Everything your security review is about to ask for.
Gathered in one place so vendor onboarding takes days rather than months. If something you need is not here, ask — we would rather send it than have you infer it.
Six control domains.
Described at the level a reviewer can assess rather than the level a brochure can assert.
Information security management
- ISMS aligned to ISO/IEC 27001 with an annual management review
- SOC 2 Type II control coverage across production environments
- Documented risk register reviewed quarterly by the leadership group
- Security policies acknowledged by every employee at onboarding and annually
Access control
- Single sign-on with mandatory phishing-resistant multi-factor authentication
- Least privilege by default; production access is time-boxed and justified
- Quarterly access reviews with automatic revocation on role change or exit
- All privileged actions logged to an append-only audit trail
Infrastructure & data
- TLS 1.2+ in transit, AES-256 at rest, keys managed in a dedicated KMS
- Segregated development, staging and production environments
- Infrastructure defined as code, peer-reviewed, with no manual production changes
- Backups encrypted, replicated cross-region, and restore-tested quarterly
Secure development
- Mandatory peer review; no direct commits to protected branches
- SAST, dependency and secret scanning enforced in continuous integration
- Threat modelling for every new service or material architecture change
- Annual independent penetration testing with remediation tracked to closure
Monitoring & response
- Centralised logging with alerting on anomalous access and error-budget burn
- 24×7 on-call rotation with a documented escalation path
- Incident response plan tested at least annually with a tabletop exercise
- Post-incident reviews shared with affected clients within 10 working days
People
- Background verification appropriate to role and jurisdiction before start
- Security and privacy training at onboarding and annually thereafter
- Confidentiality obligations that survive the end of employment
- Documented joiner, mover and leaver process with asset and access recovery
Where we stand, stated precisely.
We distinguish between 'certified', 'aligned' and 'in progress', because conflating them is how vendors lose trust at exactly the wrong moment.
ISO/IEC 27001
Aligned; certification programme in progress
Full ISMS operating with documented Statement of Applicability.
SOC 2 Type II
Control coverage in place
Security, availability and confidentiality criteria across production.
UK GDPR & EU GDPR
Compliant
DPA available with IDTA and SCCs annexed. Article 30 records maintained.
DPDP Act 2023 (India)
Compliant
Consent framework, grievance officer and data-principal rights implemented.
PCI DSS
Aligned (SAQ-A scope)
Card data handled entirely by certified processors; we never store PANs.
WCAG 2.2 Level AA
Substantially conformant
Independently audited; see the Accessibility Statement for exceptions.
Service levels.
Contractual where a signed SLA is in place, and targets otherwise.
- Production uptime commitment
- 99.9% monthly, with service credits
- P1 incident acknowledgement
- 15 minutes, 24×7
- P1 target resolution
- 4 hours
- P2 acknowledgement
- 1 business hour
- Breach notification to clients
- Within 24 hours of confirmation
- Regulator notification
- Within 72 hours where required
- Data subject request acknowledgement
- 72 hours
- Sub-processor change notice
- 30 days
What we can send you.
Most of it goes out the same day. NDA items need a mutual NDA in place first, which we can turn around in 24 hours.
- Data Processing Agreement (with SCCs & IDTA)On request
- Security whitepaperUnder NDA
- Penetration test executive summaryUnder NDA
- SOC 2 Type II reportUnder NDA
- Certificate of insuranceOn request
- Business continuity & DR plan summaryUnder NDA
- Standard security questionnaire (CAIQ / SIG Lite)Pre-completed
- Sub-processor listPublished
Found something? Tell us.
We will not pursue legal action against researchers acting in good faith within this policy.
Report vulnerabilities to security@anithrasolutions.com. Include the affected asset, reproduction steps and impact. A PGP key is available on request.
Our commitments
- Acknowledgement within 1 business day
- Triage and severity assessment within 5 days
- Regular updates until resolution
- Public credit if you would like it
Please do not
- Access, modify or exfiltrate other people's data
- Run denial-of-service or volumetric tests
- Use social engineering against our staff or clients
- Publish before we have had a chance to fix it
Related reading: Privacy Policy, Sub-processors and Accessibility Statement.
Need something for your vendor review?
Send us the questionnaire. We keep pre-completed CAIQ and SIG Lite responses on file and can usually return a bespoke one within three business days.
Prefer email? sales@anithrasolutions.com · We reply within one business day