Skip to main content
Data Consulting Trust Center

Clear trust information for responsible data and AI engagements.

Use this Trust Center to review our approach to information security, privacy, confidentiality, responsible AI, secure delivery, resilience, quality, and supplier due diligence before or during an engagement.

Our goal is to make review discussions practical and evidence-led without implying that one policy, control, technology, or legal framework automatically applies to every project.

Project-specific obligations, controls, evidence, and responsibilities remain subject to scope, contract, client requirements, and approved technical configuration.

Executive summary

Trust starts with defined scope, transparent decisions, and shared responsibility.

We organise trust discussions around the real conditions of the engagement rather than relying on broad claims. This helps client teams identify what must be confirmed, documented, configured, monitored, and owned.

Security-conscious delivery

Access, tools, environments, data movement, review gates, and handover can be discussed against project risks and client requirements.

Privacy-aware scoping

Data categories, purpose, roles, retention, transfers, and processing instructions should be identified before sensitive work begins.

Responsible AI use

AI use should be appropriate, transparent, human-reviewed, contractually permitted, and proportionate to the data and decision risk.

Transparent delivery

Assumptions, dependencies, limitations, acceptance criteria, responsibilities, and changes should be visible to relevant stakeholders.

Trust Center directory

Find the information your review team needs.

Explore focused pages for security, privacy, legal, technical, operational, quality, resilience, and procurement questions.

Security

Information Security

How we approach systems, access, project environments, and client information during delivery.

Review Information Security
Privacy

Data Privacy

How privacy considerations may be addressed through discovery, processing, retention, and closure.

Review Data Privacy
Governance

Compliance

How client obligations, control expectations, contractual requirements, and evidence requests are discussed.

Review Compliance
AI governance

Responsible AI

Principles for human oversight, appropriate use, data quality, transparency, and client-approved AI workflows.

Review Responsible AI
Data

Data Protection

Project-focused practices for access limitation, careful dataset handling, and engagement-suitable safeguards.

Review Data Protection
Confidentiality

Confidentiality

How NDAs, restricted information, need-to-know access, and confidentiality expectations can be incorporated.

Review Confidentiality
Delivery

Secure Delivery

How scope, tools, access, environments, review gates, and handover procedures may be defined.

Review Secure Delivery
Response

Incident Response

Our approach to identifying, escalating, assessing, communicating, and learning from suspected events.

Review Incident Response
Resilience

Business Continuity

How continuity, key-person dependencies, communication paths, backups, and recovery considerations may be planned.

Review Business Continuity
Third parties

Vendor Management

How third-party tools and providers may be assessed for scope, access, data exposure, and client requirements.

Review Vendor Management
Technology

Infrastructure & Technology

A practical view of technology choices, hosting dependencies, access models, and architecture discussions.

Review Infrastructure & Technology
Quality

Quality Assurance

How requirements, data outputs, models, dashboards, pipelines, documentation, and deliverables may be reviewed.

Review Quality Assurance
Service

Service Commitments

How timelines, responsibilities, acceptance criteria, communication routines, and expectations are documented.

Review Service Commitments
Experience

Client Testimonials

Client perspectives presented with context and without treating testimonials as assurance evidence.

Review Client Testimonials
Answers

FAQs

Answers for procurement, legal, security, privacy, technical, operational, and executive reviewers.

Review FAQs
Documents

Trust Documents

A central location for approved policies, summaries, questionnaires, and review materials when available.

Review Trust Documents
Contact

Contact Trust Team

Submit a due-diligence question, request available documentation, or arrange a project-specific discussion.

Review Contact Trust Team
Who this information is for

Designed for cross-functional supplier and project review.

Different stakeholders ask different questions. The Trust Center provides a shared starting point while keeping specialist review responsibilities clear.

Procurement teams

Compare supplier suitability, delivery dependencies, documentation availability, responsibilities, and review steps.

Legal teams

Review confidentiality, contractual roles, data-processing requirements, intellectual property, and engagement-specific terms.

Security teams

Understand access, tools, environments, incident escalation, third-party dependencies, and available evidence.

Privacy teams

Assess data categories, purpose, roles, retention, transfers, subprocessors, and data-subject considerations.

