Company
Security and compliance
What is actually in place, described without embellishment. Where we do not hold a certification, this page says so rather than implying otherwise.
On certification claims. Compliance badges are easy to put on a website and
easy to verify, so we only state what we can evidence with a report or an attestation. The
table below distinguishes between what we operate, what our facility providers hold, and
what we have not obtained.
Status
Certification position
| Framework | Our position | Evidence available |
|---|---|---|
| SOC 2 Type II | Not held Not currently audited at the corporate level. | None. We will not represent otherwise. |
| ISO/IEC 27001 | Not held Our internal controls are modeled on it but are not certified. | Control descriptions on request. |
| PCI DSS | Not applicable We do not store, process, or transmit cardholder data; payment processing is handled by our processors. | Processor attestations on request. |
| Facility certifications | Held by operators Our facility providers maintain their own certifications for the buildings we occupy. | Operator certificates on request, per facility. |
| GDPR & UK GDPR | Operating Data processing agreement, transfer mechanism, and records of processing in place. | DPA and SCCs on request. |
| RPKI route origin validation | Operating ROAs published for space we announce; invalids dropped from peers and upstreams. | Independently verifiable via public RPKI data. |
If a certification is a procurement requirement for you, tell us early in the conversation so we can be clear about whether we can meet it.
Technical measures
How the network and our systems are secured
Routing security
- RPKI ROAs published for announced space
- RPKI-invalid routes dropped
- IRR objects maintained
- Per-session prefix limits
- Source address validation at the edge
Access control
- Least-privilege role-based access
- Multi-factor authentication on administrative accounts
- Separate credentials for network devices
- Administrative access logged and reviewed
- Access revoked on role change or departure
Change management
- Configuration changes recorded with an owner
- Peer review for core network changes
- Defined maintenance windows and notice periods
- Documented rollback for each change
- Post-incident reports for P1 events
Attack mitigation
- Volumetric filtering at the network edge
- Customer-triggered blackholing by BGP community
- Escalation to upstream scrubbing
- Flow telemetry for attack characterisation
Physical security
- Multi-factor physical access control
- Staffed reception and CCTV, as operated per facility
- Lockable cabinets and cages
- Named access lists per customer
- A and B power feeds with UPS and generator plant
Monitoring
- Continuous reachability and capacity monitoring
- Latency and loss measurement between hubs
- Alerting to a continuously staffed NOC
- Planned work notified to account technical contacts
Need documentation for procurement?
We can supply a data processing agreement, facility operator certificates, and control descriptions to support your vendor assessment.