TRUST AND COMPLIANCE

Trust and security

Last updated: 11 September 2026

Security requirements are part of how we scope work, not a separate brochure claim. This page describes the principles we work to and the practices we can apply. Specific controls, providers and evidence are agreed in the project, because they depend on your systems, your data and your own security requirements.

A procurement or security reviewer should treat anything not written into the engagement terms as a capability we can discuss, not as a certificate we already hold.

How we approach security

We treat security as part of the design, not an afterthought after the build:

  • Agree the data first. Before implementation we identify what information is involved, where it lives, who may see it and what must not leave your environment.
  • Least privilege. Access is limited to the systems and records needed for the agreed work. We prefer working inside your existing access model rather than inventing a parallel one.
  • Human control where risk requires it. Which actions run automatically, which need approval and what happens on uncertainty are designed with you. The boundary depends on the work, not a universal rule.
  • Visible responsibilities. Ownership, logging, retention, deployment and support after launch are written into the scope so they are not left as assumptions.
  • Decline work that is a bad fit. If the data, the risk or the proposed automation would create an unacceptable problem, we will say so.

Data handling

Access

Access to client systems is granted by you, for the purpose of the engagement, and removed when that access is no longer needed. We can work under a confidentiality agreement and a data processing agreement where the work requires them.

Typical project decisions include:

  • which systems we may use
  • whether access is read only or includes changes
  • how credentials are issued and revoked
  • what is logged and who can review those logs

Encryption and hosting

Encryption, hosting and provider choices follow the project. We can work inside your existing cloud environment. Where Vantagea hosted infrastructure is required, the provider, region, retention and access model are agreed in the scope rather than assumed.

We do not claim a single encryption standard, cloud certification or hosting pattern for every engagement.

Retention

Client data is kept only as long as the engagement and any legal retention requirement need it. At the end of the work we can agree deletion, return or a handover of what you need to keep operating the system.

How we build

Secure delivery is a set of project practices, not a slogan:

  • security and access requirements are captured during scoping
  • changes to production systems need your approval
  • we test the agreed scenarios, including failure and exception paths
  • documentation covers how the system is operated, stopped and overridden

For AI systems we treat the following as design questions, not automatic features of every build:

  • what the system may do without approval
  • what it must not do
  • how unexpected input is rejected or queued
  • how a person reviews an uncertain result
  • what is recorded so a later question can be answered

We do not claim that every decision is fully auditable by default, or that every action always waits for a human. Those controls are specified where the risk justifies them.

Compliance

Vantagea Ltd is a UK company. We take UK data protection law seriously, including the UK GDPR and the Data Protection Act 2018, and we will work with the requirements that apply to your project.

We do not claim that every engagement is already certified to SOC 2, ISO 27001 or any other standard. Enterprise work can include the documentation, reviews and control evidence your security and procurement teams need. Alignment with a framework is agreed when it is relevant, not advertised as a badge we already hold.

Incidents and disclosure

If a security issue affects your data, we will notify the people named in the engagement as promptly as the situation allows and work with you on containment and next steps. Notification timing should be written into the agreement where you need a contractual commitment.

To report a vulnerability in a Vantagea system, email admin@vantagea.io with the subject line "Responsible Disclosure". We will acknowledge the report and track it. Do not include unnecessary customer data in the first message.

Contact

For security questions about a current or proposed engagement:

Vantagea Ltd
Email: admin@vantagea.io

Company Number: 14751439
71-75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom