Security & Compliance

We hold ourselves to a high standard of information security, so our clients can focus on building, not worrying.

Cyber Essentials · Cyber Essentials Plus · ICO registered, ZC175109 · ISO 27001, in progress

OUR CERTIFICATIONS

Independently verified security

Vesper holds Cyber Essentials and Cyber Essentials Plus, and is currently working towards ISO/IEC 27001, the internationally recognised standard for information security management.

Cyber Essentials — Certified

Awarded by the UK National Cyber Security Centre, this certification confirms that Vesper has the foundational security controls in place to protect against the most common cyber threats, including malware, phishing, and unauthorised access.

Cyber Essentials Plus — Certified

The enhanced tier of the Cyber Essentials scheme, verified through independent technical testing of our systems. Cyber Essentials Plus gives clients assurance that our security controls have been tested and confirmed to work in practice, not just on paper.

ISO/IEC 27001:2022 — In progress

We are currently working towards ISO 27001, the internationally recognised standard for information security management, through the British Assessment Bureau. Certification targeted for June 2027.

Security is built into everything we do

From how we manage access to our systems, to how we handle client data, security is not an afterthought at Vesper. Our current certifications, and our ongoing work towards ISO 27001, reflect the controls and processes we have in place across the business, and we continuously review and improve our posture as threats evolve.

DATA & PRIVACY

GDPR compliant. UK data residency.

We are compliant with UK GDPR and registered with the ICO. All client data is stored and processed within the United Kingdom.

ICO registered. UK GDPR compliant.

ICO registration number: ZC175109

Vesper is registered with the Information Commissioner's Office and compliant with UK GDPR. We collect only the data we need, hold it securely, and never share it with third parties without explicit agreement. Clients can request a Data Processing Agreement (DPA) at any time.

UK data residency

All client data is stored and processed within the United Kingdom. We do not transfer data outside of the UK without prior agreement, giving clients full visibility and control over where their information lives.

DOCUMENTATION

Our Policies

Our security and data protection policies are available to clients and prospective clients on request.

Data Protection Policy

Sets out how Vesper collects, stores, and processes personal data in line with UK GDPR, including the rights of data subjects and how we handle requests.

Information Security Policy

Covers how Vesper manages and protects information assets across the business, including access controls, incident response, and the responsibilities of our team.