Common Questions

Common Due-Diligence Questions

The questions procurement, security, and data-protection teams most often ask us — answered directly, with links to the fuller statement behind each answer.

Trust & Compliance Centre · Last reviewed: August 2026 · Each question has a stable identifier (e.g. HOS-01), numbered within its section — cite it when referencing an answer

Information Security & Data Protection

Do you have a documented Information Security Policy?INF-01

Yes A public summary is published in our Information Security & Access Control statement; the full policy is available to customers under NDA.

Are you GDPR compliant, with a documented framework?INF-02

Yes We operate under UK GDPR and the Data Protection Act 2018, with a published Privacy Policy and ongoing regulatory monitoring described in Certifications & Standards.

Do you encrypt data in transit and at rest?INF-03

Yes TLS on all public endpoints and encryption at rest across Azure storage and database services — see Hosting & Data Residency.

Cybersecurity

Do you hold Cyber Essentials certification?CYB-01

Yes Assemblysoft Ltd is Cyber Essentials certified — achieved 28 July 2026 for the whole organisation (certificate no. a7275954-4dd7-415e-99ba-e9d2ac193194, profile v3.3, via FIG Group / IASME; recertification due 28 July 2027). Verify the certificate on the IASME registry. We also operate documented cybersecurity controls (network controls, managed platform patching, dependency vulnerability monitoring, secrets management). See Certifications & Standards.

Cyber Essentials Plus — the independently audited assessment — was carried out on 4 August 2026 by our certification body Layer 7, against Test Specification v3.2. We are awaiting the result and will publish the certificate here once issued. Because we operate fully remotely over secure VPN — our estate and development environments are entirely cloud-based and protected, with no on-premise servers — the certification scope is clean and readily evidenced.

Do you carry out vulnerability scanning and penetration testing?CYB-02

Yes Security scanning aligned to the OWASP Top 10 is performed on a regular basis, alongside continuous dependency and known-vulnerability monitoring and Azure platform-level scanning. Independent penetration tests are arranged per engagement where the solution warrants it — see Secure Development.

Do all sites you build and host use HTTPS?CYB-03

Yes HTTPS with valid TLS certificates is enforced on all hosted solutions — see Hosting & Data Residency.

Backup & Recovery

Do you take automated backups, and how often?BCK-01

Yes Azure automated backups with geo-redundant options; database services provide point-in-time restore as standard, giving daily-or-better granularity. See Business Continuity & DR.

Do you test restores?BCK-02

Yes Recovery paths are exercised continuously through pipeline-driven redeployment, with restore verification per engagement and records available on request — see Business Continuity & DR.

Hosting & Infrastructure

Is your hosting in the UK or EEA?HOS-01

Yes Microsoft Azure within the UK/EEA — UK South (UK) or West Europe (Netherlands, EEA), agreed per engagement (UK-only available on request) — so customer data at rest stays within the UK/EEA. Full detail and verification links in Hosting & Data Residency.

Is your hosting provider ISO 27001 certified?HOS-02

Yes Microsoft Azure is ISO/IEC 27001 certified — verifiable directly via the Microsoft Service Trust Portal.

Do you guarantee a minimum uptime SLA?HOS-03

Yes Hosted services carry Azure's financially backed SLAs — minimum 99.9%, up to 99.99% by service and tier — with engagement-specific service levels agreed in writing. See Hosting & Data Residency.

Access Controls

Is MFA enforced for administrative access?ACC-01

Yes Across cloud management, source control, CI/CD, and supporting services — named individual accounts only. See Information Security & Access Control.

Do you keep audit logs of administrative access and changes?ACC-02

Yes Azure Activity Log, Entra ID sign-in and audit logs, source-control history, and deployment pipeline logs together give an attributable trail of who changed what, and when — see Information Security & Access Control.

Incident Response

Do you have a documented incident response plan?INC-01

Yes Covering detection, containment, investigation, recovery, and post-incident review — summarised publicly in Incident Response & Breach Notification, with the full plan shared under NDA.

How quickly do you notify customers of a data breach?INC-02

Without undue delay, and within 24 hours of confirming a breach affecting your systems or data — supporting your own UK GDPR obligations, including 72-hour ICO reporting where applicable. See Incident Response & Breach Notification.

