Skip to main content
← All capabilities

Security & Governance

Review access, data handling and system changes.

Every business holds information that should stay private: customer details, pricing, staff records, health or financial information. We build access control, audit trails and careful data handling into the systems we make, and we look over systems you already run to show where access, data and change could be tightened.

Send an enquiry

Illustrative example

Access follows responsibility.

Start with what each role needs to do. Check those permissions on the server, including when a person changes role or leaves.

Example: access to a service record
RoleReadEditApprove
TechnicianAssigned jobsOwn notes—
SupervisorTeam jobsTeam recordsWithin scope
ReviewerAgreed records——
Test the boundary: can a technician open another team's job by changing its URL? Hiding a button is not an access control.

When this helps

  • Everyone can see everything.

    Staff can open records their role doesn't need, because permissions were never set up.

  • Former staff still have access.

    Accounts stay open after people leave, and shared logins make it hard to tell who's still using them.

  • Nobody can say who changed a record.

    A figure or a document changes and there's no history of who did it, or why.

What a review can cover

  • Role-based access

    Permissions set by role, designed so each person reaches what their work needs and no more.

  • Separation between organisations

    Where several businesses or branches share a system, row-level security in the database is designed to keep each one's records apart.

  • Audit trails

    A record of who created or changed the records that matter, and when.

  • Encryption and key handling

    Information encrypted in transit and at rest, with a separate encryption key for each organisation where the data calls for it.

  • Sign-in controls

    Multi-factor authentication, session limits, and a process for adding and removing people that leaves a record.

  • Reviews of existing systems

    A structured look at how a system you already run handles access, data and change, with findings ranked by risk and what to fix first.

How we approach it

  1. 1.

    Find what needs protecting

    We list the information the system holds, who needs it and why, and the rules that apply to it.

  2. 2.

    Set access by role

    Each role gets the least access its work needs. Anything broader is a decision you make on purpose and write down.

  3. 3.

    Record what matters

    We agree which actions need an audit trail, and record them in the database alongside the data itself.

  4. 4.

    Check it, and keep checking

    We write automated tests that check each role reaches only what it should. Access is reviewed at handover and, under a support agreement, as your team changes.

The project process →

What you receive

An access model
Each role, what it can see and change, and why.
An access register
Every account and permission, who holds it, and when it was granted.
A data map
Where your information is stored and processed, and the country each service is in.
Findings, ranked by risk
For a review of an existing system: what we found, why it matters, and what to fix first.
What we need from you
  • For a review, read-only access to the systems in scope, through their own invite or permission settings.
  • The roles in your business, and what each one needs to do.
  • Someone who can decide what each role should be able to see.
  • Any security questionnaires or contract terms you've been asked to meet.

Before committing

Scope depends on the systems, data and access available. These are the constraints we discuss with you.

Risks we check
  • Shared logins, and accounts nobody owns.
  • Access that outlived the person or the project.
  • Records that can be changed without leaving a trace.
  • Personal information held in more places than it needs to be.
  • Services storing or processing your data in countries your agreement doesn't name.
What we won't recommend
  • Controls so strict that staff route around them. A rule people work around doesn't protect much.
  • Buying a security product before the basics of access and records are in place.
Where we're not the right fit
  • We don't certify systems or sign off that they meet a standard. A formal certificate comes from a certification body.
  • We don't carry out penetration testing. Where one is needed, we'll say so and help you brief a firm that does.
  • A review describes what we found at the time we looked. It can't show that a system is secure, only where it isn't.

Questions about security & governance

Can you tell us whether our system is secure?

We can tell you where it isn't, as far as we could see. A review shows what we found at the time, ranked by risk, with what to fix first.

Will you need access to our systems?

Read-only access to the systems in scope, granted through each system's own invite or permission settings. It goes on the access register and is removed when the work ends.

Where will our information be stored?

Your agreement names every service that stores or processes your information and the country it's in, including any overseas.

Can you help with a security questionnaire from a client or insurer?

We can help you answer it accurately from how your systems work today, and flag the questions where the honest answer is "not yet".

Do we need this if we're a small business?

Most businesses hold information someone would misuse if they could. The controls scale down: a few roles, a clear record of changes, and knowing where your data lives.

Have a project in mind?

Send a short description of the problem and the systems involved. We will review fit and availability.

Send an enquiry