The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
The questions procurement, security, and data-protection teams most often ask us — answered directly, with links to the fuller statement behind each answer.
Yes A public summary is published in our Information Security & Access Control statement; the full policy is available to customers under NDA.
Yes We operate under UK GDPR and the Data Protection Act 2018, with a published Privacy Policy and ongoing regulatory monitoring described in Certifications & Standards.
Yes TLS on all public endpoints and encryption at rest across Azure storage and database services — see Hosting & Data Residency.
Yes Assemblysoft Ltd is Cyber Essentials certified — achieved 28 July 2026 for the whole organisation (certificate no. a7275954-4dd7-415e-99ba-e9d2ac193194, profile v3.3, via FIG Group / IASME; recertification due 28 July 2027). Verify the certificate on the IASME registry. We also operate documented cybersecurity controls (network controls, managed platform patching, dependency vulnerability monitoring, secrets management). See Certifications & Standards.
Cyber Essentials Plus — the independently audited assessment — was carried out on 4 August 2026 by our certification body Layer 7, against Test Specification v3.2. We are awaiting the result and will publish the certificate here once issued. Because we operate fully remotely over secure VPN — our estate and development environments are entirely cloud-based and protected, with no on-premise servers — the certification scope is clean and readily evidenced.
Yes Security scanning aligned to the OWASP Top 10 is performed on a regular basis, alongside continuous dependency and known-vulnerability monitoring and Azure platform-level scanning. Independent penetration tests are arranged per engagement where the solution warrants it — see Secure Development.
Yes HTTPS with valid TLS certificates is enforced on all hosted solutions — see Hosting & Data Residency.
Yes Azure automated backups with geo-redundant options; database services provide point-in-time restore as standard, giving daily-or-better granularity. See Business Continuity & DR.
Yes Recovery paths are exercised continuously through pipeline-driven redeployment, with restore verification per engagement and records available on request — see Business Continuity & DR.
Yes Microsoft Azure within the UK/EEA — UK South (UK) or West Europe (Netherlands, EEA), agreed per engagement (UK-only available on request) — so customer data at rest stays within the UK/EEA. Full detail and verification links in Hosting & Data Residency.
Yes Microsoft Azure is ISO/IEC 27001 certified — verifiable directly via the Microsoft Service Trust Portal.
Yes Hosted services carry Azure's financially backed SLAs — minimum 99.9%, up to 99.99% by service and tier — with engagement-specific service levels agreed in writing. See Hosting & Data Residency.
Yes Across cloud management, source control, CI/CD, and supporting services — named individual accounts only. See Information Security & Access Control.
Yes Azure Activity Log, Entra ID sign-in and audit logs, source-control history, and deployment pipeline logs together give an attributable trail of who changed what, and when — see Information Security & Access Control.
Yes Covering detection, containment, investigation, recovery, and post-incident review — summarised publicly in Incident Response & Breach Notification, with the full plan shared under NDA.
Without undue delay, and within 24 hours of confirming a breach affecting your systems or data — supporting your own UK GDPR obligations, including 72-hour ICO reporting where applicable. See Incident Response & Breach Notification.
Yes Both — built on geo-redundant backups, infrastructure-as-code redeployment, and Azure's region pairing within the same geography, plus business-level continuity for our own operations. See Business Continuity & DR.
24–48 hours for critical hosted services as standard; tighter objectives can be architected and agreed per engagement — see Business Continuity & DR.
Our practices align with ISO 27001 principles, and formal ISO 27001/9001 certification is held at the hosting layer by Microsoft Azure. We are a Microsoft Partner. The full position — including what we deliberately don't claim — is in Certifications & Standards.
Where a project demands it, ISO 27001 certification can be acquired at organisational level for a specific engagement, at additional cost — as can Cyber Essentials Plus. Our fully remote, secure-VPN operating model, with an entirely cloud-based and protected estate and development environment, keeps the certifiable scope small and well-defined.
Ongoing monitoring of UK GDPR, DPA 2018, PECR, and ICO guidance, feeding a periodic review of our policies — every compliance page shows its last review date. See Certifications & Standards.
Yes Security posture, data protection terms (Article 28, transfer safeguards), and commercial stability are assessed before adoption, with periodic re-review. See Third-Party Supplier Management.
Yes Maintained internally and shared with customers under NDA — publishing a complete supplier map would be useful to an attacker, so we don't. See Third-Party Supplier Management.
Yes OWASP-aligned development, protected-branch code review, secrets kept out of source, and dependency monitoring — see Secure Development & Change Management.
Yes Version-controlled, pipeline-driven releases with approval gates and rollback, plus advance notice of major updates and maintenance windows — see Secure Development & Change Management.
You do. Customer data and bespoke deliverables are the customer's property under our openly published Master Services Agreement — summarised in Data Ownership & Portability.
Yes Standard-format data exports (SQL, CSV, JSON), source and infrastructure handover, transition assistance, and secure deletion after confirmed handover — see Data Ownership & Portability.
