Skip to content

Everything a procurement officer needs to send to a compliance colleague.

Insurance cover, partner programmes, how we handle access, code and data, who else touches your data, and what happens if something goes wrong. Your code never touches our laptops, changes to your environment are made as code with a name and a time, and every copy of your data has a chain of custody. This page is written to be forwarded and printed, and everything on it is available as documentation on request.

Last reviewed 7 September 2026. Reviewed quarterly and after any change to insurance, partners or subprocessors.

Legal entity
ItemDetail
Legal nameHexploits Ltd
Company number11669296
VAT numberGB481356383
Registered office71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Trading sinceNovember 2018
Headcount100+
ICO registrationZB895216
TrademarkHexploits is a registered trademark of Hexploits Ltd.

Programmes we are members of. We do not hold ISO or Cyber Essentials certification today; our engineering practice is built to ISO 27001-aligned controls and that is stated as alignment, not certification.

  • Amazon Web Services

    AWS Partner Network

    Member

    Cloud architecture, migration and managed platforms on AWS, in the client’s own account.

    Programme details
  • Anthropic

    Anthropic Partner Network

    Member

    Applied AI on Claude under enterprise terms with no training on client data, alongside private open-weight models where residency requires it.

    Programme details
Insurance cover
CoverLimit
Professional indemnity£5,000,000
Cyber and data£1,000,000

Further cover is held and disclosed in proposals. Certificates are provided on request and attached to every proposal.

How we work inside your systems. Each practice is documented, and the documents are provided on request.

  • Access

    Named accounts only, single sign-on with hardware-key MFA and conditional access policies, least-privilege roles, quarterly access review, and offboarding within one working day. Every credential lives in a company password manager; nothing is shared over chat or email.

  • Your code never touches our laptops

    All client code is worked on in virtualised development environments (Coder) behind a VPN, under conditional access policies. Nothing is cloned to an engineer’s device. The environments are destroyed when the engagement ends.

  • Devices

    Company laptops enrolled in Microsoft Intune, with full-disk encryption, screen lock, managed updates and endpoint protection. No client data on personal devices.

  • Chain of custody for your data

    Every copy of client data is recorded and audited from the day we receive it to the day it is deleted, so we can show where it has been, who touched it, and that nothing insecure remains once the work is done. Deletion is confirmed in writing.

  • Changes to your environment as code

    Infrastructure and environment changes are made as code (Terraform) through CI/CD, from the virtualised environments, each with a name and a timestamp. Nobody has direct access to your environment except named DevOps operators, and only if you choose to grant it.

  • Development

    Code review on every change, dependency scanning, secrets kept in a vault and never in source, and production changes through a pipeline with an audit trail.

  • Incidents

    A written incident process with a named owner, and notification without undue delay and in any case within 72 hours of any incident affecting your data. You also get a client-facing incident portal: report issues, bugs or security concerns and they go straight to the engineering team and are triaged as the top priority.

  • Continuity

    Documented runbooks for every managed system, tested restores, and at least two engineers familiar with each client environment.

  • Documentation on request

    All of the above is available as written documentation: access and device policies, the environment and change-control model, the chain-of-custody process and the incident process. Ask and it is sent with the proposal.

We act as a processor for client data under a data processing agreement that forms part of every contract. Client data stays in the client's own systems and accounts wherever the engagement allows. Where we must hold a copy, it is encrypted at rest and in transit, access is limited to named engineers on the engagement, and it is deleted at the end of the engagement with written confirmation.

Data is hosted in the UK or EU by default. Transfers outside the UK and EU happen only where a client chooses a service that requires it, and are covered by the UK International Data Transfer Agreement or EU standard contractual clauses.

AI model providers (Anthropic and OpenAI) are used under enterprise terms that exclude training on inputs, with EU residency. Where a client prefers, open-weight models are served on Hexploits Cloud LLM in the EU, owned by Hexploits, with no training on inputs and no logging of prompts or outputs, so nothing leaves the client's boundary. Which applies is stated per system in the statement of work.

Third parties that may process client data in the course of an engagement. Clients are notified of changes 30 days in advance.

Subprocessors
ProviderPurposeLocation
Amazon Web ServicesHosting in the client’s own accountEU (eu-west-1 Ireland or eu-west-2 London)
Microsoft 365Email, calendar and document collaborationUK / EU
Hexploits CloudReserved Kubernetes capacity and hosting, owned and operated by HexploitsEU
GitLab (self-hosted)Source control and CI, hosted on Hexploits CloudEU
Jira (Atlassian cloud)Work tracking and the client incident portalUK (data residency locked to the UK)
CloudflareDNS, TLS, bot protectionGlobal (EU data localisation available)
PostHogWebsite analyticsEU
Anthropic and OpenAIModel APIs where a client engagement uses them, under enterprise terms with no training on inputsEU residency
Hexploits Cloud LLMOpen-weight models served on Hexploits Cloud: no training on inputs, no logging of prompts or outputs. Owned by HexploitsEU
  • Key-person cover

    At least two engineers are familiar with every managed client environment. Runbooks are kept current so that cover does not depend on memory.

  • Backups and recovery

    Managed systems are backed up on a schedule agreed per system, with restores tested at least quarterly and recovery objectives written into the service schedule.

  • Our own systems

    Source control, CI and documentation run on Hexploits Cloud in the EU with off-site backups. Loss of our office or any single provider does not stop client work.

  • Incident communication

    A named incident owner, a client-facing incident portal for issues, bugs and security concerns, a status page for managed clients, and notification without undue delay and in any case within 72 hours of any incident affecting client data.

  • If Hexploits ceased trading

    Because code, infrastructure and accounts are in the client’s name from the start, a client can continue with any other supplier without our involvement. Handover documentation is part of the standard managed contract, not an extra.

Provided on request, and attached to every proposal.

  • Insurance certificates

    PDF

  • Data processing agreement

    Standard terms; we will work on yours

  • Information security policy summary

    On request

  • Security practices documentation

    Access and devices, virtualised environments, change control as code, chain of custody, incident process

  • Completed supplier security questionnaire

    CAIQ or your template

Questions about anything on this page: [email protected] or request the documents.

Send us your security questionnaire.

We complete it, with evidence, as part of a proposal. If we cannot meet a requirement we say so in the response rather than on the first day.