Security and assurance

Trust should be visible in how the work is handled.

Universities, institutes and funded organisations need a clear answer about data, access, AI, suppliers and accountability before work begins. This page sets out our current approach.

Our control principles

Proportionate controls, agreed before access.

The exact assurance model depends on the service and information involved. We document that position rather than asking clients to rely on a general promise.

01

Data minimisation

We begin with the minimum information needed. An initial conversation does not require sensitive award, research or personal data.

02

Purpose and access

For client work, the purpose, data set, access route, authorised people and review points are agreed before information is shared.

03

Storage and transfer

Approved platforms, locations and secure transfer arrangements are documented for the service and the client’s requirements.

04

Retention and deletion

Engagement records are retained for an agreed purpose and period, then returned or securely deleted subject to legal and contractual obligations.

05

AI-enabled services

We agree the approved sources, human review, access and permitted use before client information is used in an AI-enabled workflow. We do not treat model output as an accountable decision.

06

Incidents and continuity

Security concerns are escalated through a named contact, investigated and communicated in line with contractual and legal requirements.

Public website

What happens on this site

Health Check
Answers and results stay in the browser unless the user chooses to save and download the report. The submitted fields are shown clearly before that choice.
Analytics
Plausible provides aggregate journey and conversion reporting without analytics cookies or cross-site advertising profiles.
Website forms
Netlify processes form submissions for saved Health Check results and opt-in updates. Marketing consent is separate from saving a requested report.
Bookings
Calendly is an external service with its own privacy, cookie and security arrangements.
Hosting
Technical request information may be processed by the hosting provider to deliver and protect the site.

Responsible AI

From AI ambition to policy, strategy and accountable practice.

We help organisations define responsible use, ownership, risk controls, approved workflows, evidence and oversight.

ISO/IEC 42001 qualified Lead ImplementerCertificate no. ENR-01704976

Supplier due diligence

Ask for the current assurance position.

We can respond to proportionate supplier-security and data-protection questions for a proposed engagement, including the service scope, information flow, subprocessors where relevant and control responsibilities.

Certifications are stated only when they are current and evidenced; this page does not imply a certification that is not explicitly named. Contact us for the latest position and supporting documents.

Request assurance information ↗

Security by design

What assurance does your organisation need before we begin?

Share the relevant due-diligence route at the start. We will give you a clear current answer and identify anything that needs to be agreed in the scope.

Book a 30-minute operations review