01Trust & security

Hand over your data with confidence.

Every credential on this page carries its current status: held, or in progress. If a certificate matters to your security review, you can see its status here.

02Credentials & partner status

What is attained, and what is in progress.

Each item below is marked attained or in progress.

Information governance

ICO registration & UK GDPR / DUAA 2025 alignment

In progress

ICO data-protection registration is in progress. We already operate to UK GDPR and the Data (Use and Access) Act 2025 (lawful basis, data minimisation, least-privilege access and a documented handling trail on every engagement) and will show our ICO registration here once it is confirmed.

SOC 2 Type II

In progress

Readiness in progress. SOC 2 Type II requires an observation period and an independent auditor's report, so we will not claim it as held until that report is issued. A NDA and DPA are available on request in the meantime.

ISO/IEC 27001: Information security management

In progress

Building our information-security management system towards ISO/IEC 27001. Certification is awarded by an accredited body following audit; listed as in-progress until then.

ISO/IEC 27701: Privacy information management

In progress

Extending the management system towards ISO/IEC 27701 for privacy. In-progress until independently certified.

Platform partner status

Microsoft Solutions Partner roadmap: Data & AI (Azure)

In progress

Working towards the Microsoft Solutions Partner designation for Data & AI, which is earned over time against skilling, certification and customer-success measures. We will publish the designation here once Microsoft awards it.

Team certifications

Microsoft PL-300: Power BI Data Analyst

In progress

Certification in progress for the team. Until each exam is passed we describe this as in-progress rather than implying it is already held.

Microsoft DP-600: Fabric Analytics Engineer

In progress

Certification in progress for the team, covering Microsoft Fabric analytics engineering. Marked in-progress until awarded.

03Working across timezones

A reliable window with you, wherever you are.

We plan delivery around guaranteed overlap and work async by default, so progress keeps moving across time zones, day and night.

Benelux (NL, BE, LU)

UTC+1 / UTC+2 (CET/CEST)

A full shared working day. One hour ahead of the UK, so we are effectively in the same business hours for live working sessions.

US East

UTC-5 / UTC-4 (ET)

Guaranteed daily overlap. Your morning is our afternoon, giving a dependable window every working day for calls and reviews.

US West

UTC-8 / UTC-7 (PT)

Scheduled overlap. We hold a regular booked window (typically your morning, our late afternoon) for synchronous work, with async progress in between.

Australia

UTC+8 to UTC+11 (AWST–AEDT)

A dedicated UK early-morning window (around 08:00–10:00 UK time) reserved for live Australian sessions, so you reach us inside your working day.

Async-first, everywhere

Any timezone

Async by default. Written updates, recorded walkthroughs and a clear backlog keep progress moving across time zones, day and night.

04Data residency

Your data stays in the right region.

We host client data in the Azure region that matches your jurisdiction, keeping it inside the appropriate data boundary.

United Kingdom
Data hosted in UK Azure regions, governed by UK GDPR and the Data (Use and Access) Act 2025.
Benelux (NL, BE, LU)
Kept inside the Microsoft EU Data Boundary, using Azure Netherlands and Belgium regions to keep EU data within the EU.
United States
Hosted in US Azure regions for US-based engagements, with our SOC 2 Type II readiness programme underpinning the control set.
Australia
Hosted in the Azure Australia East region so Australian client data stays onshore.
05Security posture

Careful by default, not by exception.

Least-privilege access

We request only the access a task needs, scoped and time-bound, and we remove it when the work is done. Service accounts and roles are documented so you always know who can see what.

NDA & DPA on request

We sign a mutual NDA before sensitive discussions and a Data Processing Agreement (DPA) before handling personal data, so responsibilities and processing terms are clear in writing.

Data minimisation by design

We collect the least we need and avoid storing raw personal identifiers where a hash will do, for example salting and hashing IP addresses rather than retaining them, so analytics never depend on identifiable data.

Let's talk

Security or compliance question?

We answer it directly.

A fixed price agreed in writing before we start, and you own everything we hand over.