Information Security Policy
The Company's business concerns the governance of AI usage. Meeting the standard we ask of customers is treated as a precondition of that business.
Effective: September 2026
1. Purpose
This policy exists to protect the information assets the Company handles, and thereby to sustain its operations and the trust of its customers.
2. Scope
This policy applies to all officers and employees, and to all information assets the Company handles.
3. Authorisation and access
Access to information assets is granted to the minimum extent required by the work. Granted access is reviewed periodically and removed promptly once no longer necessary.
4. Records and audit
Significant operations and changes of authority are recorded and kept verifiable after the fact. Records are retained in a form resistant to alteration.
5. Use of generative AI
Where the Company uses generative AI in its operations or products, it verifies before deployment the impact of incorrect outputs, whether human review is required, how outputs are evaluated, defences against prompt injection, and the preservation and reproducibility of logs.
The Company does not, at its own discretion, submit customer information to external AI services for training.
6. Incident response
On becoming aware of an information security event, the Company prioritises identifying the scope of impact, preventing escalation, and reporting to those affected. Causes are analysed afterwards and preventive measures recorded.
7. Review
This policy is reviewed periodically in response to changes in the business and in the threat environment.