Last updated 4 August 2026 · Version 2.0
Security.
We work inside our clients’ environments, with credentials to their systems and access to their data. That access is the most sensitive thing we hold, and our security programme is built around it.
Our programme
We operate an information security management system aligned to ISO/IEC 27001, covering information security policy, access control, cryptography, cloud security, secure development, supplier management, incident response, business continuity, and acceptable use. The policy set is maintained as controlled documents with named owners and an annual review cycle.
We are aligned to the standard and working toward certification. We say aligned rather than certified because we do not yet hold a certificate, and we would rather you learn that from us than from an auditor.
Access control
Least privilege by default. Access to client environments is requested, approved, time-bound where the client’s systems support it, and revoked when an engagement ends or a team member’s role changes.
Multi-factor authentication is required on all corporate accounts and on all access to client systems. Administrative access is separated from day-to-day accounts. Credentials are held in a managed secrets store, never in code, configuration files, or messages.
Data handling
Encryption in transit using TLS 1.2 or above, and at rest using platform-managed keys.
Client data stays in the client’s environment wherever the engagement allows it. Our strong preference is to build in your cloud rather than move your data into ours. Where we must hold client data, it is segregated per client, encrypted, kept only as long as the engagement requires, and deleted on request or at engagement close with confirmation provided.
Production data is not used in development or test environments without the client’s written approval and appropriate masking.
Infrastructure
Our systems run on AWS, using isolated accounts per environment, private networking by default, and regional deployment matched to client data residency requirements. Infrastructure is defined as code, and changes go through review.
Secure development
Version control with mandatory peer review before merge. Automated dependency and secret scanning in the pipeline. Static analysis on application code. Separate development, staging and production environments with no shared credentials.
Monitoring and incident response
Centralised logging and alerting across infrastructure and applications. We maintain a documented incident response plan with defined severity levels, named responders, and communication paths.
Where an incident affects client data, we notify the affected client without undue delay and within the timeframes set in the engagement contract, so the client can meet its own regulatory obligations. Notification covers what we know, what we do not yet know, and what we are doing about it.
People
Every team member is subject to a written confidentiality agreement, background screening appropriate to their role and jurisdiction, and security awareness training at onboarding and annually. Access is provisioned through a documented starter process and revoked the same day someone leaves.
Suppliers
We keep the third-party estate deliberately small. Every supplier with access to personal information is assessed before onboarding, bound by a data processing agreement, and reviewed periodically. Our current sub-processor list is provided on request and forms part of every client data processing agreement, with advance notice of any change.
Business continuity
Infrastructure and code are backed up with defined recovery objectives, and restores are tested. Client deliverables are documented and handed over throughout an engagement rather than at the end, so no part of a client’s system depends on our continued availability.
Reporting a vulnerability
If you believe you have found a security issue in anything we operate, email security@augmentedx.ai. We will acknowledge within two business days. We will not pursue legal action against anyone who reports a genuine issue in good faith, gives us reasonable time to fix it, and does not access or modify data beyond what is needed to demonstrate the problem.
For your security review
Our policy set, architecture documentation, sub-processor list, and completed security questionnaires are available under NDA. Email security@augmentedx.ai and tell us which framework you assess against, and we will map to it rather than sending a document that answers different questions.