Skip to content

    Customer Security Document

    How amarti protects client information: a summary for clients and prospective clients.

    Document control
    Reference AM-CSD-001
    Version 1.0
    Classification Public
    Owner James Peachey, Co-founder
    Approved by James Peachey, Co-founder, on 2 June 2026
    Next review 2 June 2027
    Applies to Clients, prospective clients and their assurance teams
    Standards alignment ISO/IEC 27001:2022; ISO 9001:2015; Cyber Essentials; UK GDPR

    This document answers the security questions clients ask us most often, in one place.

    It is written for procurement, security and vendor assurance teams assessing amarti as a supplier. It summarises our certifications, our controls and our commitments. It is a summary, not the whole management system. The underlying policies, our Statement of Applicability and our certificates are available on request, under a non-disclosure agreement where appropriate.

    If your assessment needs something this document does not cover, ask. We would rather answer a direct question than have you infer an answer.

    Legal entity amarti Ltd, registered in England and Wales, company number 12543976
    Registered office 61 Westway, Caterham, England, CR3 5TQ
    Services Data strategy, data governance, data architecture, data engineering, data visualisation, cloud and platform engineering, operational transformation and delivery
    Delivery model UK-based, remote-first, delivered by employed consultants and vetted associates
    Security contact Amardeep Sirha, Co-founder, amardeep@amarti.io
    Commercial contact Ben Alexander, Co-founder, ben@amarti.io
    Accountable executive James Peachey, Co-founder, james@amarti.io
    Certification Scope Status
    ISO/IEC 27001:2022 Information security management system covering the provision of software and data engineering consultancy services Certified; subject to annual surveillance audit by an accredited certification body
    ISO 9001:2015 Quality management system covering the same scope Certified; subject to annual surveillance audit
    Cyber Essentials amarti corporate IT estate Certified; renewed annually

    Certificates are available on request and our Cyber Essentials certificate is publicly verifiable. We are monitoring the ISO 9001:2026 revision, published in September 2026 with a three-year transition, and will transition within that window.

    • Accountability for information security sits with James Peachey, Co-founder. Amardeep Sirha, Co-founder, acts as Information Security Manager and runs the ISMS day to day.
    • A documented policy framework covers information security, access control, remote working, mobile devices, information transfer, email, equipment disposal, incident management and business continuity. Policies are reviewed at least annually and re-acknowledged by all personnel annually.
    • All personnel are screened before access is granted (identity, right to work and references), with additional screening where a client requires it. We can accommodate BPSS, DBS or client-specific vetting on request.
    • Everyone signs confidentiality obligations that survive the end of their employment or engagement.
    • Security awareness training is completed at induction and refreshed at least annually, with phishing awareness included.
    • A formal disciplinary process applies to information security violations, satisfying ISO/IEC 27001:2022 control A.6.4.
    • Associates and subcontractors are contractually bound to the same standards as employees.
    Area Control
    Identity and access Least privilege and deny-by-default. Multi-factor authentication enforced on all business systems and all administrative access. Separate named administrative accounts. Access reviewed every six months, and quarterly for privileged and client access. Leavers deprovisioned by the end of their last working day.
    Endpoints Company-issued devices only for client work. Full-disk encryption, centrally enforced device management, endpoint protection, automatic screen lock, host firewall. Personal devices may not access client data or systems.
    Patching Supported operating systems and applications. Critical and high-severity vulnerabilities remediated within 14 days.
    Networks Company VPN mandatory on any network we do not control. Public Wi-Fi permitted only over VPN.
    Data in transit and at rest TLS 1.2 or above for data in transit. Encryption at rest on endpoints and in cloud storage.
    Secrets Credentials held in a managed secret store or password manager. Secrets are never committed to source control; repositories are configured with secret scanning.
    Logging Logging enabled across business systems and cloud environments, retained for a minimum of 90 days.
    Change control Version control for all code and configuration. Peer review and an approved change record required before any production change.
    Test data Production personal data is never used in non-production environments. Synthetic or properly anonymised data is used instead.
    Backup Automated, encrypted backup of business-critical data, restore-tested at least annually.
    • Where we process personal data on your behalf we act as your processor, on your documented instructions only, under a written agreement meeting Article 28 of the UK GDPR.
    • Client data is classified as Client Confidential and may be stored only in locations approved for the engagement, normally your own environment. We prefer to work in your tenancy rather than take copies.
    • Client data is not used for any amarti purpose, is not used to train any model, and is not pasted into AI or online tools that have not been approved.
    • Data residency is UK or EEA by default. Any transfer outside the UK requires your documented instruction and an appropriate Chapter V safeguard.
    • Access to your environment is requested through your process and approved by your named approver. amarti does not self-provision.
    • At the end of an engagement, access is revoked and confirmed to you in writing, and any client data held by amarti is returned or securely destroyed to a documented standard, with a certificate where you require one.
    • A documented incident management procedure operates 24 hours a day, led by the Incident Manager, with severity-based triage targets: 30 minutes for a critical incident.
    • We notify affected clients of any incident involving their data or service. Our default is within 24 hours of confirming client impact, or sooner where your contract requires it.
    • Where amarti is a controller and a personal data breach presents a risk to individuals, we notify the ICO within 72 hours. Where we are your processor, we notify you without undue delay and support your notification.
    • A blameless post-incident review is held for every critical and high-severity incident, and the report is shared with affected clients.
    • A documented Business Continuity Plan covers loss of premises, connectivity, systems, key people and suppliers.
    • Our remote-first model means we have no single point of physical failure. Business-critical data is held in resilient cloud services, not on individual devices.
    • The plan is tested at least annually and after any material change. Test reports, including recovery times achieved against objectives, are available to clients on request.
    • Suppliers are tiered by risk, assessed before engagement and reviewed annually where they touch client data or our delivery capability.
    • Contracts with critical suppliers require security incident notification within 24 hours, Article 28 data protection terms, change notification and exit assistance.
    • A current list of the sub-processors we use is available on request.
    • Evidence. You may request our certificates, policy summaries, Statement of Applicability, penetration test summaries and business continuity test reports.
    • Assurance questionnaires. We complete client security questionnaires as part of onboarding and periodic reassessment.
    • Audit. We accommodate a reasonable annual audit or assessment where your contract provides for it, on reasonable notice.
    • Notification of change. We tell you in advance of any material change to how your data is handled, including a change of sub-processor or hosting region.
    • Named contacts. You have a named security contact and a named commercial contact, listed in section 2.
    • Escalation. Any concern can be escalated directly to James Peachey, Co-founder, at james@amarti.io. Complaints are handled under our published Customer Complaint Procedure (AM-PRO-001).

    This document is reviewed at least annually and whenever our certifications, controls or delivery model change materially.

    The first point of contact for this document is James Peachey (james@amarti.io). Where a query is best handled by another member of the leadership team, it will be routed as follows:

    Contact Area Email
    Amardeep Sirha, Co-founder Technical, information security and platform matters amardeep@amarti.io
    Ben Alexander, Co-founder Sales, client engagement and consultant operations ben@amarti.io