Security, privacy and how we handle your data.
This page is maintained by Stratford Ellis to answer the common security and privacy questions we get from clients in the property, construction and infrastructure sectors. We hold ISO 9001, 14001, 45001 and 50001 certification to 2029. Everything else here describes our own practices and commitments, not an audit report, and we say which is which.
Straight answers on standards.
Plenty of consultancies imply certifications they do not hold. We would rather tell you exactly where we stand, because your security team will check.
Group recertification against ISO 9001, 14001, 45001 and 50001.
Our management systems have been recertified across the Group, with certificates valid to 2029. These cover quality, environment, health and safety, and energy. Certificates are available on request for procurement and vendor onboarding.
ISO 9001
to 2029Quality management
How we run engagements: scoping, review, delivery and how we handle things when they go wrong.
ISO 14001
to 2029Environmental management
Our environmental management system, including travel, hardware and supplier choices.
ISO 45001
to 2029Occupational health and safety
Health and safety management for our own people, including work on client sites.
ISO 50001
to 2029Energy management
How we measure and reduce the energy our operations use.
ISO/IEC 27001 control alignment
Our internal practices are mapped to the ISO 27001 Annex A control themes: access control, people, physical and technological controls. Alignment is not certification: we are not currently able to present an ISO 27001 certificate, and we will say so plainly in any procurement process.
SOC 2 Trust Services Criteria
We use the SOC 2 criteria for security, confidentiality and availability as the reference model for how we handle client systems and data. We do not hold a completed SOC 2 Type I or Type II report, and we do not describe ourselves as SOC 2 certified.
Cyber Essentials
Cyber Essentials covers the fundamentals we already operate: boundary firewalls, secure configuration, access control, malware protection and patch management. Ask us for our current certification status and we will confirm it in writing, not on a web page.
Independent evidence on request
For procurement, vendor onboarding or a DPIA, we will complete your security questionnaire, walk your security team through our controls, and sign up to the contractual commitments you need. That is stronger evidence than a badge.
What we do by default on every engagement.
NDAs by default.
Every engagement starts under a mutual NDA. If you have your own template, we will sign yours.
We work inside your environment.
For sensitive engagements we work inside your tenant, VPN and tooling, so client data does not leave your perimeter.
Least-privilege access.
Access is scoped to the systems and datasets the engagement needs, time-boxed, and revoked at the end.
MFA and managed credentials.
Multi-factor authentication on every account we control, password managers instead of shared logins, and no credentials in email or chat.
Encrypted, managed devices.
Full-disk encryption, screen locks, current OS patch levels and endpoint protection on every device used on client work.
Named team, no silent subcontracting.
You know who is on your account. We do not offshore delivery or bring in subcontractors without your written agreement.
Background-checked people.
Identity and right-to-work checks on everyone who touches client systems, plus confidentiality terms in every contract.
Data minimisation.
We ask for the narrowest dataset that answers the question: anonymised, sampled or masked wherever that is sufficient.
Clear incident reporting.
Anything that could affect your data goes to your named contact promptly, with the facts as we know them at the time.
GDPR aligned, wherever you operate.
We align our handling of personal data with the UK GDPR and the EU GDPR. Where an engagement involves personal data, we act as processor under your instructions, sign a Data Processing Agreement, and agree the lawful basis, scope, retention and deletion approach before any data moves.
For clients in the United States, we support obligations under the California Consumer Privacy Act as amended by the CPRA, and the comparable state privacy laws that follow its pattern. We do not sell or share personal information, and we do not use client data for our own purposes, marketing or model training.
Cross-border transfers are handled with the appropriate mechanism for the route: UK IDTA or Addendum, EU Standard Contractual Clauses, or keeping the data resident in your own environment, which is usually the simplest answer.
Privacy requests. If you are an individual and want to know what personal data we hold about you, or want it corrected or deleted, contact us and we will respond within the statutory timeframe. Where the data sits in a client's system and we are only the processor, we will pass the request to that client and support them in answering it.
Read our privacy policyWe do not keep what we no longer need.
Client data is held only for as long as the engagement requires it. At the end of an engagement we return or delete working copies, revoke our access to your systems, and confirm in writing what has been removed. If you need a formal certificate of destruction, ask and we will provide one.
We retain engagement records (contracts, correspondence, invoices and our own working notes) for as long as we are legally and commercially required to. Those records do not include your operational datasets.
Where possible we avoid holding your data at all: working inside your tenant means there is nothing to return at the end because nothing ever left.
Named per engagement, never a surprise.
The tools involved in an engagement depend on the engagement, so we list them where they belong: in the DPA schedule you sign, not in a generic web page that may be out of date by the time you read it.
Our commitments are the same in every case. We name every subprocessor that could touch your data before work starts, we tell you where it is hosted, we give you notice before adding a new one, and you can object. Wherever your environment can host the work instead, we default to that.
This website uses a small number of analytics cookies, and only after you accept them. Nothing you submit through our contact form or booking page is used for anything other than replying to you.
We hold up our end. You control access.
Security in a consulting engagement is a partnership. We are responsible for how we handle the data you give us: the devices, accounts, channels and processes we use. You are responsible for what access we are granted, to which systems, and for how long.
Where an engagement includes software we build or platforms we configure, responsibility shifts again: we are accountable for building to the standard we agreed, and you or your chosen vendor are accountable for operating it once it is live. We set that boundary out in writing so it is not left implied.
We will always work within the constraints your security team sets. If those need tightening for a particular dataset, tell us. Remote-only working, isolated environments, restricted exports and short-lived credentials are all options we support.
Tell us, and we will act on it.
Security incidents
If you believe client data has been exposed, contact us immediately. We acknowledge reports within one business day and keep your named contact updated as we establish the facts.
Vulnerability reports
Found an issue in this site or something we built? Report it to us with enough detail to reproduce it. We will not pursue anyone who reports in good faith and does not access or alter other people's data.
Procurement & questionnaires
Need a completed security questionnaire, a DPA, insurance details or a call with your security team? Ask and we will turn it round quickly.
For anything on this page, email security@stratfordellis.com or use the contact form. We would rather answer a hard question early than have it surface halfway through an engagement.
Start with advice, not a sales pitch.
Book a call and we will give you an independent read on your data, systems and operations. Where the money is leaking, what to fix first, what it should cost. You leave with a plan you own, whether or not we build it.



