Customer Security Document
How amarti protects client information: a summary for clients and prospective clients.
| Document control | |
|---|---|
| Reference | AM-CSD-001 |
| Version | 1.0 |
| Classification | Public |
| Owner | James Peachey, Co-founder |
| Approved by | James Peachey, Co-founder, on 2 June 2026 |
| Next review | 2 June 2027 |
| Applies to | Clients, prospective clients and their assurance teams |
| Standards alignment | ISO/IEC 27001:2022; ISO 9001:2015; Cyber Essentials; UK GDPR |
1. About this document
Section titled “1. About this document”This document answers the security questions clients ask us most often, in one place.
It is written for procurement, security and vendor assurance teams assessing amarti as a supplier. It summarises our certifications, our controls and our commitments. It is a summary, not the whole management system. The underlying policies, our Statement of Applicability and our certificates are available on request, under a non-disclosure agreement where appropriate.
If your assessment needs something this document does not cover, ask. We would rather answer a direct question than have you infer an answer.
2. About amarti
Section titled “2. About amarti”| Legal entity | amarti Ltd, registered in England and Wales, company number 12543976 |
| Registered office | 61 Westway, Caterham, England, CR3 5TQ |
| Services | Data strategy, data governance, data architecture, data engineering, data visualisation, cloud and platform engineering, operational transformation and delivery |
| Delivery model | UK-based, remote-first, delivered by employed consultants and vetted associates |
| Security contact | Amardeep Sirha, Co-founder, amardeep@amarti.io |
| Commercial contact | Ben Alexander, Co-founder, ben@amarti.io |
| Accountable executive | James Peachey, Co-founder, james@amarti.io |
3. Certifications and assurance
Section titled “3. Certifications and assurance”| Certification | Scope | Status |
|---|---|---|
| ISO/IEC 27001:2022 | Information security management system covering the provision of software and data engineering consultancy services | Certified; subject to annual surveillance audit by an accredited certification body |
| ISO 9001:2015 | Quality management system covering the same scope | Certified; subject to annual surveillance audit |
| Cyber Essentials | amarti corporate IT estate | Certified; renewed annually |
Certificates are available on request and our Cyber Essentials certificate is publicly verifiable. We are monitoring the ISO 9001:2026 revision, published in September 2026 with a three-year transition, and will transition within that window.
4. Governance and people
Section titled “4. Governance and people”- Accountability for information security sits with James Peachey, Co-founder. Amardeep Sirha, Co-founder, acts as Information Security Manager and runs the ISMS day to day.
- A documented policy framework covers information security, access control, remote working, mobile devices, information transfer, email, equipment disposal, incident management and business continuity. Policies are reviewed at least annually and re-acknowledged by all personnel annually.
- All personnel are screened before access is granted (identity, right to work and references), with additional screening where a client requires it. We can accommodate BPSS, DBS or client-specific vetting on request.
- Everyone signs confidentiality obligations that survive the end of their employment or engagement.
- Security awareness training is completed at induction and refreshed at least annually, with phishing awareness included.
- A formal disciplinary process applies to information security violations, satisfying ISO/IEC 27001:2022 control A.6.4.
- Associates and subcontractors are contractually bound to the same standards as employees.
