Trust & security

Your data stays yours. And so does what we build.

Handing a process to an outside team is an act of trust. We earn it the boring way — real controls, plain terms, and systems that keep running whatever happens to us. Here's exactly how your data is handled, how we support what we deliver, and why you're never locked in.

🔒
Where you stand at a glance

Certified, registered, and private by default.

Most tools quietly send your documents off to someone else's servers. We build the opposite. Our engagements run inside your own private cloud, and Proofworks itself operates to a certified security standard.

Cyber Essentials certified ICO registered · ZC167703 UK GDPR data-processing terms Runs in your environment UK data residency MFA on every system Perpetual licence — no lock-in
Cyber Essentials Certified
Where your data lives

The safest place for your data is your own environment.

So that's where we put the system. It changes the whole security question — because for most engagements, your operational data never becomes ours to hold in the first place.

🔒

Deployed in your VPC

The whole system runs inside your own cloud account. You own where it lives, who can reach it, and the keys to it. We build it and hand it over.

The model runs in your cloud too

For in-VPC builds the model runs inside your own AWS account via Amazon Bedrock, over a private endpoint — so your content never leaves your environment to reach it, and it is never used to train anyone's models.

Two things to keep separate. Below, the security controls describe how Proofworks itself operates as a company (Cyber Essentials certified). The sub-processor list describes the third-party services our own product apps rely on. A bespoke build deployed inside your cloud is scoped with its own — typically much shorter — list, agreed with you before anything goes live.

Security overview

The controls behind the badge.

Cyber Essentials isn't a logo — it's a set of controls we operate and review. Here's what that means in practice.

Multi-factor everywhere

MFA is enabled on every account and every cloud service — mandatory for all administrative accounts and anything touching customer data.

Least-privilege access

Unique accounts per person, no shared credentials, and access granted only to what a role needs — nothing more.

Joiners, movers & leavers

Accounts are provisioned on a documented process and disabled within 24 hours of someone leaving, with keys and tokens revoked and shared secrets rotated.

Encrypted devices

Company laptops are BitLocker-encrypted and auto-patched; software is kept to supported, auto-updating versions.

Strong credentials

NCSC-aligned password policy — length and uniqueness over forced complexity, breached-password deny-lists, and password managers for every account.

Brute-force protection

Account lockout on repeated failures and platform-level rate limiting on API endpoints, backed by MFA as the primary defence.

Source control & backups

All code is version-controlled in private repositories; backups are encrypted and access-controlled.

Incident & breach response

Suspected compromise is acted on immediately; where a personal-data breach is confirmed, we assess it and notify the ICO within 72 hours where the law requires, and you without undue delay.

Reviewed, not filed and forgotten

Security policies, the asset register and the shared-responsibility review are owned by a director and reviewed at least annually.

Sub-processors

Who's in the stack — and where your data sits.

These are the third-party services our own product apps rely on. Client records are stored in the UK; the model providers are engaged for processing only, under enterprise terms that exclude your content from training.

For a build deployed in your own cloud, this list shrinks — often to almost nothing. The system runs on your infrastructure, and the model can run there too. The table below is the full list for our own product apps, published in the interest of transparency, not the list for your engagement.

ProviderPurposeData locationSafeguards
Application & data platform
VercelApplication hosting, delivery & document storageLondon (lhr1), UKHTTPS enforced; enterprise CDN; dashboard MFA
MongoDB AtlasPrimary database — client records, evidence, tenders & generated responsesAWS London (eu-west-2), UKAES-256 at rest, TLS 1.2+; SOC 2 Type II; continuous point-in-time backups; UK residency
Model & processing
Anthropic (Claude)Primary language-model processingUS API — or your own AWS region via Bedrock for in-VPC buildsContent not used for training (enterprise API terms); minimum content sent
OpenAIEmbeddings & supplementary processingUSContent not used for training (enterprise API terms); minimum content sent
n8nWorkflow automation (document ingestion)Secured cloud (UK / EU)Authenticated webhooks; isolated workflow credentials; account MFA
Identity & payments
ClerkAuthentication & identityUS / EUSOC 2 Type II; MFA enforcement; secure session handling
StripePayment processingUS / EUPCI-DSS compliant; Proofworks stores no card data

Sub-processor list last reviewed July 2026. We maintain this list and give notice of material changes to sub-processors handling personal data on your behalf.

