healthcare products Regulatory Agency (MHRA) – work that requires meeting a high assurance bar.

Practice

Secure by practice

Secure development lifecycle

Security is considered throughout design, build and review – not tested in at the end.

Code review and testing

Every change goes through review and automated testing before release.

Dependency management

We keep frameworks and libraries current and supported – a major reason we take modernisation seriously.

Data protection

We handle personal data in line with UK GDPR and the Data Protection Act 2018.

Regulated clients

Comfortable with a high bar

We already deliver software for clients in regulated and safety-critical settings – clinical homecare and major engineering programmes among them – so we’re used to meeting the security and assurance expectations that come with sensitive systems.

UK GDPR & DPA 2018 UK/EU Azure regions

Questions about security?

If you have specific security or compliance requirements, tell us – we’re happy to talk through how we’d meet them.

Or call us on 020 3433 1452