Security-conscious delivery
Access, tools, environments, data movement, review gates, and handover can be discussed against project risks and client requirements.
Use this Trust Center to review our approach to information security, privacy, confidentiality, responsible AI, secure delivery, resilience, quality, and supplier due diligence before or during an engagement.
Our goal is to make review discussions practical and evidence-led without implying that one policy, control, technology, or legal framework automatically applies to every project.
Project-specific obligations, controls, evidence, and responsibilities remain subject to scope, contract, client requirements, and approved technical configuration.
We organise trust discussions around the real conditions of the engagement rather than relying on broad claims. This helps client teams identify what must be confirmed, documented, configured, monitored, and owned.
Access, tools, environments, data movement, review gates, and handover can be discussed against project risks and client requirements.
Data categories, purpose, roles, retention, transfers, and processing instructions should be identified before sensitive work begins.
AI use should be appropriate, transparent, human-reviewed, contractually permitted, and proportionate to the data and decision risk.
Assumptions, dependencies, limitations, acceptance criteria, responsibilities, and changes should be visible to relevant stakeholders.
Explore focused pages for security, privacy, legal, technical, operational, quality, resilience, and procurement questions.
How we approach systems, access, project environments, and client information during delivery.
Review Information SecurityHow privacy considerations may be addressed through discovery, processing, retention, and closure.
Review Data PrivacyHow client obligations, control expectations, contractual requirements, and evidence requests are discussed.
Review CompliancePrinciples for human oversight, appropriate use, data quality, transparency, and client-approved AI workflows.
Review Responsible AIProject-focused practices for access limitation, careful dataset handling, and engagement-suitable safeguards.
Review Data ProtectionHow NDAs, restricted information, need-to-know access, and confidentiality expectations can be incorporated.
Review ConfidentialityHow scope, tools, access, environments, review gates, and handover procedures may be defined.
Review Secure DeliveryOur approach to identifying, escalating, assessing, communicating, and learning from suspected events.
Review Incident ResponseHow continuity, key-person dependencies, communication paths, backups, and recovery considerations may be planned.
Review Business ContinuityHow third-party tools and providers may be assessed for scope, access, data exposure, and client requirements.
Review Vendor ManagementA practical view of technology choices, hosting dependencies, access models, and architecture discussions.
Review Infrastructure & TechnologyHow requirements, data outputs, models, dashboards, pipelines, documentation, and deliverables may be reviewed.
Review Quality AssuranceHow timelines, responsibilities, acceptance criteria, communication routines, and expectations are documented.
Review Service CommitmentsClient perspectives presented with context and without treating testimonials as assurance evidence.
Review Client TestimonialsAnswers for procurement, legal, security, privacy, technical, operational, and executive reviewers.
Review FAQsA central location for approved policies, summaries, questionnaires, and review materials when available.
Review Trust DocumentsSubmit a due-diligence question, request available documentation, or arrange a project-specific discussion.
Review Contact Trust TeamDifferent stakeholders ask different questions. The Trust Center provides a shared starting point while keeping specialist review responsibilities clear.
Compare supplier suitability, delivery dependencies, documentation availability, responsibilities, and review steps.
Review confidentiality, contractual roles, data-processing requirements, intellectual property, and engagement-specific terms.
Understand access, tools, environments, incident escalation, third-party dependencies, and available evidence.
Assess data categories, purpose, roles, retention, transfers, subprocessors, and data-subject considerations.
Discuss architecture, cloud platforms, integrations, identity, deployment, observability, and handover.
Clarify owners, milestones, change control, continuity, support, and operational acceptance.
Understand material risk, accountability, decision rights, dependencies, and business implications.
Review requests are most effective when they identify the engagement, the requested evidence, the decision deadline, and the stakeholders who need the response.
Security questionnaires, vendor assessments, documentation requests, NDA discussions, DPA reviews, architecture discussions, data-flow clarification, third-party reviews, and project-specific control questions.
Identify the proposed service, data involved, systems, geography, delivery model, deadline, and decision owners.
Questions are directed to the relevant legal, privacy, security, technical, delivery, or executive owner.
Responses should rely on approved documents, contracts, technical configurations, or documented procedures rather than assumptions.
Open points may require clarification, a proposed safeguard, a contractual term, a client decision, or a documented limitation.
Confirmed obligations, owners, dependencies, acceptance criteria, and exceptions should be captured in the appropriate project or contract documents.
We distinguish approved current practices from engagement options, dependencies, client responsibilities, and future intentions.
Data, access, tools, and controls should be appropriate to the agreed work and proportionate to the relevant risk.
Important requirements, assumptions, exceptions, ownership, and acceptance decisions should be recorded in suitable project artefacts.
Professional judgment remains important for data interpretation, AI use, quality checks, exceptions, and business-impact decisions.
Cloud platforms, client systems, licences, vendors, data quality, and operational ownership can materially affect outcomes.
Clients and service providers each retain responsibilities for instructions, access, approvals, source data, platform decisions, and lawful use.