Support & service levels

When something needs us, here's what you can count on.

Clear targets, a real person, and a director on the end of the escalation path — not a ticket queue that swallows your problem. These service levels apply to systems under a Run subscription; every Build includes a defined warranty and support window at handover.

How to reach us

One route in: support@proof-works.co.uk. Run clients also get a named contact who already knows your system.

Support hours

Monday–Friday, 09:00–17:30 UK time, excluding England & Wales public holidays. Critical-incident cover can be extended by arrangement.

Escalation

Any P1 or P2 not moving within target is escalated directly to a company director. No layers to get lost in.

Round-the-clock monitoring

Automated health checks run every few minutes, 24/7, across every live system — and alert us out of hours. Many issues are caught and put right before you'd notice, even though human response targets are measured in business hours.

SeverityResponse targetWhat we aim to do
P1 · CriticalLive system down, or data at risk Within 4 business hours Immediate triage; a workaround or fix targeted the same business day, with proactive updates until resolved.
P2 · MajorKey function impaired, no safe workaround Within 1 business day Investigation started promptly; resolution targeted within 3 business days.
P3 · MinorQuestion, minor issue or change request Within 2 business days Acknowledged, assessed, and scheduled into the next maintenance or release cycle.

Incident communication. For any incident affecting your live system we notify you proactively, keep you updated through it, and follow up any P1 with a short written summary of what happened and what we've changed. Response targets are measured within support hours and reflect a specialist team that answers, rather than a call centre that doesn't.

Continuity & no lock-in

What we build keeps running — with or without us.

The fair question about any specialist supplier is "what happens if you disappear?" Our whole model is built so the honest answer is: nothing stops.

Yours to run — permanently

You keep your own deployment, your data and your configuration, under a perpetual, irrevocable licence to operate the system. ProofWorks retains the underlying platform IP — but your right to run your version can't be switched off.

It runs in your environment

Because it lives in your own cloud, your system keeps operating independently of Proofworks. There's no Proofworks server it depends on.

Your environment, your keys

Your system runs in your own cloud, under your own credentials, with a full operating runbook — so your team or another provider can keep it running. The source stays ProofWorks IP; enterprise continuity is covered by escrow.

Source-code escrow for enterprise

For enterprise engagements we can place the source in independent escrow, released to you on defined triggers such as insolvency or sustained service failure — so continuity is contractually guaranteed, not just promised.

A runbook, not tribal knowledge

Every build is handed over with SOPs and an operating runbook, so your team — or another provider — can run and maintain it without us.

No single point of failure

Proofworks runs on documented processes and monitored systems, so how things work is written down — not trapped in one person’s head.

Clean exit, any time

Run is monthly and cancellable. If you ever leave, you keep your instance, your data and your licence to run it — and walk away with a system that still works.

The assurance pack

Everything your procurement team will ask for.

Our Data Processing Agreement is published in full — the rest are ready to share under NDA for any live engagement. Ask your contact, or email admin@proof-works.co.uk.

Data Processing Agreement UK GDPR Art. 28 · read it →
Terms & Conditions of Service on request
Cyber Essentials certificate on request
Mutual NDA ready to sign
IP Assignment Deed on Build
Security policy summaries on request
Sub-processor list above & in the DPA
Shared-responsibility register on request

Do your due diligence before you commit a penny.

Send us your security questionnaire, or book a 30-minute call and bring your toughest data question. We'd rather answer it now than have it sit unspoken.