Security and compliance

What we are certified to, where your data lives, and who you are contracting with. If your procurement needs something that is not here, ask and we will send it.

What we are certified to

  • Cyber Essentials. Certified 4 February 2026, whole organisation scope, assessed by Merris Consulting Ltd under IASME. Due for recertification 4 February 2027. The certificate can be verified on the IASME registry, and we will send you a copy on request.
  • ISO/IEC 27001: in progress, not held. We are implementing an information security management system aligned to the standard, with certification targeted for spring 2027. The standard requires evidence that the system has been running before it can be assessed, which is what that date reflects. We are not certified today and do not claim to be. It is a priority rather than an aspiration, though: the work is already underway and we expect the assessment itself to be straightforward.

What these cover. Cyber Essentials covers the whole of PHC Digital Ltd. The ISO 27001 scope is deliberately narrower: the Glow Forge Labs products and the infrastructure that runs them, the ones we sell today and the ones we add later. It will not cover the bespoke software PHC Digital builds for clients, because that runs on whatever technology each client specifies, frequently inside their own environment, and cannot sensibly sit under one management system. If you are buying a Glow Forge Labs product, the scope is the thing you are buying.

Who you are contracting with

PHC Digital Ltd, registered in England and Wales, company number 11284209, at 7 The Close, Norwich NR1 4DJ. Registered with the Information Commissioner’s Office under number ZA337228. You can look the company up at Companies House before you talk to us. Glow Forge Labs is the brand PHC Digital puts on the software it owns; PHC Digital is the company you contract with and that invoices you.

Where your data lives

  • Hosted in the United Kingdom, on Google Cloud, London.
  • A database per customer rather than shared tables, so your records are not pooled with anyone else’s. A dedicated database server is available on quote.
  • Encrypted in transit and at rest. Credentials held in a secret store, never in application code.
  • An audit trail across the system, and team-based visibility so people see only what their role requires.
  • Google Cloud is our hosting sub-processor. We will name every sub-processor in writing before you sign.

Data protection

You are the data controller and PHC Digital Ltd is the processor acting on your instructions. A data processing agreement under Article 28 of the UK GDPR is available to read before you sign, not after. Ask for it and we will send it.

  • Export. You can export everything, in full, whenever you want it, in a form you can load into something else. That right is written into the contract from the first day.
  • Erasure. We delete what you ask us to delete, and the contract says so.
  • Subject access. The product has tools for finding and producing what it holds about one person, so a request does not become a manual search.
  • Breaches. We notify you without undue delay, so that you can meet your own obligations as controller.

How the AI is governed

AI features are optional and off until you switch them on. When they are on, they summarise, extract and flag, and a person confirms before anything is written to a record, so nothing enters your data because a model suggested it. What the model provider retains is a configuration choice rather than a default, and we will name the provider and work through your compliance needs with you. Our AI usage policy sets out how we use it ourselves.

What we will send you

Most security reviews ask for the same things. You do not need to chase them: ask once and we will send the data processing agreement, the Cyber Essentials certificate, our sub-processor list, the data export clause, and a completed copy of your own security questionnaire.

Our full information security, privacy and data protection, records management and data sharing policies are published in full.

Need something specific?

Send us your security questionnaire, or tell us what your procurement needs, and a person will answer it properly.