Company

Security and compliance

What is actually in place, described without embellishment. Where we do not hold a certification, this page says so rather than implying otherwise.

On certification claims. Compliance badges are easy to put on a website and easy to verify, so we only state what we can evidence with a report or an attestation. The table below distinguishes between what we operate, what our facility providers hold, and what we have not obtained.
Status

Certification position

Framework Our position Evidence available
SOC 2 Type II Not held Not currently audited at the corporate level. None. We will not represent otherwise.
ISO/IEC 27001 Not held Our internal controls are modeled on it but are not certified. Control descriptions on request.
PCI DSS Not applicable We do not store, process, or transmit cardholder data; payment processing is handled by our processors. Processor attestations on request.
Facility certifications Held by operators Our facility providers maintain their own certifications for the buildings we occupy. Operator certificates on request, per facility.
GDPR & UK GDPR Operating Data processing agreement, transfer mechanism, and records of processing in place. DPA and SCCs on request.
RPKI route origin validation Operating ROAs published for space we announce; invalids dropped from peers and upstreams. Independently verifiable via public RPKI data.

If a certification is a procurement requirement for you, tell us early in the conversation so we can be clear about whether we can meet it.

Technical measures

How the network and our systems are secured

Routing security

  • RPKI ROAs published for announced space
  • RPKI-invalid routes dropped
  • IRR objects maintained
  • Per-session prefix limits
  • Source address validation at the edge

Access control

  • Least-privilege role-based access
  • Multi-factor authentication on administrative accounts
  • Separate credentials for network devices
  • Administrative access logged and reviewed
  • Access revoked on role change or departure

Change management

  • Configuration changes recorded with an owner
  • Peer review for core network changes
  • Defined maintenance windows and notice periods
  • Documented rollback for each change
  • Post-incident reports for P1 events

Attack mitigation

  • Volumetric filtering at the network edge
  • Customer-triggered blackholing by BGP community
  • Escalation to upstream scrubbing
  • Flow telemetry for attack characterisation

Physical security

  • Multi-factor physical access control
  • Staffed reception and CCTV, as operated per facility
  • Lockable cabinets and cages
  • Named access lists per customer
  • A and B power feeds with UPS and generator plant

Monitoring

  • Continuous reachability and capacity monitoring
  • Latency and loss measurement between hubs
  • Alerting to a continuously staffed NOC
  • Planned work notified to account technical contacts

Data protection

Our own processing of personal information is described in the privacy policy. Where we process personal data on behalf of a customer, we act as processor on that customer's instructions under a data processing agreement, which is available on request and can be incorporated into your service order.

For transfers out of the United Kingdom or the European Economic Area we rely on the Standard Contractual Clauses or the UK International Data Transfer Addendum, supported by a transfer risk assessment. Copies are available from [email protected].

Sub-processors

We keep the number of parties with access to customer data small. The categories we engage are:

  • Payment processing. Card and account payments, handled so that we never receive full card numbers.
  • Business email and ticketing. Correspondence with customers and abuse reporters.
  • Monitoring and alerting. Network telemetry and incident notification.
  • Facility operators. Physical access authorization at facilities where we operate.
  • Professional advisers. Legal, accounting, and audit.

A current named list with locations is provided on request. We give notice before adding a sub-processor with access to customer personal data, and customers under a DPA may object.

Security incident response

We maintain a documented incident response process covering detection, containment, eradication, recovery, and review. Where a security incident affects customer data we notify affected customers without undue delay, along with what we know, what we are doing, and what we recommend you do.

Where personal data is affected and notification to a regulator is required, we notify within the applicable statutory period. Post-incident reports are issued in writing.

Personnel

  • Confidentiality obligations for everyone with access to customer data.
  • Background checks appropriate to the role, where lawful in the relevant jurisdiction.
  • Security awareness briefing at onboarding and periodically thereafter.
  • Access provisioned on a least-privilege basis and reviewed on role change.

Business continuity

The network is built so that the loss of a single facility, router, or upstream does not take a region offline. Customers who require site-level resilience should take diverse services in a dual-facility market, and the service level agreement assesses availability against the pair rather than each circuit.

Business systems are backed up daily with encryption at rest, and restoration is tested periodically.

Reporting a vulnerability

Send reports to [email protected]. Our machine-readable contact is published at /.well-known/security.txt per RFC 9116. The full disclosure guidelines, including what is and is not in scope, are on the abuse and DMCA page.

Need documentation for procurement?

We can supply a data processing agreement, facility operator certificates, and control descriptions to support your vendor assessment.