Information Security Management System Policy
We build software for clients who trust us with their most sensitive assets: their source code, their intellectual property, and the data we handle on their behalf. Protecting that information, alongside our own, is a condition of doing business. We run an Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 to keep that protection consistent and accountable.
The policy covers the whole Organisation: every team, system, and process that handles information, whether it belongs to us or to a client.
Our leadership owns it. They fund the ISMS, hold every team to its controls, commit us to our legal, regulatory, and contractual security obligations, and treat improvement as a standing requirement, not a periodic project.
What we hold ourselves to:
- Protect the confidentiality, integrity, and availability of information, ours and our clients’.
- Build security into how we develop software, and guard client source code and IP as we would our own.
- Find, weigh, and reduce security risks before they reach a client.
- Stay compliant with ISO/IEC 27001 and the laws and contracts that bind us.
- Keep our people fluent in security; most incidents trace back to people, not technology.
We check whether the ISMS actually works through internal audits, management reviews, and the near-misses we learn from. We fix what falls short. This policy carries the authority of our leadership and applies to everyone who works here.