Security and data protection are embedded into For-Sight's platform architecture, operational processes, and organisational culture. Our ISO-certified management systems provide the framework for continuous, verifiable protection.
For-Sight operates as a GDPR-aligned data processor. We process data only as instructed by customers under documented agreements.
Our customers remain data controllers for their guest data. Lawful basis, consent, and data subject rights are customer responsibilities.
Responsibilities are documented in our Data Processing Agreement. Security is a shared responsibility with clear boundaries.
Our certifications are actively maintained and independently audited. They represent ongoing operational discipline, not one-off achievements.
Provides independent validation of our information security management system. Covers risk management, access controls, incident response, and continuous improvement. Audited annually by Citation.
Ensures consistent service quality and reliable delivery. Covers process documentation, customer focus, and continuous improvement. Audited annually by Citation.


Enforced controls across the platform protect your data throughout its lifecycle. These are operational realities, not policy statements.
Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Encryption is enforced at the infrastructure level with no opt-out.
Role-based access with least-privilege principles. Multi-factor authentication is enforced for all staff access. Permissions are reviewed regularly.
All data is hosted in UK and EU Microsoft Azure data centres. No data is transferred outside these jurisdictions without explicit agreement.
Per-customer logical segregation is enforced at both application and database levels. Customer data is never co-mingled.
Continuous monitoring with regular internal reviews. External audits are conducted annually in line with ISO 27001 certification requirements.
We use a risk-based approach to identify and manage vulnerabilities, with regular security assessments and reviews. Issues are prioritised, tracked, and resolved in line with risk and agreed service levels.
Security and compliance ownership is clearly assigned and actively managed, not delegated to policy documents.
Dedicated security and compliance roles with clear accountability for controls and certifications.
Formal risk registers and Data Protection Impact Assessments inform control decisions and priorities.
Security policies are reviewed annually and updated in response to changes in risk or regulation.
Documented incident response procedures are tested and maintained as part of ISO 27001 compliance.
A formal incident response process is in place and documented. In the event of a security incident, our team assesses impact, contains the issue, and initiates remediation. Where a personal data breach occurs, notification to affected customers and relevant authorities is made within GDPR-required timeframes. Our process is aligned with ISO 27001 requirements and tested regularly.
Strong security outcomes require clear responsibilities on both sides. Here's how we divide them.
Common questions from procurement, legal, and IT security teams.
For security questionnaires, Data Processing Agreements, audit documentation, or other procurement-related queries, contact our security team. We respond to standard security questionnaires as part of normal enterprise operations.