Accredited third parties assess our controls every year against internationally recognized standards. Our certificates, audit reports and policies are published through Risk Ledger, where your assurance team can access them directly.
Our certificates, audit reports, penetration test summaries and policies are published through Risk Ledger, alongside our completed responses to the standard security questionnaire. One profile, continuously maintained rather than assembled on request.
Connect with us there and your team gets access directly, without a separate document request cycle.
Information security management system covering product development, hosting and support operations.
Security, Availability and Confidentiality trust services criteria over a 12-month observation window.
UK NCSC-backed scheme demonstrating baseline protection against common cyber threats.
UK NCSC-backed scheme with hands-on technical verification of our technical controls.
Privacy information management extension to our ISMS.
Artificial intelligence management system standard supporting responsible AI governance.
Listed supplier on UK public sector purchasing frameworks, with contract-specific assurance as required.
Annual penetration testing performed by a CREST-accredited provider against product and infrastructure.
Beyond certification, we maintain control mappings so customers can evidence their own obligations without a bespoke assessment.
| Framework | Relevance | Our Position |
|---|---|---|
| UK GDPR / EU GDPR | Processing of personal data | Aligned; DPA with UK IDTA and EU SCCs |
| NIST Cybersecurity Framework | US federal and commercial customers | Control mapping available via Risk Ledger |
| NCSC Cloud Security Principles | UK public sector procurement | Documented assertion per principle |
| EU AI Act | AI-enabled product capabilities | Readiness assessment complete; see Responsible AI |
| NIS2 Directive | Essential and important entities in the EU | Supplier obligations supported contractually |
| DORA | Financial services customers in the EU | ICT third-party provisions available on request |
Procurement and assurance teams can access our full security documentation on Risk Ledger, including our SOC 2 report, ISO certificates and policies. If your review needs something we haven't published there, raise a support case and we'll confirm what we can provide.
© 2026 i2 Group / N. Harris Computer Corporation. All trademarks owned by N. Harris Computer Corporation.
1 Cambridge Square, Milton Avenue, Cambridge, CB4 0AE, UK