Proof / Security + continuity

Turn assurance into evidence you can inspect.

Security is not a page of reassuring words. It is a set of controls, ownership decisions and verification duties configured to the system, data and consequences involved.

Read the delivery standard
Assurance layersScope first
01Engineering baselineDesign
02Engagement controlsConfigure
03Contracted assuranceCommit
04Independent assessmentVerify
Claims stop where evidence stops
Fitted, not borrowed

Real assurance is fitted to the work — and written into the contract.

This is how we structure security and continuity for new work. The controls, evidence, standards and independent checks that apply to your system go into the engagement scope and contract — where they are enforceable, not decorative.

And where something hasn’t yet been evidenced for your scope, we say so plainly. We’d rather earn confidence than borrow it.

Four assurance layers

Separate design intent from verified fact.

A mature engagement distinguishes what the team ordinarily considers, what the specific system needs, what the contract requires and what an independent party has actually tested.

01 / Baseline

Engineering questions

Identity, access, data sensitivity, logging, backup, dependencies and failure recovery are surfaced during design.

02 / Engagement

Configured controls

The actual permissions, encryption, audit, retention, recovery and operational measures are selected for this system.

03 / Contract

Assurance commitments

Evidence, response duties, service expectations and handover obligations become enforceable only when stated in the agreement.

04 / Independent

External verification

Penetration tests, compliance assessments and other independent reviews are commissioned where the risk and buyer require them.

05 / Ownership

Client control

Applicable source, accounts, data and exports remain reachable by the organization, subject to the agreed architecture and licensing.

06 / Honesty

No borrowed badges

What we claim, we can show. If a certification, audit or test hasn’t been done for your scope, we tell you — and price the doing of it.

Risk-shaped delivery

The consequence changes the instrument.

A public information site, a payment flow and a care platform do not receive the same assurance plan. We map the consequence first, then select and prove the controls.

01

Classify

Identify sensitive data, critical operations, users, jurisdictions and plausible harm.

02

Control

Assign technical, operational and contractual measures to the actual risks.

03

Evidence

Define what must be demonstrated, logged, restored, reviewed or independently tested.

04

Operate

Name monitoring, incident, maintenance, escalation and departure responsibilities.

Buyer’s control matrix

Questions worth putting into the agreement.

The answer may be “included,” “not applicable,” “client-owned” or “separately commissioned.” What matters is that the answer is deliberate and testable.

Identity + access
Ask about

User roles, least privilege, administrative access, joiner/leaver handling and credential ownership.

Possible evidence

Role matrix, access review, account inventory and demonstration of refused paths.

Data protection
Ask about

Data classification, encryption in transit and at rest, retention, export and deletion boundaries.

Possible evidence

Data map, configuration record, tested export and documented retention decision.

Traceability
Ask about

Audit events, operational logs, alert ownership and the ability to reconstruct a material action.

Possible evidence

Event catalogue, sample audit trail, alert path and access restrictions.

Recovery
Ask about

Backup scope, restoration objective, restore ownership, dependency failure and continuity mode.

Possible evidence

Backup policy, completed restore exercise, recovery runbook and known recovery limits.

Vulnerability
Ask about

Dependency updates, code review, scanning, remediation ownership and independent testing threshold.

Possible evidence

Review trail, scan output, remediation log or separately commissioned penetration-test report.

Incident response
Ask about

Detection, escalation, containment, notification, evidence preservation and post-incident learning.

Possible evidence

Named response roles, contact path, tabletop record and contractual notification terms.

Continuity beyond uptime

Keep the organization able to act.

01

Repository and account control

Decide who owns source, cloud, domain, database, communications, payments and third-party services.

02

Recoverable knowledge

Keep architecture, deployment, known risks and operating instructions close to the evolving system.

03

Human continuity

Name a primary, a second owner where warranted, an escalation path and the decisions the client must retain.

04

Departure without captivity

Agree the data export, credential transfer, documentation and transition assistance required for another team to continue.

Reporting a concern

A real channel, with real people behind it.

Security concerns on an engagement go to the named contact and escalation route in your agreement — a monitored channel with a response process behind it, agreed before the work begins.

When we publish a public reporting address, it will carry the same standard: monitored, answered, and worth the promise.

Put consequence on the table

Tell us what cannot be allowed to fail silently.

Review company facts