Security & assurance

What your CISO will ask, answered

We are a consultancy, so our security posture is mostly about people and access, not about a product. Here is what we commit to contractually, what we hold today, and what is still in progress.
commitments in place today, each evidenced during supplier onboarding
9
assurance items in progress: Cyber Essentials Plus certifying now, ISO 27001 targeted for 2027
4
breach notification, committed as a term of the DPA
24h
screening standard, completed before any client access
BS7858

Reviewed · reviewed quarterly · every commitment below is evidenced during supplier onboarding

On this page
Start here if you are forwarding this page

Supplier onboarding pack

MSA, SOW template, DPA with sub-processor annex, insurance certificates and completed security questionnaires. Sent same week, usually same day.

Request the pack

https://tenhaw.com/security

Assurance posture

Held today, and in progress

Commitments and certifications in place now, and assurance work in progress, with the current state of each.

9

in place today

Ask us to evidence any of these during supplier onboarding.

  • UK GDPR and Data Protection Act 2018 compliant, as a UK-registered company
  • DPA with sub-processor annex available for every engagement
  • 24-hour personal data breach notification, committed in the Data Processing Agreement
  • UK data processing by default, with EU residency available where an engagement requires it
  • Engagement sub-processor list published on the security page and annexed to the DPA
  • BS7858-standard personnel screening before client access
  • No-substitution commitment written into the SOW: the people on an engagement are not changed without the client's written agreement
  • Named-tool-only policy for AI systems touching client data
  • Professional indemnity £1m, employers' liability £10m, public liability £1m, cyber £25k, legal expenses £100k
4

in progress

If one of these is a hard gate for you, raise it on the first call and we will tell you whether we can meet it in your timeframe.

  • Cyber Essentials Plus: certification in progressIn progress
  • ISO 27001: gap assessment complete, certification targeted for 2027Target 2027
  • ISO/IEC 42001 (AI management systems), under assessment, and increasingly the one clients ask forIn progress
  • SOC 2 Type II: will follow ISO 27001 where clients require itIn progress
Insurance

Our cover, in numbers

Published rather than sent on request, and adjustable per engagement where your supplier standard sets specific limits. Certificates are available during supplier onboarding.

If your supplier standard sets specific limits

Any line on the schedule can be increased for a specific engagement, with the additional premium priced into it. Name the limit your supplier standard requires, on any call, and the increased cover is in place at that limit within three working days, ahead of contract signature.

Professional indemnity

£1,000,000

Covers claims arising from our advice or our work. This is the line most procurement teams set a floor on, and the limit can be increased for a specific engagement where your supplier standard requires it.
Employers' liability

£10,000,000

Statutory cover for our people, including associates on engagement.
Public liability

£1,000,000

Covers injury or damage caused while we are working on your premises.
Cyber

£25,000

Covers incident response and liabilities arising from a cyber event. We hold no client production data and work inside your estate under your controls, which is what limits the exposure this line answers for. Where your risk function requires a higher limit, we price the increase into the engagement, on the same three-working-day commitment that applies to every line on the schedule.
Legal expenses

£100,000

Cover for defending or pursuing a contractual dispute.

Liability is capped per engagement in the Statement of Work, with breach of confidentiality and data protection treated separately from the general cap.

People, access and data

Who reaches your estate, and what they can touch

Screening, access, data residency, incident response and the build toolchain, in the order a supplier review works through them.

01

Our people, before they reach your estate

The main security surface of a consultancy is its people. The screening, substitution and confidentiality commitments below are written into the engagement agreement.

  • Delivery teams are two or three senior people, with James Rooney accountable on every engagement; every associate is someone he has already delivered alongside, and nobody is recruited after a client commits
  • The people on your engagement are not substituted without your written agreement
  • BS7858-standard screening (identity, right to work, employment history and criminal record checks) completed before any client access, for employees and associates alike
  • Associates are contracted under the same confidentiality, screening and data-handling obligations as employees, with no onward sub-contracting without your consent
  • Confidentiality obligations survive the end of the engagement indefinitely
02

How we work inside your systems

Our default is to work on your infrastructure under your controls, rather than pulling your data out to ours.

  • We use your identity provider, your access controls and your devices where you provide them
  • Working software is built and deployed on your infrastructure and designed around your organisation's policies, so there is nothing to migrate off our estate when the engagement ends
  • Access is requested against the principle of least privilege and time-boxed to the engagement, with a documented offboarding step on exit
  • Where we use our own devices, they are full-disk encrypted, MDM-managed, screen-locked and remotely wipeable
  • Client data is not copied to Tenhaw-controlled storage unless the engagement agreement expressly permits it
  • We do not retain client production data after an engagement ends; retention and deletion terms are set in the Data Processing Agreement
03

Where your data lives

Where engagement data is processed, and under what terms.

