01Registrations, insurance and certifications
Everything below is either in place today or stated plainly as not yet in place — we would rather show you a gap than assert something we cannot evidence. Certificates, schedules and registration documents are in the procurement pack, released before engagement.
| Legal name | Probative Co |
| Contact for legal notices | diin@probativeco.com |
| Registrations, insurance and certificates | Released in the procurement pack on request, confirmed in writing before any engagement — nothing here is asserted before we hold the paperwork. |
Insurance position, with certificate wording and limits, is confirmed in writing in the procurement pack before any engagement starts. If cover suitable for the work is not in place, we will say so and decline rather than proceed uninsured.
02Access control and confidentiality
- Least privilege. Access to client material is granted per engagement, to the people working on it, and removed when the engagement ends.
- Authentication. Multi-factor authentication is required on email, file storage, hosting and payment accounts.
- Device controls. Full-disk encryption, automatic screen lock, current patching, and no client material on removable media or personal cloud accounts.
- Written confidentiality. Everyone with access — including engaged associates and subcontractors — is bound by written confidentiality and data-protection obligations no less protective than our client terms.
- Matter separation. Work for different clients is kept separately, with no shared working areas between engagements.
03Encryption, transfer and storage
- Transport encryption (TLS) for all transfers, and encryption at rest for stored material.
- Encrypted transfer routes only: our link, or your own SFTP or portal. Never plain email attachments.
- Files are held only for as long as the engagement requires, then deleted with written confirmation.
- Redaction is welcome and encouraged: we need the structure of a record, not the identities in it. Where it is practical we work from redacted sets by default.
- Backups are encrypted and access-controlled; deleted material is removed from live systems immediately and ages out of backup cycles within the period stated in your DPA.
04Retention and deletion
| Record | Retention |
|---|---|
| Client files provided for review | Deleted on completion of the engagement, with written confirmation |
| Engagement records and deliverables | 6 years after the engagement ends, for professional indemnity and accounting purposes |
| Onboarding form submissions | 12 months |
| Enquiries and correspondence | 24 months from last contact |
| Newsletter subscriptions | Until you unsubscribe, then deleted within 5 working days |
| Website logs and cookies | Not retained: the site sets no cookies and runs no analytics |
05Subprocessors
We name our subprocessors before engagement and will not add one for your engagement without telling you first. The current list:
| Subprocessor | Purpose | Location | Status |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting and content delivery (Pages), form submission storage (KV) | Global edge network; KV data stored in the region configured for the account | in use |
| Google Fonts | Web font delivery for this website | EU/US | in use |
| Stripe Payments UK Ltd | Card payments, where a client chooses to pay by card | UK/EU | pending |
| Secure file transfer provider | Encrypted transfer of client files | To be confirmed at launch | pending |
| Email provider | Transactional and newsletter email | To be confirmed at launch | pending |
06AI-specific controls
Some of our services use our own tooling to perform a structured first pass over document sets. The controls around that are the same ones we audit in other firms, and we publish them so you can hold us to them:
- User-scoped access. Where we deploy retrieval over a firm's documents it inherits that firm's permissions and ethical walls rather than bypassing them; in our own reviews, access is limited to the named reviewer.
- No training on client data. Client material is not used to train any model, ours or a third party's, and is not processed outside the environment agreed with you.
- Human decision on every finding. Automated observations are confirmed, rejected or escalated by a qualified specialist; rejections stay in the audit trail.
- Traceability. Each finding records the rule applied, the evidence relied on, a confidence rating and the human decision; ruleset and model versions are recorded in the methodology appendix.
- Reproducibility. A deliverable can be re-run and challenged against the same ruleset version.
- No client data in vendor models. Where a third-party model is used in delivery it is named in the subprocessor list before use, and the position on training and retention is documented in writing.
07Incident response
- Detection and assessment. Suspected incidents are triaged by the person accountable for information security within one working day of detection.
- Containment. Access is revoked, affected systems isolated, and evidence preserved before remediation.
- Client notification. Where an incident affects client data we notify affected clients without undue delay and within 48 hours, with what we know, what we have done, and what they need to do.
- Regulatory notification. Where we are the controller and a breach is reportable, we notify the ICO within 72 hours.
- Review. Every incident produces a written note of cause, impact and the change we have made to prevent recurrence. We will share it with affected clients.
08Business continuity
- Encrypted backups of working systems, tested periodically rather than assumed.
- Deliverables and methodologies are held in a form we can operate without a single supplier, including our own review tooling.
- Where an engagement depends on a third-party platform — a DMS, a hosting tenancy, a model provider — the exit plan is documented as part of the engagement, including how your data leaves and in what format.
- If we cannot deliver for any reason, you keep everything produced to date in editable formats, and we tell you immediately rather than quietly slipping.
09What we ask of you
- Compliance records, not privileged advice. We would rather not see privileged material, and we can work from a redacted set.
- One named contact who can answer process questions and approve scope.
- A file list for sampling, or approval of the sample we propose.
- An encrypted transfer route — ours or yours. Please do not email client documents.
- Prompt notice if you become aware of anything that affects the engagement, including a change in your own systems or a suspected incident.
10Procurement pack — one request
Email our contact address with “procurement pack” in the subject line and you will receive: company details and registration numbers, insurance certificates and schedules, the Cyber Essentials certificate where held, this security overview, the subprocessor list, our DPA template, the terms of engagement, and the synthetic sample report. Usually the same working day.