Company

Trust, Governance and How We Handle Your Data

A security company that cannot answer questions about its own controls should not be asking about yours. Here is how we operate.

REGISTRATION
Companies House, No. 16141995
DATA LAW
UK GDPR & DPA 2018
INSURANCE
Professional Indemnity
AGREEMENTS
Written Scope, NDA & DPA
In short

How does Cipher Knights protect client data during an engagement?

Client data is handled under a written engagement agreement with defined access, encrypted storage and a stated retention period. Findings and reports are treated as confidential, access is limited to consultants working on your engagement, and evidence is securely destroyed at the end of the agreed retention window.

Access we ask for, and access we do not

Security work requires access, and that access is exactly what makes a consultancy a risk to its clients. We keep it proportionate: read-only wherever read-only will do, scoped to the systems in the engagement, time-limited to the engagement period, and using named individual accounts rather than a shared credential.

You are entitled to know which of our consultants will hold access, to have that access revoked at any point, and to see a record of what was accessed. We ask clients to remove our access at the end of an engagement, and we will remind you if you have not.

  • Read-only access wherever the work permits it
  • Named individual accounts, never shared logins
  • Access scoped to the systems in the agreed engagement
  • Time-limited and revoked at engagement close
  • MFA enforced on every account we hold in your environment

Confidentiality and reporting

Reports describing your weaknesses are among the most sensitive documents your business will ever hold, and they are equally sensitive in our hands. They are stored encrypted, shared through a secure route rather than as email attachments, and never used as marketing material.

We publish case studies only with written client consent, and by default they are anonymised by sector and size. If you would prefer we never reference the engagement at all, that is the default position unless you tell us otherwise.

Commercial independence

We do not take commission from security product vendors. That matters because a recommendation is worth nothing if the recommender is paid by the outcome. Where we suggest a product we will tell you why, what the alternatives are, and whether something you already own would do the job.

Where an assessment finds that a client needs less than they are currently buying, we say so, including where that reduces our own revenue.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Trust & Governance — your questions answered

Are you insured?
Yes, we hold professional indemnity insurance. Evidence of cover is provided on request during procurement or supplier due diligence.
Will you sign an NDA?
Yes, as standard. We sign a mutual NDA before any technical discussion, and a data processing agreement where our work involves processing personal data on your behalf.
How long do you keep our reports and evidence?
For a retention period defined in the engagement agreement — long enough to support retests and any subsequent queries, then securely destroyed. You can request earlier destruction at any point.
Can we see your own security certifications?
Ask us during due diligence and we will tell you exactly what we hold and what we do not. We would rather answer that question plainly than imply accreditations we have not earned.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about trust & governance?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.