- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- All services and systems operated or managed by us
On this page
Security & Shared Responsibility Statement
This statement describes our security approach without claiming that any internet-connected system is risk-free or certified beyond its actual scope.
1. Governance
We use proportionate policies, assigned responsibilities, risk assessment, supplier management, incident handling and service-change controls appropriate to our size, services and risk profile.
2. Access control
Measures may include named accounts, role-based permissions, least privilege, MFA where supported, privileged-access restrictions, credential rotation, leaver controls and audit logging.
3. Infrastructure and application security
Measures may include network segmentation, firewalls, encrypted transport, secure configuration, patching, dependency review, backups, monitoring, anti-abuse controls, code review and separation of live and test environments.
4. Personnel and suppliers
Personnel receive security and confidentiality expectations appropriate to their role. Suppliers are assessed according to service criticality, data access and available assurance.
5. Incident management
We may investigate, contain, isolate, reset credentials, block traffic, disable integrations, restore from backup and notify affected parties. We prioritise containment and safe restoration over uninterrupted access during a serious incident.
6. Vulnerability management
We review reported vulnerabilities and relevant updates and prioritise remediation according to exploitability, impact, exposure and operational risk. Not every update is deployed immediately where it could create a greater stability risk.
7. Shared responsibility
Customers are responsible for endpoint security, user behaviour, access approval, lawful configuration, physical security, local networks, supported equipment, backups within their control and implementation of reasonable recommendations.
8. No absolute assurance
No security measure eliminates all risk. We do not warrant that a Service will be free from every vulnerability, attack, loss, outage or unauthorised access. Customers should maintain appropriate insurance and continuity arrangements.
9. Assurance requests
We may provide reasonable security information subject to confidentiality and protection of other customers. Extensive questionnaires, audits or bespoke evidence are chargeable unless included in the Order.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
