Policies
Information Security PolicyOur security programme: network segregation, anti-virus, daily security baseline, suppliers and backups.Read policy →Access Control PolicyLeast-privilege access to systems and personal data, multi-factor authentication and quarterly reviews.Read policy →Data Classification and Encryption PolicyFour classification levels, and encryption of sensitive data in transit and at rest.Read policy →Incident Response PolicyRoles, reporting channels, severity levels and breach notification timelines.Read policy →Vulnerability and Threat Management ProcedureScanning, patch timelines, threat monitoring and responsible disclosure.Read policy →Data Protection PolicyInternal UK GDPR policy: data subject requests, retention, data location and end-of-contract deletion.Read policy →Privacy PolicyWhat personal data we collect, why, how long we keep it and your rights.Read policy →
At a glance
| Area | Our position |
|---|---|
| Security programme | Published Information Security Policy with named ownership and supporting policies |
| Network protection | Default-deny firewalls, private-only databases, intrusion prevention, HTTPS with HSTS |
| Endpoint protection | Anti-malware on all devices and servers, full-disk encryption, automatic updates |
| Access control | Least privilege, multi-factor authentication, SSH keys, automatic blocking of repeated failed logins, quarterly access reviews |
| Encryption | TLS 1.2+ in transit, full-disk encryption on devices, and secrets kept only in private storage that is not reachable from the internet |
| Incident response | Defined roles, partner notification within 24 hours, ICO within 72 hours where required |
| Vulnerability management | Daily OS update checks, dependency audits, patching within 72 hours for critical issues |
| Data location | Germany (European Economic Area) |
| Data subject requests | We help clients, sellers and platforms access, update or delete data on request |
| End of contract | Personal data deleted within 30 days |
| Certifications | We do not currently hold ISO 27001, ISO 27701 or SOC 2 certification. Our controls are documented in the policies above. |
PDF downloads
| Document | File |
|---|---|
| Information Security Policy | information-security-policy.pdf |
| Access Control Policy | access-control-policy.pdf |
| Data Classification and Encryption Policy | data-classification-and-encryption-policy.pdf |
| Incident Response Policy | incident-response-policy.pdf |
| Vulnerability and Threat Management Procedure | vulnerability-management-procedure.pdf |
| Data Protection Policy | data-protection-policy.pdf |
| Privacy Policy | privacy.pdf |
Report a security or privacy concern
Report security or privacy concerns through the contact form at skylarksphere.co.uk/#contact (choose “Something else” and start the message with “Security” or “Privacy”), or in writing to our registered office. See also our security.txt.