Security + trust

Trust is evidence.
Not a logo wall.

The principles, controls and disclosures behind the way Sevenpoynt Security operates this website and handles business enquiries.

Report a concern ↗
01

Data minimisation

We collect the information required to respond, publish and operate the service—then retain it only for a defined purpose.

02

Access control

Publishing and administrative actions are authenticated and restricted to an explicit administrator allowlist.

03

Encryption

The hosting platform provides encryption in transit and at rest for application data and uploaded media.

04

Secure delivery

Changes are validated before deployment and administrative actions are recorded for accountability.

05

Supplier discipline

Technology and delivery relationships are represented accurately; planned routes are not presented as active authorisations.

06

Incident readiness

We maintain escalation routes and a responsible-disclosure process for security concerns affecting this service.

07

Honest assurance

We do not claim certifications, accreditations or partnerships that have not been independently confirmed.

Current assurance position

Clear about what exists today.

Sevenpoynt Security is an early-stage independent security business. The company does not currently claim ISO 27001, SOC 2 or CREST certification for its own operations. Where accredited delivery is required, the proposed delivery organisation and its assurance status will be identified in the engagement.

This page will evolve as formal controls, insurance, accreditations and supplier due diligence mature.