Compliance & accreditations

The standards we hold
ourselves to.

BS7858, BPSS, PSA Ireland, GDPR, ICO registration and ISO 27001 in flight. Compliance isn't a marketing tab for us — it's the product.

Compliance & accreditations

The standards we hold ourselves to.

BS7858:2019
British Standard for security screening
BPSS
Baseline Personnel Security Standard
PSA Ireland
Private Security Authority licensing
GDPR
UK GDPR + Data Protection Act 2018
ICO
Registered Z-A1 92847 · since 2021
ISO 27001
In progress · Stage 2 audit Q3 26
What we screen

Three standards.
One bureau.

BS7858, BPSS and PSA — fully managed end-to-end. We pick the third-party providers, we chase the references, we sign the certificates.

Standard · BSI 2019
Security industry

BS7858

The British Standard for screening individuals working where the safety of people, goods or property is paramount.

What's included
Identity verification (IDV)
5-year address history with gap reconciliation
5-year employment + education history
Two character references + two employment references
Credit & AML check (CreditSafe)
Self-declaration of unspent convictions
Secondary screener sign-off
Security & data handling

Personal data,
handled like it matters.

Passports, credit files, criminal disclosure, references — the most sensitive evidence a candidate has. We treat every byte like it could be ours.

01
UK-only data residency
All evidence stored in eu-west-2 (London). No cross-border transfer without explicit consent.
02
Encryption at rest + in transit
AES-256 at rest, TLS 1.3 in transit, document-level keys rotated every 30 days.
03
Per-check consent + revocation
Every check is opt-in, revocable, and logged in an immutable audit trail.
04
Redaction-aware reporting
Org reports show outcomes, not source documents. Auditors see what they need — nothing more.
05
Retention with purpose
Evidence purged 7 years after certificate issuance, per BS7858 retention guidance.
06
Penetration tested
External pentest annually. Bug bounty in place via HackerOne (private).

Need our compliance pack?

Send a quick note and we'll share our DPA, ISO progress letter, sub-processor list and security questionnaire.

Talk to complianceTalk to compliance