Data minimisation
We begin with the minimum information needed. An initial conversation does not require sensitive award, research or personal data.
Security and assurance
Universities, institutes and funded organisations need a clear answer about data, access, AI, suppliers and accountability before work begins. This page sets out our current approach.
Our control principles
The exact assurance model depends on the service and information involved. We document that position rather than asking clients to rely on a general promise.
We begin with the minimum information needed. An initial conversation does not require sensitive award, research or personal data.
For client work, the purpose, data set, access route, authorised people and review points are agreed before information is shared.
Approved platforms, locations and secure transfer arrangements are documented for the service and the client’s requirements.
Engagement records are retained for an agreed purpose and period, then returned or securely deleted subject to legal and contractual obligations.
We agree the approved sources, human review, access and permitted use before client information is used in an AI-enabled workflow. We do not treat model output as an accountable decision.
Security concerns are escalated through a named contact, investigated and communicated in line with contractual and legal requirements.
Public website
Responsible AI
We help organisations define responsible use, ownership, risk controls, approved workflows, evidence and oversight.
ISO/IEC 42001 qualified Lead ImplementerCertificate no. ENR-01704976Supplier due diligence
We can respond to proportionate supplier-security and data-protection questions for a proposed engagement, including the service scope, information flow, subprocessors where relevant and control responsibilities.
Certifications are stated only when they are current and evidenced; this page does not imply a certification that is not explicitly named. Contact us for the latest position and supporting documents.
Request assurance information ↗Security by design
Share the relevant due-diligence route at the start. We will give you a clear current answer and identify anything that needs to be agreed in the scope.
Book a 30-minute operations review