Security Statement
What we have in place today, what is still on the roadmap, and how we handle client data on the delivery floor and in our systems.
Language: this document is published in English. Any translated version is provided for convenience only — the English text is the authoritative version and prevails in the event of any inconsistency.
1. Our posture, stated plainly
Security questionnaires are where outsourcing deals stall, usually because a vendor overstates its position and then cannot evidence it. We would rather tell you exactly where we are.
What is in place today: documented policies, role-based access control, encryption in transit and at rest, multi-factor authentication across all staff accounts and on administrative, privileged and remote access, signed confidentiality agreements for every member of staff, controlled delivery-floor operations, logging and a defined incident response procedure.
What is not yet in place: we do not hold a SOC 2 Type II report or ISO 27001 certification. Both are on the roadmap with the status shown below, and we will not claim either until an auditor has issued it. Independent penetration testing is not yet a scheduled recurring exercise — we run vulnerability scanning in the build pipeline for software we develop, and we will arrange an independent test for a specific engagement where a client requires it.
2. Certification status
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | Planned | Controls implementation underway. Audit window targeted for 2026. No report currently exists. |
| ISO/IEC 27001 | In progress | ISMS scoping in progress. Not yet certified. |
| GDPR / UK GDPR | Aligned | Data Processing Agreements available. Standard Contractual Clauses used for restricted transfers. Records of processing maintained. |
| HIPAA | Aligned | Business Associate Agreement available for healthcare engagements. PHI handling training delivered before assignment to a healthcare program. |
| PCI DSS | Scoped | Where payment data is in scope we work through compliant payment processors and pause-and-resume call recording rather than storing cardholder data. |
3. Governance
- Written information security policy set, reviewed at least annually.
- A named individual accountable for information security and data protection.
- Risk register maintained, with treatment plans for identified risks.
- Security and data protection training at onboarding and on a recurring cycle.
4. People and the delivery floor
- Background and reference checks appropriate to the role and to client requirements.
- Signed confidentiality and acceptable-use agreements for all staff and contractors, surviving termination.
- Clean-desk policy on the operations floor.
- Removable media may not be connected to company devices without written authorization, on every engagement. Personal device and mobile phone use is restricted on the operations floor. For regulated engagements we go further: controlled floor access and dedicated seating for the client's program.
- Documented joiner, mover and leaver process, including same-day revocation of access on exit.
5. Access control
- Least-privilege provisioning, with access granted by role rather than by individual request.
- Multi-factor authentication for administrative, privileged and remote access, and enforced across all accounts in our productivity suite.
- Unique named accounts. Shared credentials are prohibited.
- Access reviews at least quarterly against current role, with privileged access reviewed every cycle, and immediate revocation on role change or exit.
- Agents work inside the client's own systems under the client's licenses and access controls wherever the client prefers, so data stays in the client's environment.
6. Data protection
- TLS for data in transit; encryption at rest for stored data.
- Data minimisation — we ask for the narrowest data set that lets us deliver the service.
- Segregation of client data and environments.
- Defined retention periods. Where an engagement does not specify one, client data is retained only for the duration of the engagement and returned or securely deleted within 30 days of termination; security and system logs are retained for 12 months unless a longer period is contractually required.
- Call recording and transcript handling configured to the client's regulatory requirements, including masking and pause-and-resume where needed.
7. Network and endpoint
- Managed endpoints with disk encryption, endpoint protection and centrally applied patching.
- Segmented network with firewalling between operational zones.
- Centralised logging with retention, and alerting on defined security events.
- Remote access via controlled, authenticated channels only.
8. Application and development security
- Separate development, staging and production environments.
- Peer code review before merge; no direct pushes to production branches.
- Dependency and vulnerability scanning in the build pipeline.
- Secrets held in a managed secret store, never in source control.
- Production data is not used in development or test environments without masking.
- Release through a controlled CI/CD pipeline with rollback capability.
9. AI systems
- Client data is not used to train third-party foundation models.
- AI-generated output in regulated or high-impact contexts is subject to human review or escalation.
- Prompt and output logging is configurable to the client's retention and privacy requirements.
- Every AI-supported workflow, and every AI-delivered language, is documented in the SOW.
10. Vendor management
Sub-processors and platform vendors are assessed before onboarding and reviewed periodically. Each is engaged under written contract with confidentiality and data protection obligations. A current sub-processor list is available to clients on request, and material changes are notified in line with the applicable DPA.
11. Resilience and continuity
- Redundant internet connectivity and backup power at the delivery site.
- Documented business continuity and disaster recovery plans, with defined recovery objectives per engagement.
- Work-from-home fallback capability under controlled access, where the client's compliance position permits it.
- Backups taken on a defined schedule and restore-tested.
12. Incident response
We maintain a documented incident response procedure covering detection, triage, containment, eradication, recovery and post-incident review. In the event of a confirmed personal data breach affecting a client, we notify that client without undue delay and within any period specified in the applicable agreement, and support them in meeting their own regulatory notification obligations.
13. What we ask of clients
Security is shared. We ask clients to provision access on a least-privilege basis, to notify us promptly of leavers on their side, to keep DPAs and BAAs current, and to tell us in advance when a program's data classification changes.
14. Reporting a vulnerability
If you believe you have found a security vulnerability in this website or in any system we operate, please report it to info@premiercore.solutions with "Security" in the subject line.
Please give us a reasonable opportunity to investigate and remediate before public disclosure. We will acknowledge your report and keep you updated. We will not pursue action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data beyond what is needed to demonstrate the issue.