Trust through accurate boundaries

Security & Confidentiality

Understand what the public website does today, what belongs in the planned production case environment, and why evidence should never be sent through a public enquiry form.

Current controls and planned production architecture are labelled separately. No unverified security certification or provider claim is made.

Public websiteNo evidence upload

The estimator and enquiry form request non-sensitive scoping information only.

Large evidenceControlled media route

Large or structured sets may receive encrypted physical-media instructions after activation.

Final handoverEncrypted USB

The designed workflow uses tracked delivery with access details supplied separately.

Currently implemented

The public website is separated from customer evidence

The current public site provides service information, a workload estimator and a non-sensitive initial-review form prototype. It has no evidence upload field and no production submission or storage backend.

Do not paste case documents, private correspondence, account details, passwords or sensitive evidence into the estimator or public form. No third-party analytics or tracker is currently authorised.

  • No public evidence upload
  • No production portal or storage claim
  • No analytics or marketing tracker
  • No published receiving address

Planned production architecture

Case-specific intake and isolation are launch requirements

Once a future production project is scoped, paid and activated, the agreed secure intake method will be provided. Eligible manageable evidence sets may use authenticated case-specific online intake; initial sets above the configured 500 MB threshold and source-sensitive structured datasets may use encrypted physical media.

Production architecture must isolate customers and cases, apply explicit permissions, record access and processing events, and keep evidence outside the public marketing site and source repository.

  • Authenticated case-specific access
  • Tenant and case isolation
  • Minimum-necessary permissions
  • Auditable intake and processing
  • Approved retention and deletion policy required

Source integrity

Original material and working copies remain distinct

The service design preserves original received material and records source provenance. Processing or normalisation creates derived working copies rather than silently modifying the source.

Hash records can help show whether a digital file remains unchanged between controlled points. A hash does not prove truth, authenticity or legal significance.

  • Source hash where available
  • Original relative path and provenance
  • Derived-file relationship
  • Processing history and limitations

Secure handover design

Encrypted delivery with access details sent separately

The planned standard final handover is an encrypted USB sent using tracked delivery. Password or access details are supplied separately and must not appear on packaging, labels, unencrypted files or tracking messages.

The production receiving address, retention periods, infrastructure providers and security assurance programme remain subject to operator and legal/compliance approval. No ISO, Cyber Essentials, SOC 2, data-centre, cloud-encryption, malware-provider or penetration-test certification is claimed.

Practical answers

Frequently asked questions

Security questions

Can I upload evidence on this website?

No. The public site and form do not accept case evidence. The agreed secure intake method is provided only for an activated production case.

What does a file hash prove?

It can help detect whether file content changed between controlled points. It does not prove authenticity, truth or legal relevance.

Who can access customer documents?

Production access must be explicitly authorised, case-scoped, minimum-necessary and auditable. That production environment is not currently implemented.

How long will files be retained?

Durations are to be approved. They will be governed by a final retention and deletion policy reviewed before production.