Business Continuity

Do you have business continuity and disaster recovery plans?BCN-01

Yes Both — built on geo-redundant backups, infrastructure-as-code redeployment, and Azure's region pairing within the same geography, plus business-level continuity for our own operations. See Business Continuity & DR.

What is your recovery time objective (RTO)?BCN-02

24–48 hours for critical hosted services as standard; tighter objectives can be architected and agreed per engagement — see Business Continuity & DR.

Compliance & Certifications

Do you hold ISO 27001, ISO 9001, or other certifications?CMP-01

Our practices align with ISO 27001 principles, and formal ISO 27001/9001 certification is held at the hosting layer by Microsoft Azure. We are a Microsoft Partner. The full position — including what we deliberately don't claim — is in Certifications & Standards.

Where a project demands it, ISO 27001 certification can be acquired at organisational level for a specific engagement, at additional cost — as can Cyber Essentials Plus. Our fully remote, secure-VPN operating model, with an entirely cloud-based and protected estate and development environment, keeps the certifiable scope small and well-defined.

How do you stay current with UK data protection law?CMP-02

Ongoing monitoring of UK GDPR, DPA 2018, PECR, and ICO guidance, feeding a periodic review of our policies — every compliance page shows its last review date. See Certifications & Standards.

Third Parties

Do you vet your own suppliers?TPS-01

Yes Security posture, data protection terms (Article 28, transfer safeguards), and commercial stability are assessed before adoption, with periodic re-review. See Third-Party Supplier Management.

Do you keep a register of suppliers with access to customer data?TPS-02

Yes Maintained internally and shared with customers under NDA — publishing a complete supplier map would be useful to an attacker, so we don't. See Third-Party Supplier Management.

Development & Change

Do you follow secure coding practices with code review?DEV-01

Yes OWASP-aligned development, protected-branch code review, secrets kept out of source, and dependency monitoring — see Secure Development & Change Management.

Is there a formal change process with customer notification?DEV-02

Yes Version-controlled, pipeline-driven releases with approval gates and rollback, plus advance notice of major updates and maintenance windows — see Secure Development & Change Management.

Contracts & Data Ownership

Who owns our data and deliverables?CON-01

You do. Customer data and bespoke deliverables are the customer's property under our openly published Master Services Agreement — summarised in Data Ownership & Portability.

Can we take our data and code if we leave?CON-02

Yes Standard-format data exports (SQL, CSV, JSON), source and infrastructure handover, transition assistance, and secure deletion after confirmed handover — see Data Ownership & Portability.

Insurance & Company Standing

Do you hold Professional Indemnity Insurance?INS-01

Yes Professional indemnity and liability cover is in place and renewed annually. Evidence of insurance naming Assemblysoft — with insurer, cover and expiry — is provided directly to counterparties on request; see Insurance & Company Information for why we don't publish certificates.

Do you hold Cyber Liability Insurance?INS-02

Yes Certificate and coverage details provided directly on request — see Insurance & Company Information.

How long have you been trading?INS-03

Incorporated in England & Wales in 2009 — over 15 years of trading, verifiable at Companies House (07098083).

Ongoing Assurance

How do you monitor your security and compliance posture day-to-day?ASR-01

Through a self-managed compliance programme: controls are self-assessed on a quarterly cycle against our documented policy set, with continuous posture signals between reviews from Microsoft Defender for Cloud secure score, Azure Policy, and Entra ID identity secure score. The supporting evidence — policies, registers, and dated logs — is maintained as a standing pack, shareable under NDA. See Certifications & Standards.

Does your team receive security awareness training?ASR-02

Yes Everyone with access to customer systems completes security and data protection awareness training on induction and at least annually — covering recognising and reporting a personal data breach, routing a data-subject rights request, controller and processor obligations, secure handling, and phishing awareness. Completion is recorded in our Data Protection Training & Awareness Record, which forms part of our UK GDPR framework and is available to customers on request under NDA — see Information Security & Access Control.

How are devices secured for a fully remote team?ASR-03

Because we operate fully remotely over secure VPN with an entirely cloud-based estate, device posture matters — so a security baseline (disk encryption, screen lock, OS patching, malware protection) is verified through quarterly device attestation against our documented baseline, following the NCSC's device security guidance. See Information Security & Access Control.

