Security & governance

Your data stays yours.
We just move it.

Handling a business's operational data is a serious responsibility, whatever the size of the business. Here is exactly how we treat yours — in plain terms, not marketing language.

Foundations

Six commitments, applied to every engagement.

Least privilege

Each connector is scoped to the narrowest read it needs. We ask for nothing beyond the fields in your agreed spec, and write access only where a delivery requires it.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Credentials are held in a managed secret store, rotated on a schedule, and never committed to configuration.

UK data residency

Processing and storage stay in UK or EU regions by default. Sub-processors are documented, and we'll tell you before that list changes.

Complete audit trail

Every pipeline run, every Delta question, every export destination — recorded with user, timestamp, row count and outcome.

Access you control

SSO where you have it, role-based access where you don't, and row-level rules mirrored from your existing systems.

UK GDPR alignment

Data minimisation by design, documented lawful basis, DPA and retention schedule as standard, and support for subject access requests.

Operating practice

How we run, day to day.

Change control

Every change to a data flow is reviewed, versioned and reversible.

Isolated environments

Your data is logically separated with per-client credentials and storage.

Dependency scanning

Automated vulnerability scanning on every deploy, with a patch SLA.

Incident response

A written plan, named contacts and a 24-hour notification commitment.

Backups and recovery

Point-in-time recovery on managed stores, tested restores.

Offboarding

On exit we return your data and destroy our copies, with written confirmation.

Due diligence

Need to put us through your process?

We're used to it, and we don't stall. We'll complete your security questionnaire, sign your DPA, walk your IT lead or MSP through the architecture, and agree penetration testing arrangements where required.

Questions your IT lead needs answering?

Bring them to the call. We'd rather have the detailed conversation early than gloss over it.