Fracto Services Fracto Services ← Back to site
Legal

Security

Last updated: 5 June 2026

Security is core to what we do. We hold ourselves to the same standards we set for our clients — protecting information through layered technical and organisational controls, and being honest about how we work.

01 Our approach

We take a risk-based, defence-in-depth approach aligned with recognised good practice such as the UK National Cyber Security Centre (NCSC) guidance and the principles behind ISO/IEC 27001 and Cyber Essentials. Security is built into our engagements from the outset rather than added afterwards.

  • Confidentiality, integrity, and availability guide every decision.
  • Least privilege and need-to-know by default.
  • Continuous review — controls are assessed and improved, not set once.

02 Data protection

  • Encryption in transit — data exchanged with our website and systems is protected using current TLS standards.
  • Encryption at rest — sensitive data we hold is encrypted using industry-standard algorithms.
  • Data minimisation — we collect and retain only what is necessary, and delete it securely when no longer needed.
  • Confidentiality — we sign a non-disclosure agreement before any client briefing as standard.

For how we handle personal data, see our Privacy Policy.

03 Access control

  • Multi-factor authentication on business-critical accounts.
  • Role-based access on a least-privilege, need-to-know basis.
  • Strong, unique credentials managed through a password manager.
  • Access is reviewed regularly and revoked promptly when no longer required.

04 Infrastructure security

  • Reputable cloud providers operating their own certified, hardened data centres.
  • Systems kept current with security patches and updates.
  • Endpoint protection and managed device configuration.
  • Secure configuration baselines applied to the services we run.

05 People & suppliers

Our engagements are delivered only by senior practitioners — no offshore juniors and no handing your data to people we don't know. We assess the security posture of the suppliers and processors we rely on, and put written terms in place that require appropriate safeguards.

  • Security awareness is part of how we work, not an annual tick-box.
  • Suppliers are selected and reviewed with data protection in mind.

06 Monitoring & resilience

  • Logging and monitoring of key systems to detect unusual activity.
  • Backups of important data, tested for recoverability.
  • Business continuity planning so we can keep operating through disruption.

07 Incident response

We maintain a process to identify, contain, and resolve security incidents. Where an incident involves personal data and is likely to result in a risk to individuals, we will notify the Information Commissioner's Office (ICO) without undue delay and, where required, within 72 hours — and we will inform affected parties where the law requires.

08 Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in our website or systems, please tell us so we can investigate and fix it.

  • Email info@fractoservices.com with the details and steps to reproduce.
  • Give us a reasonable time to respond and remediate before any public disclosure.
  • Do not access, modify, or delete data that is not yours, and avoid any action that could harm the service or its users.

Acting in good faith under this guidance, we will not pursue or support legal action against you for your research.

09 Contact

Fracto Services Limited

Security contact: info@fractoservices.com

Registered in Northern Ireland · Company No. NI713278