Data minimisation
We collect the information required to respond, publish and operate the service—then retain it only for a defined purpose.
Security + trust
The principles, controls and disclosures behind the way Sevenpoynt Security operates this website and handles business enquiries.
Report a concern ↗We collect the information required to respond, publish and operate the service—then retain it only for a defined purpose.
Publishing and administrative actions are authenticated and restricted to an explicit administrator allowlist.
The hosting platform provides encryption in transit and at rest for application data and uploaded media.
Changes are validated before deployment and administrative actions are recorded for accountability.
Technology and delivery relationships are represented accurately; planned routes are not presented as active authorisations.
We maintain escalation routes and a responsible-disclosure process for security concerns affecting this service.
We do not claim certifications, accreditations or partnerships that have not been independently confirmed.
Current assurance position
Sevenpoynt Security is an early-stage independent security business. The company does not currently claim ISO 27001, SOC 2 or CREST certification for its own operations. Where accredited delivery is required, the proposed delivery organisation and its assurance status will be identified in the engagement.
This page will evolve as formal controls, insurance, accreditations and supplier due diligence mature.