Official Statutory Registers
Each policy document constitutes a legally binding commitment to ethical engineering, data confidentiality, workplace welfare, and statutory compliance under UK law.
Privacy & Data Protection Notice
Full transparency on Data Controller details, legal bases under UK GDPR Article 6, zero third-party profiling, strict retention timelines, and data subject rights (DSAR).
Cookie & Technical Storage Policy
Explanations of strictly necessary security tokens (anti-CSRF, rate limiters) vs optional telemetry. Interactive preference controls to customize or revoke consent anytime.
Master Terms of Engagement
Commercial framework governing technical audits, Statements of Work (SOW), intellectual property rights, non-destructive warranties, liability caps, and English jurisdiction.
Acceptable Use Policy (AUP)
Prohibits unauthorized penetration testing of non-client hosts, automated denial-of-service, API scrapers, credential theft, and reverse engineering of proprietary telemetry.
Anti-Bribery & Corruption Policy
Zero tolerance for commercial bribery, public official inducements, and facilitation payments. Strict gifts and hospitality register, procurement integrity, and severe disciplinary sanctions.
Modern Slavery & Human Trafficking
Compliance statement pursuant to Section 54 of the Modern Slavery Act 2015. Supplier due diligence across cloud platforms, hardware sourcing, fair wages, and ethical recruitment.
Corporate Anti-Facilitation of Tax Evasion
Measures under Part 3 of the Criminal Finances Act 2017 to prevent the criminal facilitation of tax evasion in the United Kingdom and internationally. Rigorous billing and invoicing controls.
Whistleblowing & Protected Disclosures
Protected channels under the Public Interest Disclosure Act 1998 for reporting security concealment, financial irregularities, or unlawful activity with full anti-retaliation immunity.
Information Security & Cyber Policy
Technical & Organisational Measures (TOMs) under UK GDPR Article 32: TLS 1.3 encryption, AES-256 envelope vaults, Zero-Trust network segmentation, and 72h ICO breach notification SLA.
Health, Safety & Environment (HSE)
Adherence to the Health and Safety at Work etc. Act 1974. Hardware laboratory safety, display screen ergonomics, engineer mental wellbeing, and sustainable low-carbon cloud computing.
Vulnerability Disclosure & Safe Harbor
Rules of engagement for defensive researchers, legal Safe Harbor against Computer Misuse Act claims for good-faith disclosures, PGP encryption key, and security.txt standards.
UK Statutory Enactments & Compliance Audit Table
| STATUTORY ENACTMENT | PRIMARY MANDATE | BURUOPS STATUS | REVIEW FREQUENCY |
|---|---|---|---|
| Data Protection Act 2018 / UK GDPR | Data minimization, lawful basis, subject rights, breach notification | VERIFIED COMPLIANT | Biannual |
| PECR 2003 (Reg 6) | Prior consent for non-essential cookies, no pre-ticked boxes | VERIFIED COMPLIANT | Continuous |
| Bribery Act 2010 (Sec 7) | Adequate procedures preventing commercial & public official bribery | VERIFIED COMPLIANT | Annual |
| Modern Slavery Act 2015 (Sec 54) | Supply chain transparency, zero forced labor, fair living wage | VERIFIED COMPLIANT | Annual Board Sign-off |
| Criminal Finances Act 2017 (Part 3) | Prevention of facilitation of UK and foreign tax evasion | VERIFIED COMPLIANT | Annual |
| Computer Misuse Act 1990 | Prohibition of unauthorized access; authorized scope boundaries | STRICT CONTRACT ENFORCEMENT | Per Engagement SOW |
| Public Interest Disclosure Act 1998 | Confidential reporting protection for whistleblowers | VERIFIED COMPLIANT | Continuous |
| Health and Safety at Work etc. Act 1974 | Duty of care for staff, electrical testing, display screen equipment | VERIFIED COMPLIANT | Annual Assessment |
Compliance Officer & Data Protection
For Data Subject Access Requests (DSAR), legal inquiries, or verification of our regulatory documentation, address correspondence to the compliance office.