Technical leaders

Discuss architecture, cloud platforms, integrations, identity, deployment, observability, and handover.

Operations teams

Clarify owners, milestones, change control, continuity, support, and operational acceptance.

Executive stakeholders

Understand material risk, accountability, decision rights, dependencies, and business implications.

How we support client reviews

Practical coordination for due diligence and project-specific questions.

Review requests are most effective when they identify the engagement, the requested evidence, the decision deadline, and the stakeholders who need the response.

Common review requests

Security questionnaires, vendor assessments, documentation requests, NDA discussions, DPA reviews, architecture discussions, data-flow clarification, third-party reviews, and project-specific control questions.

01

Define the review context

Identify the proposed service, data involved, systems, geography, delivery model, deadline, and decision owners.

02

Route the request

Questions are directed to the relevant legal, privacy, security, technical, delivery, or executive owner.

03

Validate available evidence

Responses should rely on approved documents, contracts, technical configurations, or documented procedures rather than assumptions.

04

Resolve engagement-specific gaps

Open points may require clarification, a proposed safeguard, a contractual term, a client decision, or a documented limitation.

05

Record agreed responsibilities

Confirmed obligations, owners, dependencies, acceptance criteria, and exceptions should be captured in the appropriate project or contract documents.

Trust principles

Principles that guide responsible delivery.

Clarity before claims

We distinguish approved current practices from engagement options, dependencies, client responsibilities, and future intentions.

Purpose and proportionality

Data, access, tools, and controls should be appropriate to the agreed work and proportionate to the relevant risk.

Documented decisions

Important requirements, assumptions, exceptions, ownership, and acceptance decisions should be recorded in suitable project artefacts.

Human review

Professional judgment remains important for data interpretation, AI use, quality checks, exceptions, and business-impact decisions.

Dependency awareness

Cloud platforms, client systems, licences, vendors, data quality, and operational ownership can materially affect outcomes.

Shared responsibility

Clients and service providers each retain responsibilities for instructions, access, approvals, source data, platform decisions, and lawful use.

What this means for clients

A practical responsibility matrix for early-stage review.

This matrix is illustrative. Final ownership must be confirmed for the actual engagement.

Review areaOur typical contributionClient contributionMust be confirmed
Scope and purposeClarify proposed services, assumptions, deliverables, and dependencies.Provide business purpose, authorised instructions, stakeholders, and constraints.Approved scope, decision rights, and success criteria.
Data and accessRequest access reasonably needed for the agreed work and follow approved methods.Classify data, approve access, configure client systems, and remove access when appropriate.Data categories, roles, environments, access path, retention, and deletion.
Technology and vendorsExplain proposed tools and relevant delivery dependencies.Approve platforms, licences, accounts, configurations, and restricted technologies.Hosting, location, subprocessors, integrations, and responsibility boundaries.
Quality and acceptancePerform agreed reviews and communicate known limitations.Provide representative inputs, subject expertise, timely feedback, and final approval.Test criteria, review gates, acceptance process, and production ownership.
Security and incidentsFollow applicable procedures and agreed escalation paths.Provide client contacts, system context, and required internal response coordination.Reporting route, notification obligations, evidence, and decision authority.
Featured trust documents

Documentation for structured review.

The entries below are clearly labelled placeholders until approved, current documents and controlled download routes are available.

Placeholder

Information Security Overview

Suggested content: governance, access, delivery environments, secure working practices, incident escalation, and responsibility boundaries.

Do not publish a download until security and legal approval is recorded.
Placeholder

Privacy and Data Processing Summary

Suggested content: roles, purpose limitation, data categories, retention, deletion, transfers, subprocessors, and engagement-specific DPA considerations.

Requires privacy and legal approval before publication.
Placeholder

Responsible AI Principles

Suggested content: approved use, human oversight, data sensitivity, transparency, validation, limitations, intellectual property, and client instructions.

Requires technical, legal, privacy, and executive approval.

Important considerations

This Trust Center describes a general approach. It does not create a warranty, legal commitment, certification, service level, or representation that every practice applies to every engagement.

Contractual documents, approved project plans, client instructions, and verified technical configurations take precedence for a specific engagement.

