1. Security approach
RegInspect uses authenticated access, tenant scoping and role controls to protect firm information. Users should maintain appropriate permissions, protect sign-in methods and use available multi-factor authentication. Authorised platform operations are separate from ordinary firm access.
2. Data and operations
Protected transport, cloud encryption, private storage, audit records, monitoring and backup/recovery procedures support the service. Vulnerability checks and controlled release procedures form part of maintenance. Controls and operational evidence must be assessed for the actual deployed environment.
3. Assurance
This policy does not assert ISO 27001 certification, Cyber Essentials certification, a completed independent penetration test or an independently certified recovery objective. Ask for available assurance evidence and any agreed service commitments. Provider certifications do not automatically certify this application.
4. Incidents and reporting
Report a suspected vulnerability or incident through our published contact route, marking the subject Security. Give enough information to reproduce the issue without disclosing real client records, credentials or tokens. Do not access other firms’ records, disrupt the service or publicly disclose sensitive details while a coordinated response is arranged. Breach notifications affecting customer personal data follow the DPA and applicable law.
Contact
Drawbridges Business Services Ltd · Company number 15260510
Townshend House, 30
Crown Road, Norwich NR1 3DT, United Kingdom
contact@reginspect.co.uk. For privacy or security matters, include “Privacy” or “Security” in the subject. Do not send sensitive client records in an initial enquiry.