Legal / Security
Security Information
How we protect information, described at a high level.
Our approach
We apply technical and organisational measures appropriate to the service, the systems involved and the sensitivity of the data. No method of transmission or storage is completely secure.
Controls we operate
- Encryption of data in transit, and at rest where appropriate.
- Role-based access and least-privilege principles.
- Authentication controls, with multi-factor authentication where the risk assessment requires it.
- Logging and monitoring of relevant security events.
- Backup and recovery processes proportionate to the service.
- Supplier and subprocessor due diligence and contractual controls.
- Incident-response and escalation procedures.