5. Technical controls
Section titled “5. Technical controls”| Area | Control |
|---|---|
| Identity and access | Least privilege and deny-by-default. Multi-factor authentication enforced on all business systems and all administrative access. Separate named administrative accounts. Access reviewed every six months, and quarterly for privileged and client access. Leavers deprovisioned by the end of their last working day. |
| Endpoints | Company-issued devices only for client work. Full-disk encryption, centrally enforced device management, endpoint protection, automatic screen lock, host firewall. Personal devices may not access client data or systems. |
| Patching | Supported operating systems and applications. Critical and high-severity vulnerabilities remediated within 14 days. |
| Networks | Company VPN mandatory on any network we do not control. Public Wi-Fi permitted only over VPN. |
| Data in transit and at rest | TLS 1.2 or above for data in transit. Encryption at rest on endpoints and in cloud storage. |
| Secrets | Credentials held in a managed secret store or password manager. Secrets are never committed to source control; repositories are configured with secret scanning. |
| Logging | Logging enabled across business systems and cloud environments, retained for a minimum of 90 days. |
| Change control | Version control for all code and configuration. Peer review and an approved change record required before any production change. |
| Test data | Production personal data is never used in non-production environments. Synthetic or properly anonymised data is used instead. |
| Backup | Automated, encrypted backup of business-critical data, restore-tested at least annually. |
6. How we handle your data
Section titled “6. How we handle your data”- Where we process personal data on your behalf we act as your processor, on your documented instructions only, under a written agreement meeting Article 28 of the UK GDPR.
- Client data is classified as Client Confidential and may be stored only in locations approved for the engagement, normally your own environment. We prefer to work in your tenancy rather than take copies.
- Client data is not used for any amarti purpose, is not used to train any model, and is not pasted into AI or online tools that have not been approved.
- Data residency is UK or EEA by default. Any transfer outside the UK requires your documented instruction and an appropriate Chapter V safeguard.
- Access to your environment is requested through your process and approved by your named approver. amarti does not self-provision.
- At the end of an engagement, access is revoked and confirmed to you in writing, and any client data held by amarti is returned or securely destroyed to a documented standard, with a certificate where you require one.
7. Incidents, continuity and supply chain
Section titled “7. Incidents, continuity and supply chain”Incident response
Section titled “Incident response”- A documented incident management procedure operates 24 hours a day, led by the Incident Manager, with severity-based triage targets: 30 minutes for a critical incident.
- We notify affected clients of any incident involving their data or service. Our default is within 24 hours of confirming client impact, or sooner where your contract requires it.
- Where amarti is a controller and a personal data breach presents a risk to individuals, we notify the ICO within 72 hours. Where we are your processor, we notify you without undue delay and support your notification.
- A blameless post-incident review is held for every critical and high-severity incident, and the report is shared with affected clients.
Business continuity
Section titled “Business continuity”- A documented Business Continuity Plan covers loss of premises, connectivity, systems, key people and suppliers.
- Our remote-first model means we have no single point of physical failure. Business-critical data is held in resilient cloud services, not on individual devices.
- The plan is tested at least annually and after any material change. Test reports, including recovery times achieved against objectives, are available to clients on request.
Supply chain
Section titled “Supply chain”- Suppliers are tiered by risk, assessed before engagement and reviewed annually where they touch client data or our delivery capability.
- Contracts with critical suppliers require security incident notification within 24 hours, Article 28 data protection terms, change notification and exit assistance.
- A current list of the sub-processors we use is available on request.
8. Your rights as a client
Section titled “8. Your rights as a client”- Evidence. You may request our certificates, policy summaries, Statement of Applicability, penetration test summaries and business continuity test reports.
- Assurance questionnaires. We complete client security questionnaires as part of onboarding and periodic reassessment.
- Audit. We accommodate a reasonable annual audit or assessment where your contract provides for it, on reasonable notice.
- Notification of change. We tell you in advance of any material change to how your data is handled, including a change of sub-processor or hosting region.
- Named contacts. You have a named security contact and a named commercial contact, listed in section 2.
- Escalation. Any concern can be escalated directly to James Peachey, Co-founder, at james@amarti.io. Complaints are handled under our published Customer Complaint Procedure (AM-PRO-001).
This document is reviewed at least annually and whenever our certifications, controls or delivery model change materially.
Questions about this document
Section titled “Questions about this document”The first point of contact for this document is James Peachey (james@amarti.io). Where a query is best handled by another member of the leadership team, it will be routed as follows:
| Contact | Area | |
|---|---|---|
| Amardeep Sirha, Co-founder | Technical, information security and platform matters | amardeep@amarti.io |
| Ben Alexander, Co-founder | Sales, client engagement and consultant operations | ben@amarti.io |