Can you support our own audit or certification programmes?ASR-04

Yes We respond to customer audits and questionnaires as standard, and we already hold Cyber Essentials at company level, with Cyber Essentials Plus assessed on 4 August 2026 and the result awaited. Further engagement-specific certification — ISO 27001, acquired for a specific engagement at additional cost — can be stood up quickly: our documented, self-managed control set means the evidence base already exists.

As a Vanta partner, we also guide your platform through certification: SOC 2 Type II, ISO 27001, and GDPR readiness with Vanta — baseline preparation, the initial remediation sprint, and ongoing SDLC alignment — so security posture becomes a commercial differentiator rather than a blocker to enterprise deals. See the Vanta Compliance Partnership section of our Client Playbook.

How do you manage risk on an ongoing basis?ASR-05

Delivery and technical risks are tracked per engagement with mitigation owners (see our development workflow), supplier risk is reviewed periodically per Third-Party Supplier Management, and control drift in our own estate is caught by our quarterly control self-assessment, backed by continuous posture signals from Microsoft Defender for Cloud — so risk review is a standing activity, not an annual event.

Working with Assemblysoft

Will you sign an NDA before we share details?WRK-01

Yes We routinely sign NDAs ahead of scoping conversations, and our Master Services Agreement carries confidentiality obligations lasting five years beyond an engagement.

Will you enter into a Data Processing Agreement?WRK-02

Yes Where we process personal data on your behalf we contract on UK GDPR Article 28 terms, including sub-processor transparency and breach notification commitments. Assemblysoft is controller for the personal data it processes to run its own business, and processor for client personal data it accesses on your documented instructions. For many engagements we deliver software you deploy and operate yourself: where we hold no production credentials and develop against synthetic or anonymised data, we process none of your operational personal data and the processor role does not arise at all. The position applicable to an engagement is confirmed in the proposal — see Supplier & Sub-processor Management and breach notification commitments.

Do you use subcontractors or offshore teams?WRK-03

Delivery is led by our own UK-based team. Specialist contractors are engaged for peak demand under contract and NDA, through documented and regulated arrangements, operating within our access controls — see Third-Party Supplier Management and our Modern Slavery Statement. Engagement-specific staffing is always agreed with you.

Do you use AI tools in development, and is our data protected?WRK-04

AI-assisted engineering tools are used where they add value, inside the same controls as all our development: code is reviewed by our engineers before release, secrets never enter prompts, and customer data is not submitted to third-party AI services without your agreement. See Secure Development.

Where is your team based, and what are your support hours?WRK-05

We are based in Bournemouth, Dorset, operating UK business hours, with a distributed, remote-capable team — engagement-specific support arrangements are agreed in writing. Get in touch to discuss yours.

Can we audit you or request further evidence?WRK-06

Yes We respond to supplier questionnaires as part of onboarding, and evidence beyond these pages — policies, certificates, registers, test records — is provided on request, under NDA where appropriate. The Trust & Compliance Centre lists what's available.

What happens to our systems if Assemblysoft ceased trading?WRK-07

You would not be stranded: you own your data and deliverables, source code and infrastructure definitions are held in repositories transferable to you, hosting runs in Azure subscriptions that can move to your tenancy, and escrow arrangements can be agreed where required — see Data Ownership & Portability.

How does billing work?WRK-08

Transparent day rates billed weekly, with proposals generally pre-paid per phase under the Master Services Agreement — current ranges are published on our rate card.

Do you have a Modern Slavery Statement?WRK-09

Yes Published here, covering our operations and supply chain commitments.

Do you build to accessibility standards?WRK-10

WCAG guidance is applied to user-facing builds where the engagement requires it, alongside data-protection-by-design — see Certifications & Standards.

Is there a guide to how you run engagements end-to-end?WRK-11

Yes Our Client Playbook walks the full journey — discovery, development, DevOps and CI/CD, security & compliance baselines, penetration testing, cloud hosting and management, the Vanta compliance partnership, and the commercial framework — so you can see exactly how an engagement operates before you commit.

A question we haven't covered?

Send your questionnaire or question to hello@assemblysoft.com — we answer supplier due-diligence requests as part of onboarding, and good questions tend to end up on this page.

Back to the Trust & Compliance Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor