ServicesProductsHow we buildWorkSecurityPartnersStart a project
SECURITY

Security anddata protection.

How we protect client data and the products we run. If something here doesn't match what your security team needs, email us: we'd rather answer questions than have you guess.

How we handle your data

We work under UK GDPR. On client projects we act as your processor, only access the data we need to do the work, and can sign a data processing agreement on request. A list of our sub-processors is available on request.

Secure development

  • Every change is reviewed by a second engineer before it merges.
  • Automated tests run on every change and gate the merge.
  • Dependency and secret scanning run in our CI pipeline.
  • Development, staging and production environments are kept separate.

Infrastructure

  • Data is encrypted in transit with TLS and encrypted at rest.
  • Infrastructure is defined as code, so environments are repeatable and reviewable.
  • Backups and monitoring are set up as part of each production release.
  • Hosting region is agreed with you per project.

People and access

  • We sign an NDA before any roadmap or codebase discussion.
  • Access follows least privilege, with multi-factor authentication on our core systems.
  • Access to your systems is removed when an engagement ends.

If something goes wrong

If we detect an incident that affects your data, we tell you without undue delay and work with you on containment, investigation and any regulator notification.

Report a vulnerability

We welcome good-faith reports. Email security@exactiv.co.uk with the details and how to reproduce it. Our contact details are also published in security.txt.

Certifications

We are working towards Cyber Essentials certification. We'll list certificates here once they're issued, and we won't claim any we don't hold.

Need something specific?

Email security@exactiv.co.uk for our data processing agreement, sub-processor list, or to have us complete a security questionnaire.