Handing a process to an outside team is an act of trust. We earn it the boring way — real controls, plain terms, and systems that keep running whatever happens to us. Here's exactly how your data is handled, how we support what we deliver, and why you're never locked in.
Most tools quietly send your documents off to someone else's servers. We build the opposite. Our engagements run inside your own private cloud, and Proofworks itself operates to a certified security standard.
So that's where we put the system. It changes the whole security question — because for most engagements, your operational data never becomes ours to hold in the first place.
The whole system runs inside your own cloud account. You own where it lives, who can reach it, and the keys to it. We build it and hand it over.
For in-VPC builds the model runs inside your own AWS account via Amazon Bedrock, over a private endpoint — so your content never leaves your environment to reach it, and it is never used to train anyone's models.
Two things to keep separate. Below, the security controls describe how Proofworks itself operates as a company (Cyber Essentials certified). The sub-processor list describes the third-party services our own product apps rely on. A bespoke build deployed inside your cloud is scoped with its own — typically much shorter — list, agreed with you before anything goes live.
Cyber Essentials isn't a logo — it's a set of controls we operate and review. Here's what that means in practice.
MFA is enabled on every account and every cloud service — mandatory for all administrative accounts and anything touching customer data.
Unique accounts per person, no shared credentials, and access granted only to what a role needs — nothing more.
Accounts are provisioned on a documented process and disabled within 24 hours of someone leaving, with keys and tokens revoked and shared secrets rotated.
Company laptops are BitLocker-encrypted and auto-patched; software is kept to supported, auto-updating versions.
NCSC-aligned password policy — length and uniqueness over forced complexity, breached-password deny-lists, and password managers for every account.
Account lockout on repeated failures and platform-level rate limiting on API endpoints, backed by MFA as the primary defence.
All code is version-controlled in private repositories; backups are encrypted and access-controlled.
Suspected compromise is acted on immediately; where a personal-data breach is confirmed, we assess it and notify the ICO within 72 hours where the law requires, and you without undue delay.
Security policies, the asset register and the shared-responsibility review are owned by a director and reviewed at least annually.
These are the third-party services our own product apps rely on. Client records are stored in the UK; the model providers are engaged for processing only, under enterprise terms that exclude your content from training.
For a build deployed in your own cloud, this list shrinks — often to almost nothing. The system runs on your infrastructure, and the model can run there too. The table below is the full list for our own product apps, published in the interest of transparency, not the list for your engagement.
| Provider | Purpose | Data location | Safeguards |
|---|---|---|---|
| Application & data platform | |||
| Vercel | Application hosting, delivery & document storage | London (lhr1), UK | HTTPS enforced; enterprise CDN; dashboard MFA |
| MongoDB Atlas | Primary database — client records, evidence, tenders & generated responses | AWS London (eu-west-2), UK | AES-256 at rest, TLS 1.2+; SOC 2 Type II; continuous point-in-time backups; UK residency |
| Model & processing | |||
| Anthropic (Claude) | Primary language-model processing | US API — or your own AWS region via Bedrock for in-VPC builds | Content not used for training (enterprise API terms); minimum content sent |
| OpenAI | Embeddings & supplementary processing | US | Content not used for training (enterprise API terms); minimum content sent |
| n8n | Workflow automation (document ingestion) | Secured cloud (UK / EU) | Authenticated webhooks; isolated workflow credentials; account MFA |
| Identity & payments | |||
| Clerk | Authentication & identity | US / EU | SOC 2 Type II; MFA enforcement; secure session handling |
| Stripe | Payment processing | US / EU | PCI-DSS compliant; Proofworks stores no card data |
Sub-processor list last reviewed July 2026. We maintain this list and give notice of material changes to sub-processors handling personal data on your behalf.
Clear targets, a real person, and a director on the end of the escalation path — not a ticket queue that swallows your problem. These service levels apply to systems under a Run subscription; every Build includes a defined warranty and support window at handover.
One route in: support@proof-works.co.uk. Run clients also get a named contact who already knows your system.
Monday–Friday, 09:00–17:30 UK time, excluding England & Wales public holidays. Critical-incident cover can be extended by arrangement.
Any P1 or P2 not moving within target is escalated directly to a company director. No layers to get lost in.
Automated health checks run every few minutes, 24/7, across every live system — and alert us out of hours. Many issues are caught and put right before you'd notice, even though human response targets are measured in business hours.
| Severity | Response target | What we aim to do |
|---|---|---|
| P1 · CriticalLive system down, or data at risk | Within 4 business hours | Immediate triage; a workaround or fix targeted the same business day, with proactive updates until resolved. |
| P2 · MajorKey function impaired, no safe workaround | Within 1 business day | Investigation started promptly; resolution targeted within 3 business days. |
| P3 · MinorQuestion, minor issue or change request | Within 2 business days | Acknowledged, assessed, and scheduled into the next maintenance or release cycle. |
Incident communication. For any incident affecting your live system we notify you proactively, keep you updated through it, and follow up any P1 with a short written summary of what happened and what we've changed. Response targets are measured within support hours and reflect a specialist team that answers, rather than a call centre that doesn't.
The fair question about any specialist supplier is "what happens if you disappear?" Our whole model is built so the honest answer is: nothing stops.
You keep your own deployment, your data and your configuration, under a perpetual, irrevocable licence to operate the system. ProofWorks retains the underlying platform IP — but your right to run your version can't be switched off.
Because it lives in your own cloud, your system keeps operating independently of Proofworks. There's no Proofworks server it depends on.
Your system runs in your own cloud, under your own credentials, with a full operating runbook — so your team or another provider can keep it running. The source stays ProofWorks IP; enterprise continuity is covered by escrow.
For enterprise engagements we can place the source in independent escrow, released to you on defined triggers such as insolvency or sustained service failure — so continuity is contractually guaranteed, not just promised.
Every build is handed over with SOPs and an operating runbook, so your team — or another provider — can run and maintain it without us.
Proofworks runs on documented processes and monitored systems, so how things work is written down — not trapped in one person’s head.
Run is monthly and cancellable. If you ever leave, you keep your instance, your data and your licence to run it — and walk away with a system that still works.
Our Data Processing Agreement is published in full — the rest are ready to share under NDA for any live engagement. Ask your contact, or email admin@proof-works.co.uk.
Send us your security questionnaire, or book a 30-minute call and bring your toughest data question. We'd rather answer it now than have it sit unspoken.