  • Engagement data is processed in the United Kingdom by default, with EU residency available where your policy requires it
  • Our default is to work inside your estate under your controls, so in most engagements your data never leaves your own infrastructure
  • Where data does reach our systems, it is processed in the UK on encrypted, MDM-managed devices and deleted at engagement end under the terms of the Data Processing Agreement
  • Every engagement sub-processor is published on this page with entity, location, purpose and transfer mechanism, and annexed to the Data Processing Agreement
04

Engagement sub-processors

The full sub-processor list for consulting engagements, as annexed to the Data Processing Agreement. It is short, because delivery happens inside your estate.

  • Google Workspace (Google Ireland Limited): business email, calendar and documents carrying engagement correspondence and client contact details, processed in the UK and EU, with any US support access governed by the UK Addendum to the EU Standard Contractual Clauses
  • Close (Elastic Inc., United States): customer relationship management holding client contact records, under the UK International Data Transfer Addendum and Standard Contractual Clauses
  • Cal.com Inc. (United States): scheduling, processing the name, email address and meeting details provided when booking a call, under Standard Contractual Clauses
  • Model providers (Anthropic, OpenAI and Google): only content named and approved by you in writing for your engagement, under zero-retention or enterprise agreements
  • The processors behind this website are listed separately in the Privacy Policy and do not touch engagement data
05

Incident response and breach notification

What happens if something goes wrong, and how quickly you hear about it.

  • A personal data breach affecting your data is notified to you without undue delay, and in any event within 24 hours of us becoming aware of it, as a term of the Data Processing Agreement, so your own 72-hour regulatory clock starts with time to spare
  • A security incident touching your engagement is raised with your named contact by the route agreed at kickoff, with an initial notification first and updates as the investigation progresses
  • A written incident report follows, covering root cause, impact and remediation, and we stay engaged until your own team closes the incident
  • Vulnerability reports to security@tenhaw.com are acknowledged within two working days, and we do not take legal action against good-faith research
06

How AI-built code is secured before it ships

AI-accelerated delivery runs under the same engineering controls as any other build. They run in the pipeline from the first commit, and because we build on your infrastructure they run under your standards and land in your audit trail.

  • Static analysis with quality gates, SonarQube or Semgrep or your own equivalent, runs on every commit
  • Dependency and vulnerability scanning, Snyk or Dependabot, on every build, with continuous alerts on newly disclosed CVEs
  • Secrets scanning with push protection in CI and before commit, GitHub secret scanning or gitleaks
  • A software bill of materials and licence provenance checks for anything we ship, so AI-generated code arrives with its supply chain documented
  • Protected main branches and human code review before merge, with a model-led security review of the whole system roughly every fifth prompt during a build
  • Independent penetration testing in the productionisation phase, scoped to the code that shipped

Continuity, including who carries an engagement when the accountable partner is unavailable, is covered on the team page.

The question we get asked hardest

AI tooling, and what touches your data

Our engineers work inside client estates and client data. The rules below govern every AI tool that touches them.

  • No client data, code or documentation goes into any AI tool that has not been named and approved by you in writing
  • Where you have an approved enterprise AI tenancy, we work inside it rather than bringing our own
  • Where you have no approved tenancy, the default toolchain is named for your review: Anthropic's Claude Code, OpenAI's models and Google's Gemini, combined for what each does best, running inside your infrastructure and aligned to your policies, and substituted for your approved stack on request
  • We use zero-retention or enterprise agreements with model providers so client content is not retained or used for training
  • Agentic systems we build for you are designed with action logging, human-in-the-loop approval gates for consequential or irreversible decisions, and an auditable trail from decision to outcome
  • Model and agent risk is documented during operating model design, with your second-line risk function as a co-author rather than a reviewer
Contract, liability and our own estate

What your legal and procurement teams will ask for

Everything below is available during supplier onboarding.

This website

Our own estate is small, because we deliberately hold very little. This site is a static marketing site with no customer accounts and no client data on it.

  • Statically generated and served over TLS with HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy headers set
  • No client data, no accounts and no authenticated area; the visitor-analytics estate is disclosed in full in our Privacy Policy
  • Third-party processors used by this site are listed individually in our Privacy Policy
  • Multi-factor authentication is enforced on every business system we operate

If you are regulated, start with the governance

In financial services the binding constraint on agentic transformation is almost never the technology, it is accountability. Under SM&CR a named individual remains accountable for outcomes, and “the agent decided” is not a defence. We map accountability for agent decisions onto real people with matching authority before anything is deployed, and we bring your second line in as designers of that framework rather than as reviewers of it.

How we work in financial services →

Responsible disclosure. Found a vulnerability in this site or anything else we run? Email security@tenhaw.com and we will acknowledge within two working days. We will not pursue legal action for good-faith research.

A question this page did not answer

Ask a supplier-assurance questionanswers from our stated position
Ask anything your security review needs. I will tell you what we hold today, what is still in progress, and where the honest answer is that you need to speak to James.

Prefer to talk it through? Ask us on a discovery call →

Answers here are generated from the pages on this site and are not a contractual statement of our security posture. The controls above, and the onboarding pack, are.

book a call

Send this to your security team, then book the call.

A 30-minute call with James Rooney. Bring your questionnaire. We will tell you on the call which items we can evidence today and which are still in progress.

most start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks

// pick a slot · cal.com/tenhaw/professional-servicesLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.