Yes Professional indemnity and liability cover is in place and renewed annually. Evidence of insurance naming Assemblysoft — with insurer, cover and expiry — is provided directly to counterparties on request; see Insurance & Company Information for why we don't publish certificates.
Yes Certificate and coverage details provided directly on request — see Insurance & Company Information.
Incorporated in England & Wales in 2009 — over 15 years of trading, verifiable at Companies House (07098083).
Through a self-managed compliance programme: controls are self-assessed on a quarterly cycle against our documented policy set, with continuous posture signals between reviews from Microsoft Defender for Cloud secure score, Azure Policy, and Entra ID identity secure score. The supporting evidence — policies, registers, and dated logs — is maintained as a standing pack, shareable under NDA. See Certifications & Standards.
Yes Everyone with access to customer systems completes security and data protection awareness training on induction and at least annually — covering recognising and reporting a personal data breach, routing a data-subject rights request, controller and processor obligations, secure handling, and phishing awareness. Completion is recorded in our Data Protection Training & Awareness Record, which forms part of our UK GDPR framework and is available to customers on request under NDA — see Information Security & Access Control.
Because we operate fully remotely over secure VPN with an entirely cloud-based estate, device posture matters — so a security baseline (disk encryption, screen lock, OS patching, malware protection) is verified through quarterly device attestation against our documented baseline, following the NCSC's device security guidance. See Information Security & Access Control.
Yes We respond to customer audits and questionnaires as standard, and we already hold Cyber Essentials at company level, with Cyber Essentials Plus assessed on 4 August 2026 and the result awaited. Further engagement-specific certification — ISO 27001, acquired for a specific engagement at additional cost — can be stood up quickly: our documented, self-managed control set means the evidence base already exists.
As a Vanta partner, we also guide your platform through certification: SOC 2 Type II, ISO 27001, and GDPR readiness with Vanta — baseline preparation, the initial remediation sprint, and ongoing SDLC alignment — so security posture becomes a commercial differentiator rather than a blocker to enterprise deals. See the Vanta Compliance Partnership section of our Client Playbook.
Delivery and technical risks are tracked per engagement with mitigation owners (see our development workflow), supplier risk is reviewed periodically per Third-Party Supplier Management, and control drift in our own estate is caught by our quarterly control self-assessment, backed by continuous posture signals from Microsoft Defender for Cloud — so risk review is a standing activity, not an annual event.
Yes We routinely sign NDAs ahead of scoping conversations, and our Master Services Agreement carries confidentiality obligations lasting five years beyond an engagement.
Yes Where we process personal data on your behalf we contract on UK GDPR Article 28 terms, including sub-processor transparency and breach notification commitments. Assemblysoft is controller for the personal data it processes to run its own business, and processor for client personal data it accesses on your documented instructions. For many engagements we deliver software you deploy and operate yourself: where we hold no production credentials and develop against synthetic or anonymised data, we process none of your operational personal data and the processor role does not arise at all. The position applicable to an engagement is confirmed in the proposal — see Supplier & Sub-processor Management and breach notification commitments.
Delivery is led by our own UK-based team. Specialist contractors are engaged for peak demand under contract and NDA, through documented and regulated arrangements, operating within our access controls — see Third-Party Supplier Management and our Modern Slavery Statement. Engagement-specific staffing is always agreed with you.
AI-assisted engineering tools are used where they add value, inside the same controls as all our development: code is reviewed by our engineers before release, secrets never enter prompts, and customer data is not submitted to third-party AI services without your agreement. See Secure Development.
We are based in Bournemouth, Dorset, operating UK business hours, with a distributed, remote-capable team — engagement-specific support arrangements are agreed in writing. Get in touch to discuss yours.
Yes We respond to supplier questionnaires as part of onboarding, and evidence beyond these pages — policies, certificates, registers, test records — is provided on request, under NDA where appropriate. The Trust & Compliance Centre lists what's available.
You would not be stranded: you own your data and deliverables, source code and infrastructure definitions are held in repositories transferable to you, hosting runs in Azure subscriptions that can move to your tenancy, and escrow arrangements can be agreed where required — see Data Ownership & Portability.
Transparent day rates billed weekly, with proposals generally pre-paid per phase under the Master Services Agreement — current ranges are published on our rate card.
Yes Published here, covering our operations and supply chain commitments.
WCAG guidance is applied to user-facing builds where the engagement requires it, alongside data-protection-by-design — see Certifications & Standards.
Yes Our Client Playbook walks the full journey — discovery, development, DevOps and CI/CD, security & compliance baselines, penetration testing, cloud hosting and management, the Vanta compliance partnership, and the commercial framework — so you can see exactly how an engagement operates before you commit.
Send your questionnaire or question to hello@assemblysoft.com — we answer supplier due-diligence requests as part of onboarding, and good questions tend to end up on this page.