The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
Everything a UK customer's procurement, security, or data-protection team needs to assess Assemblysoft as a supplier — in one place, mapped to the questions due-diligence questionnaires actually ask.
Public summaries of our policies and operating practices. Each document opens with an "at a glance" answer to the underlying due-diligence questions.
UK/EEA data residency on Microsoft Azure, our hosting provider's ISO 27001 certification, and platform uptime SLAs — with links to Microsoft's official documentation.
Last reviewed: March 2026
Read the statementMulti-factor authentication for administrative access, least-privilege access management, and audit logging of administrative activity on customer systems.
Last reviewed: May 2026
Read the statementOur documented incident response process and our customer breach-notification commitments under UK GDPR.
Last reviewed: January 2026
Read the statementHow services are recovered after disruption, our recovery time objectives for critical services, and the Azure capabilities that underpin them.
Last reviewed: March 2026
Read the statementThe standards we align to, the certifications held at our hosting layer, and how we stay current with UK data protection and privacy regulation.
Last reviewed: August 2026
Read the statementHow we conduct due diligence on hosting providers, integrations, and other suppliers, and how our supplier register is maintained.
Last reviewed: August 2026
Read the statementSecure coding practices, code review, dependency management, and the change-management process we follow before releases reach customers.
Last reviewed: June 2026
Read the statementContractual confirmation that customers own their data and deliverables, plus data extraction and handover options at contract end.
Last reviewed: January 2026
Read the statementProfessional indemnity and cyber liability cover, Companies House registration, and evidence of company stability and trading history.
Last reviewed: April 2026
Read the statementDirect answers to the questions assessors ask most — security, hosting, continuity, contracts, insurance, and how we work — each linked to its fuller statement.
Last reviewed: August 2026
Browse the answersOur published legal and policy documents, referenced throughout the statements above.
How we collect, use, and protect personal data as a UK data controller and processor.
View policyFull contractual terms covering engagements — including intellectual property, data ownership, confidentiality, and termination.
View agreementOur commitment to preventing modern slavery and human trafficking in our operations and supply chains.
View statementSome due-diligence evidence is deliberately not published on a public website, because doing so would create security or fraud risk. The following are available to customers and prospective customers on request, under NDA where appropriate:
To request any of the above, contact hello@assemblysoft.com with a note of the engagement or tender it relates to.