Security, privacy, and trust between companies
An ecosystem only works if the companies inside it can trust the building, the network, and each other. This is what we do, written so a reviewer can check it.
The practices described here are the intended programme for this build. Certifications, audit reports, and sub-processor lists must be published here before launch, and nothing on this page should be represented to a customer until it is true and evidenced.
What we cover
Network security
Segmented networks per office, WPA3 on member Wi-Fi, and the option of a dedicated VLAN or private line for teams that need one. Guest traffic never shares a segment with member traffic.
Physical security
Keycard or mobile-key access on every door that matters, CCTV in common areas, visitor registration at reception, and access logs retained to a documented schedule.
Data protection
Member data is processed on a documented lawful basis, held in-region where the law requires it, and deleted on a published retention schedule. Sub-processors are listed and reviewed.
Confidentiality between companies
Deep collaboration requires trust. Member companies keep their intellectual property, and the center’s conduct rules and specialist agreements are built to protect it.
Resilience
Redundant connectivity at every center, backup power where the market requires it, and documented incident response with named owners.
Vulnerability disclosure
A published disclosure programme with a three-business-day acknowledgement, safe-harbour language, and credit for researchers who want it.
Reporting a vulnerability
Send the issue, the steps to reproduce it, and its likely impact to our disclosure address. We acknowledge within three business days.
Read the disclosure policyDue diligence requests
Security questionnaires, data-processing agreements, and architecture reviews go to your center team, or to us directly if you are still evaluating.
Contact us