Shared responsibilities

Clients remain responsible for lawful instructions, source-data rights, access approvals, platform ownership, internal governance, user decisions, and appropriate use of outputs.

We remain responsible for the commitments expressly accepted in the applicable agreement and for performing the agreed scope with appropriate professional care.

Frequently asked questions

Answers for procurement, legal, privacy, security, and technical reviewers.

What is the purpose of this data consulting Trust Center?

It gives prospective clients and review teams a central place to understand our approach to security, privacy, confidentiality, responsible AI, resilience, quality, third-party dependencies, and due diligence. It is not a substitute for project-specific contractual or technical review.

Does this Trust Center confirm that every control applies to every engagement?

No. Data consulting engagements vary by scope, platform, data category, client environment, access model, geography, and delivery method. Applicable practices and responsibilities should be confirmed during scoping and documented in the relevant agreement or project plan.

Do you hold specific certifications or independent audit reports?

No certification or audit status is claimed on this page. Where approved evidence exists, it should be listed in the Trust Documents area. Procurement and security teams may request available documentation for review, subject to confidentiality and access restrictions.

Can you complete a security questionnaire or vendor assessment?

We can review reasonable questionnaires and supplier-assessment requests. Completion depends on relevance, available verified evidence, confidentiality requirements, scope, and the time needed to coordinate accurate responses with the appropriate owners.

Will you sign a non-disclosure agreement?

Confidentiality terms, including an NDA where appropriate, can be discussed before sensitive information is exchanged. Final terms are subject to legal review, the nature of the engagement, jurisdiction, and the responsibilities of each party.

Can a data processing agreement be used?

A DPA may be appropriate where the engagement involves processing personal data on a client’s behalf. Roles, instructions, data categories, purposes, subprocessors, transfers, retention, deletion, and security measures must be reviewed for the specific engagement.

How do you approach access to client systems and data?

Our approach is to seek only the access reasonably required for the agreed work, define authorised users and environments, and align access methods with client requirements where practical. Exact controls depend on the client platform, delivery model, and approved technical configuration.

How is confidential information handled?

Confidential information should be identified, shared through approved channels, limited to authorised participants, and used only for the agreed purpose. Handling, return, deletion, and retention requirements should be captured in applicable contracts and project procedures.

How do you use AI in client delivery?

AI use should be purposeful, proportionate, reviewed by people, and aligned with client instructions. Whether an AI tool is appropriate depends on data sensitivity, contractual restrictions, model behaviour, transparency needs, intellectual-property considerations, and the required level of human review.

Do you guarantee that AI or analytics outputs will be accurate?

No. Models, forecasts, dashboards, reports, and automated decisions can be affected by source quality, assumptions, drift, missing context, configuration, and user interpretation. Validation criteria, human review, limitations, and acceptance responsibilities should be agreed for each engagement.

What happens if a suspected security or privacy incident affects an engagement?

Suspected events should be escalated, assessed, contained where possible, documented, and communicated according to applicable procedures and contractual requirements. Exact notification duties, contacts, and timelines must be defined and approved for the engagement.

How are third-party tools and cloud platforms considered?

Third-party dependencies may be reviewed for purpose, data exposure, access, location, contractual terms, service criticality, and client restrictions. The client may also retain responsibilities for approving platforms, accounts, licences, configurations, and vendor terms.

What documentation can procurement or legal teams request?

Depending on availability and approval, requests may include policy summaries, completed questionnaires, data-flow information, architecture notes, incident-process summaries, business-continuity information, privacy details, or contractual documentation. Some materials may require an NDA or controlled access.

How do you manage data retention and deletion?

Retention and deletion should be based on project needs, legal and contractual obligations, technical feasibility, backup dependencies, and client instructions. Engagement-specific requirements should be agreed rather than inferred from a general website statement.

Who should we contact for a trust or due-diligence question?

Use the Contact Trust Team page or the main contact route and identify the review type, project, deadline, requested materials, and relevant stakeholders. This helps route the request to the appropriate legal, privacy, security, technical, or delivery owner.

Trust review support

Contact Our Trust Team or request available documentation.

Include the proposed service, review type, requested materials, deadline, and relevant stakeholders so the request can be routed accurately.