Security & Compliance
Your clients' data, under controls you can audit
Every firm that outsources has to answer to its own clients for how their data is handled. This page exists so you can answer that question with specifics, and so your vendor due-diligence process has somewhere to start.
Controls
The control set we operate
We are happy to complete your vendor questionnaire in full and to walk your IT or risk lead through any of the controls below.
Least-privilege access
Role-based access to client data, provisioned per engagement and revoked on completion.
Controlled workstations
Centrally managed workstations with external storage devices disabled.
Secured facility
Access-controlled office floor; no client work performed from home.
Encrypted transfer
Client data moves only over encrypted channels and approved portals.
Confidentiality agreements
Signed NDAs covering the firm and every individual assigned to your engagements.
Restricted printing & egress
Printing restricted and outbound channels controlled on work networks.
Monitored networks
Firewalled, segmented networks with browsing restrictions on delivery floors.
Backup & continuity
Automated backup with documented recovery procedures.
Due Diligence
Running a vendor assessment on us?
Send your security questionnaire, DPA or third-party risk assessment and we will complete it. If you need a call with whoever owns security on our side, ask for it.
Questions about how we handle your data?
We would rather answer them properly before an engagement than be asked about them during one.
