Everything a procurement officer needs to send to a compliance colleague.
Insurance cover, partner programmes, how we handle access, code and data, who else touches your data, and what happens if something goes wrong. Your code never touches our laptops, changes to your environment are made as code with a name and a time, and every copy of your data has a chain of custody. This page is written to be forwarded and printed, and everything on it is available as documentation on request.
Last reviewed 7 September 2026. Reviewed quarterly and after any change to insurance, partners or subprocessors.
Company
| Item | Detail |
|---|---|
| Legal name | Hexploits Ltd |
| Company number | 11669296 |
| VAT number | GB481356383 |
| Registered office | 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom |
| Trading since | November 2018 |
| Headcount | 100+ |
| ICO registration | ZB895216 |
| Trademark | Hexploits is a registered trademark of Hexploits Ltd. |
Partners
Programmes we are members of. We do not hold ISO or Cyber Essentials certification today; our engineering practice is built to ISO 27001-aligned controls and that is stated as alignment, not certification.
Amazon Web Services
AWS Partner Network
Member
Cloud architecture, migration and managed platforms on AWS, in the client’s own account.
Programme detailsAnthropic
Anthropic Partner Network
Member
Applied AI on Claude under enterprise terms with no training on client data, alongside private open-weight models where residency requires it.
Programme details
Insurance
| Cover | Limit |
|---|---|
| Professional indemnity | £5,000,000 |
| Cyber and data | £1,000,000 |
Further cover is held and disclosed in proposals. Certificates are provided on request and attached to every proposal.
Security practices
How we work inside your systems. Each practice is documented, and the documents are provided on request.
Access
Named accounts only, single sign-on with hardware-key MFA and conditional access policies, least-privilege roles, quarterly access review, and offboarding within one working day. Every credential lives in a company password manager; nothing is shared over chat or email.
Your code never touches our laptops
All client code is worked on in virtualised development environments (Coder) behind a VPN, under conditional access policies. Nothing is cloned to an engineer’s device. The environments are destroyed when the engagement ends.
Devices
Company laptops enrolled in Microsoft Intune, with full-disk encryption, screen lock, managed updates and endpoint protection. No client data on personal devices.
Chain of custody for your data
Every copy of client data is recorded and audited from the day we receive it to the day it is deleted, so we can show where it has been, who touched it, and that nothing insecure remains once the work is done. Deletion is confirmed in writing.
Changes to your environment as code
Infrastructure and environment changes are made as code (Terraform) through CI/CD, from the virtualised environments, each with a name and a timestamp. Nobody has direct access to your environment except named DevOps operators, and only if you choose to grant it.
Development
Code review on every change, dependency scanning, secrets kept in a vault and never in source, and production changes through a pipeline with an audit trail.
Incidents
A written incident process with a named owner, and notification without undue delay and in any case within 72 hours of any incident affecting your data. You also get a client-facing incident portal: report issues, bugs or security concerns and they go straight to the engineering team and are triaged as the top priority.
Continuity
Documented runbooks for every managed system, tested restores, and at least two engineers familiar with each client environment.
Documentation on request
All of the above is available as written documentation: access and device policies, the environment and change-control model, the chain-of-custody process and the incident process. Ask and it is sent with the proposal.
Data handling
We act as a processor for client data under a data processing agreement that forms part of every contract. Client data stays in the client's own systems and accounts wherever the engagement allows. Where we must hold a copy, it is encrypted at rest and in transit, access is limited to named engineers on the engagement, and it is deleted at the end of the engagement with written confirmation.
Data is hosted in the UK or EU by default. Transfers outside the UK and EU happen only where a client chooses a service that requires it, and are covered by the UK International Data Transfer Agreement or EU standard contractual clauses.
AI model providers (Anthropic and OpenAI) are used under enterprise terms that exclude training on inputs, with EU residency. Where a client prefers, open-weight models are served on Hexploits Cloud LLM in the EU, owned by Hexploits, with no training on inputs and no logging of prompts or outputs, so nothing leaves the client's boundary. Which applies is stated per system in the statement of work.
Subprocessors
Third parties that may process client data in the course of an engagement. Clients are notified of changes 30 days in advance.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting in the client’s own account | EU (eu-west-1 Ireland or eu-west-2 London) |
| Microsoft 365 | Email, calendar and document collaboration | UK / EU |
| Hexploits Cloud | Reserved Kubernetes capacity and hosting, owned and operated by Hexploits | EU |
| GitLab (self-hosted) | Source control and CI, hosted on Hexploits Cloud | EU |
| Jira (Atlassian cloud) | Work tracking and the client incident portal | UK (data residency locked to the UK) |
| Cloudflare | DNS, TLS, bot protection | Global (EU data localisation available) |
| PostHog | Website analytics | EU |
| Anthropic and OpenAI | Model APIs where a client engagement uses them, under enterprise terms with no training on inputs | EU residency |
| Hexploits Cloud LLM | Open-weight models served on Hexploits Cloud: no training on inputs, no logging of prompts or outputs. Owned by Hexploits | EU |
Business continuity
Key-person cover
At least two engineers are familiar with every managed client environment. Runbooks are kept current so that cover does not depend on memory.
Backups and recovery
Managed systems are backed up on a schedule agreed per system, with restores tested at least quarterly and recovery objectives written into the service schedule.
Our own systems
Source control, CI and documentation run on Hexploits Cloud in the EU with off-site backups. Loss of our office or any single provider does not stop client work.
Incident communication
A named incident owner, a client-facing incident portal for issues, bugs and security concerns, a status page for managed clients, and notification without undue delay and in any case within 72 hours of any incident affecting client data.
If Hexploits ceased trading
Because code, infrastructure and accounts are in the client’s name from the start, a client can continue with any other supplier without our involvement. Handover documentation is part of the standard managed contract, not an extra.
Documents
Provided on request, and attached to every proposal.
Insurance certificates
PDF
Data processing agreement
Standard terms; we will work on yours
Information security policy summary
On request
Security practices documentation
Access and devices, virtualised environments, change control as code, chain of custody, incident process
Completed supplier security questionnaire
CAIQ or your template
Questions about anything on this page: [email protected] or request the documents.
Next step
Send us your security questionnaire.
We complete it, with evidence, as part of a proposal. If we cannot meet a requirement we say so in the response rather than on the first day.