Home/Security & Compliance

Security built in, not bolted on

Everything we build runs inside your Microsoft 365 boundary, is protected by your controls, and follows a security discipline we apply to our own operations.

Protection

Controls on every engagement

The same measures protect a two week quick win and a multi year programme.

Microsoft-aligned

Our own operations run to Microsoft-aligned controls for access, change, incident and supplier management, and every project applies the same discipline.

Data stays in your tenant

Apps and flows run inside your Microsoft 365 subscription. We never copy business data to our own servers or outside your environment.

Least privilege access

Role based access control grants each person only what their job needs. Conditional access and multi factor authentication guard every entry point.

Audit trails

Every action is logged and reviewable: who opened what, who changed what and when. Management can see the full history of any record.

Secure development

We build to Microsoft platform security best practice: connectors scoped to what is needed, secrets in Azure Key Vault, no hard coded credentials.

Review before release

Changes move through review and test first. Nothing reaches users without a named owner and a documented change.

Governance

Structure that holds over time

Security is a daily habit, so we build the routines that keep it that way.

Separate environments

Development, test and production stay apart, with data in test anonymised or sampled. Production changes follow an approved release path.

Approvals before change

Administrator actions and solution changes require a second approval, so no single person can act alone in production.

Backup and recovery

SharePoint versioning, Power Automate backups and scheduled solution exports keep every asset restorable. Recovery steps are tested, not assumed.

Monitoring and alerts

Usage, failure and security signals are monitored, and the right people are alerted early, before a small issue becomes a visible one.

Your data, your rules

We process on your instructions

Client data belongs to the client. We process it only under your instructions and a data processing agreement, and we store nothing outside your tenant. Our policies set out the details.

Ask us anything

Security questions? Talk to the team.

Whether you need our certification documents, a data processing agreement or a threat model for a specific project, we will share everything you ask for.