This matrix is illustrative. Final ownership must be confirmed for the actual engagement.
| Review area | Our typical contribution | Client contribution | Must be confirmed |
|---|---|---|---|
| Scope and purpose | Clarify proposed services, assumptions, deliverables, and dependencies. | Provide business purpose, authorised instructions, stakeholders, and constraints. | Approved scope, decision rights, and success criteria. |
| Data and access | Request access reasonably needed for the agreed work and follow approved methods. | Classify data, approve access, configure client systems, and remove access when appropriate. | Data categories, roles, environments, access path, retention, and deletion. |
| Technology and vendors | Explain proposed tools and relevant delivery dependencies. | Approve platforms, licences, accounts, configurations, and restricted technologies. | Hosting, location, subprocessors, integrations, and responsibility boundaries. |
| Quality and acceptance | Perform agreed reviews and communicate known limitations. | Provide representative inputs, subject expertise, timely feedback, and final approval. | Test criteria, review gates, acceptance process, and production ownership. |
| Security and incidents | Follow applicable procedures and agreed escalation paths. | Provide client contacts, system context, and required internal response coordination. | Reporting route, notification obligations, evidence, and decision authority. |
The entries below are clearly labelled placeholders until approved, current documents and controlled download routes are available.
Suggested content: governance, access, delivery environments, secure working practices, incident escalation, and responsibility boundaries.
Do not publish a download until security and legal approval is recorded.Suggested content: roles, purpose limitation, data categories, retention, deletion, transfers, subprocessors, and engagement-specific DPA considerations.
Requires privacy and legal approval before publication.Suggested content: approved use, human oversight, data sensitivity, transparency, validation, limitations, intellectual property, and client instructions.
Requires technical, legal, privacy, and executive approval.This Trust Center describes a general approach. It does not create a warranty, legal commitment, certification, service level, or representation that every practice applies to every engagement.
Contractual documents, approved project plans, client instructions, and verified technical configurations take precedence for a specific engagement.
Clients remain responsible for lawful instructions, source-data rights, access approvals, platform ownership, internal governance, user decisions, and appropriate use of outputs.
We remain responsible for the commitments expressly accepted in the applicable agreement and for performing the agreed scope with appropriate professional care.
It gives prospective clients and review teams a central place to understand our approach to security, privacy, confidentiality, responsible AI, resilience, quality, third-party dependencies, and due diligence. It is not a substitute for project-specific contractual or technical review.
No. Data consulting engagements vary by scope, platform, data category, client environment, access model, geography, and delivery method. Applicable practices and responsibilities should be confirmed during scoping and documented in the relevant agreement or project plan.
No certification or audit status is claimed on this page. Where approved evidence exists, it should be listed in the Trust Documents area. Procurement and security teams may request available documentation for review, subject to confidentiality and access restrictions.
We can review reasonable questionnaires and supplier-assessment requests. Completion depends on relevance, available verified evidence, confidentiality requirements, scope, and the time needed to coordinate accurate responses with the appropriate owners.
Confidentiality terms, including an NDA where appropriate, can be discussed before sensitive information is exchanged. Final terms are subject to legal review, the nature of the engagement, jurisdiction, and the responsibilities of each party.
A DPA may be appropriate where the engagement involves processing personal data on a client’s behalf. Roles, instructions, data categories, purposes, subprocessors, transfers, retention, deletion, and security measures must be reviewed for the specific engagement.
Our approach is to seek only the access reasonably required for the agreed work, define authorised users and environments, and align access methods with client requirements where practical. Exact controls depend on the client platform, delivery model, and approved technical configuration.
Confidential information should be identified, shared through approved channels, limited to authorised participants, and used only for the agreed purpose. Handling, return, deletion, and retention requirements should be captured in applicable contracts and project procedures.
AI use should be purposeful, proportionate, reviewed by people, and aligned with client instructions. Whether an AI tool is appropriate depends on data sensitivity, contractual restrictions, model behaviour, transparency needs, intellectual-property considerations, and the required level of human review.
No. Models, forecasts, dashboards, reports, and automated decisions can be affected by source quality, assumptions, drift, missing context, configuration, and user interpretation. Validation criteria, human review, limitations, and acceptance responsibilities should be agreed for each engagement.
Suspected events should be escalated, assessed, contained where possible, documented, and communicated according to applicable procedures and contractual requirements. Exact notification duties, contacts, and timelines must be defined and approved for the engagement.
Third-party dependencies may be reviewed for purpose, data exposure, access, location, contractual terms, service criticality, and client restrictions. The client may also retain responsibilities for approving platforms, accounts, licences, configurations, and vendor terms.
Depending on availability and approval, requests may include policy summaries, completed questionnaires, data-flow information, architecture notes, incident-process summaries, business-continuity information, privacy details, or contractual documentation. Some materials may require an NDA or controlled access.
Retention and deletion should be based on project needs, legal and contractual obligations, technical feasibility, backup dependencies, and client instructions. Engagement-specific requirements should be agreed rather than inferred from a general website statement.
Use the Contact Trust Team page or the main contact route and identify the review type, project, deadline, requested materials, and relevant stakeholders. This helps route the request to the appropriate legal, privacy, security, technical, or delivery owner.
Include the proposed service, review type, requested materials, deadline, and relevant stakeholders so the request can be routed accurately.