Skip to content
Security and due diligence

Start with your requirements.

A useful security review starts with the actual workload, data, risks, and responsibilities. Discuss these with our team before agreeing an engagement.

An operations room with a large network display.

Scope the review before the work.

The topics below guide a conversation; they are not an attestation of controls or certification. We do not currently have independent compliance reports or certifications available to substantiate public claims. Confirm any required evidence and contractual commitments with our team.

Identity and access

Define who needs access, how they authenticate, and how access is approved and reviewed.

Data handling

Identify the data in scope, its sensitivity, permitted locations, and retention requirements.

Backup and recovery

Agree recovery objectives, backup scope, restore testing, and the responsibilities of each party.

Monitoring and response

Specify what is monitored, who receives alerts, and the response arrangements for the engagement.

Change and vulnerability management

Review the proposed controls for releases, patching, security findings, and operational changes.

Evidence and responsibilities

Identify the evidence your review requires and confirm what can be provided before making a decision.