Trust & Compliance

Trust & Compliance Centre

Everything a UK customer's procurement, security, or data-protection team needs to assess Assemblysoft as a supplier — in one place, mapped to the questions due-diligence questionnaires actually ask.

Compliance statements

Public summaries of our policies and operating practices. Each document opens with an "at a glance" answer to the underlying due-diligence questions.

Hosting

Hosting & Data Residency

UK data residency on Microsoft Azure, our hosting provider's ISO 27001 certification, and platform uptime SLAs — with links to Microsoft's official documentation.

Last reviewed: March 2026

Read the statement
Access Controls

Information Security & Access Control

Multi-factor authentication for administrative access, least-privilege access management, and audit logging of administrative activity on customer systems.

Last reviewed: October 2025

Read the statement
Incident Response

Incident Response & Breach Notification

Our documented incident response process and our customer breach-notification commitments under UK GDPR.

Last reviewed: January 2026

Read the statement
Business Continuity

Business Continuity & Disaster Recovery

How services are recovered after disruption, our recovery time objectives for critical services, and the Azure capabilities that underpin them.

Last reviewed: July 2025

Read the statement
Compliance

Certifications, Standards & Regulatory Monitoring

The standards we align to, the certifications held at our hosting layer, and how we stay current with UK data protection and privacy regulation.

Last reviewed: February 2026

Read the statement
Third Parties

Third-Party Supplier Management

How we conduct due diligence on hosting providers, integrations, and other suppliers, and how our supplier register is maintained.

Last reviewed: September 2025

Read the statement
Development

Secure Development & Change Management

Secure coding practices, code review, dependency management, and the change-management process we follow before releases reach customers.

Last reviewed: December 2025

Read the statement
Contracts

Data Ownership & Portability

Contractual confirmation that customers own their data and deliverables, plus data extraction and handover options at contract end.

Last reviewed: May 2025

Read the statement
Insurance & Stability

Insurance & Company Information

Professional indemnity and cyber liability cover, Companies House registration, and evidence of company stability and trading history.

Last reviewed: April 2026

Read the statement

Legal documents

Our published legal and policy documents, referenced throughout the statements above.

Legal

Privacy Policy

How we collect, use, and protect personal data as a UK data controller and processor.

View policy
Legal

Website Terms & Conditions

Terms governing use of the Assemblysoft website.

View terms
Legal

Master Services Agreement

Full contractual terms covering engagements — including intellectual property, data ownership, confidentiality, and termination.

View agreement
Statements

Modern Slavery Statement

Our commitment to preventing modern slavery and human trafficking in our operations and supply chains.

View statement

Evidence available on request

Some due-diligence evidence is deliberately not published on a public website, because doing so would create security or fraud risk. The following are available to customers and prospective customers on request, under NDA where appropriate:

  • Insurance certificates (professional indemnity and cyber liability) — published certificates are easily copied and misused; we provide current certificates directly to counterparties.
  • Third-party supplier register — the full register of suppliers with access to customer data is confidential and shared with customers under NDA.
  • Incident Response Plan (full document) — the complete plan contains internal contact trees and playbooks; a public summary is provided here.
  • Business Continuity / Disaster Recovery runbooks — full recovery procedures describe internal infrastructure and are shared under NDA; a public summary is provided here.
  • Access control policy (full document) and audit log samples — detailed control configurations are not published for security reasons.

To request any of the above, contact hello@assemblysoft.com with a note of the engagement or tender it relates to.

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor