Independently
audited.

Four certifications, each assessed by an external body and renewed annually. The certificates are on this page — numbers, dates, scope and all — so your procurement team can check them rather than take our word for it.

ISO 42001:2023

AI Management System

The international standard for managing AI responsibly: risk assessment, human oversight, data-boundary controls and accountability for what ships. It is why we can tell you how AI was used on your project rather than asking you to take it on trust.

Certifying body
Cardan Compliance Services
Certificate number
CARCERT00206
Issued
26 March 2026
Valid until
25 March 2027

Scope

The design, development and delivery of custom software solutions, including web and mobile applications, product strategy consulting and UI/UX design services — covering all supporting business functions, infrastructure and personnel.

Download certificate (PDF)

ISO 27001:2022

Information Security Management System

The international standard for information security management. It governs how client data, credentials and source code are handled and protected across every engagement.

Certifying body
Cardan Compliance Services
Certificate number
CARCERT00202
Issued
27 October 2025
Valid until
26 October 2026

Scope

The design, development and delivery of custom software solutions, including web and mobile applications, product strategy consulting and UI/UX design services — covering all supporting business functions, infrastructure and personnel.

Download certificate (PDF)

Cyber Essentials

UK Government-backed Cyber Security Scheme

Baseline endpoint, network and access security across our operating environment, assessed against the UK scheme that many public-sector and regulated buyers require before they will contract at all.

Certifying body
IASME Consortium, assessed by ITPS
Certificate number
77c1fa32-49e2-4605-a6bf-1a7532808c12
Issued
30 March 2026
Valid until
30 March 2027

Scope

Whole organisation. Assessed against profile version 3.2 (Willow).

Download certificate (PDF)

IASME Cyber Baseline

Level One

Organisational and supply-chain security governance — the assurance a buyer's procurement team asks for when we sit inside their supply chain rather than beside it.

Certifying body
IASME Consortium
Certificate number
f3f5881d-77f5-426c-ad0a-ed42bbfbfbae
Issued
18 February 2026
Valid until
18 February 2027

Scope

Whole organisation. Subject to continuous assessment and independent annual review.

Download certificate (PDF)

A certificate is only worth
what it changes.

Certification obliges us to evidence how work is actually done, which is why the evidence is built into delivery rather than assembled when someone asks. The audit trail is a by-product of the way we work, not a document we write afterwards.

You can see the same delivery data we work from — release history, health, what shipped and when, what is awaiting your approval — in the Bitcube Hub.

What it covers

AI use

Approved tools, defined contexts, documented data handling and human review before anything reaches your codebase.

Your data

How client data, credentials and source code are handled and protected, across every engagement.

Our environment

Endpoint, network and access security across the machines and accounts our people work from.

Supply chain

Organisational governance, reviewed independently each year rather than self-declared.

Need something we haven't listed?

Security questionnaires, insurance details, DPAs, sub-processor lists — if your procurement process needs it, ask and we will send it.

Talk to us