Trust

Transparency

The split below does not vary with the party asking, nor with the commercial stake of the consultation. Knowing it in advance avoids a request we could not answer.

Published on this site

  • Commitments on security, data protection and responsible use.
  • Deployment modes offered and the principle of key custody.
  • Company registration identifiers.
  • Responsible disclosure policy and reporting address.

Shared at pre-qualification

  • Complete internal policies and current attestations.
  • Capability statement matched to the scope of the consultation.
  • References, with the prior written agreement of the organisation concerned.
  • Curricula of the proposed team and insurance cover.

Never disclosed

  • The name of a client not authorised for publication, in any form.
  • Architecture, configuration or vulnerability of a system operated for a client.
  • Data processed during an engagement, including in anonymised form.
  • Operational capabilities whose disclosure would expose an organisation.

Hosting and subcontracting

The public site and the enquiry service run on the group’s own infrastructure. The named list of subcontractors and hosts involved in an engagement is provided to the client organisation and updated on every change.

Shared at pre-qualification

This material is provided to an identified organisation once the request has been qualified.

  • List of subcontractors and hosts applicable to the engagement.
  • Change log of the published policies.
  • Security advisories concerning systems operated for the client.

Request the documentation

Consultations · Pre-qualifications · Partnerships

Let’s discuss your project.

Describe your priority, its operating context and the intended outcome. We will route the enquiry to the right person.