1. Purpose
Security is fundamental to how FirstProof designs, develops and operates its services.
This Security Overview provides a high-level summary of our approach to protecting customer information, supporting enterprise procurement, and maintaining trust.
It is intended for prospective customers, procurement teams, information security reviewers, and other stakeholders seeking an overview of our security posture.
This document is an overview only and does not replace contractual security documentation or technical due diligence where required.
2. Security Principles
Our security programme is built around the following principles:
- Protect customer information.
- Minimise unnecessary collection of personal data.
- Apply security throughout the product lifecycle.
- Restrict access using the principle of least privilege.
- Monitor and continually improve our security controls.
- Support customers in meeting their own security and compliance obligations.
Security is considered throughout product development and operational decision-making.
3. Infrastructure Security
The FirstProof marketing website is hosted using modern cloud infrastructure designed to provide availability, resilience, and secure delivery.
Security measures include:
- HTTPS encryption
- Secure hosting
- Transport Layer Security (TLS)
- HTTP Strict Transport Security (HSTS)
- Continuous platform updates through our hosting provider
Infrastructure components are maintained using recognised cloud security practices.
4. Encryption
We use encryption to help protect information during transmission.
This includes:
- encrypted communications using HTTPS/TLS
- encrypted connections between users and our website where supported
Where personal information is processed by our services, appropriate encryption measures are applied consistent with the nature of the information being processed.
5. Access Control
Access to systems and information is restricted to authorised individuals with a legitimate business need.
Our approach includes:
- role-based access where appropriate
- least privilege principles
- controlled administrative access
- authentication mechanisms designed to protect administrative functions
Administrative access is reviewed as part of our operational governance processes.
6. Data Protection
We are committed to protecting personal information throughout its lifecycle.
Our approach includes:
- data minimisation
- appropriate retention periods
- secure deletion where appropriate
- privacy by design principles
- documented governance policies
Personal information is processed in accordance with applicable data protection legislation and our published privacy documentation.
7. Incident Management
We maintain documented processes for responding to security incidents.
Our objectives are to:
- identify security incidents promptly
- investigate potential impacts
- contain and remediate issues
- communicate with affected parties where appropriate
- continually improve our security practices
Where a personal data breach occurs, we aim to respond in accordance with applicable legal and contractual obligations.
8. Responsible AI
FirstProof incorporates artificial intelligence to support structured assessment workflows.
Our approach to AI includes:
- human oversight
- configurable AI-assisted functionality
- documented governance controls
- transparency regarding AI use
- ongoing review of AI-related risks
FirstProof does not position AI as replacing human decision-making in recruitment or employment decisions.
9. Compliance
Our governance framework is designed to support compliance with applicable legal and regulatory requirements, including:
- UK GDPR
- Data Protection Act 2018
- applicable contractual obligations
- relevant principles of the EU AI Act for high-risk AI systems
Compliance is supported through documented policies, governance procedures, and regular review.
10. Enterprise Security Documentation
Where appropriate and subject to confidentiality requirements, additional documentation may be made available during customer procurement or due diligence processes.
This may include:
- Data Processing Agreement (DPA)
- Technical and Organisational Measures (TOMs)
- AI governance documentation
- privacy documentation
- security questionnaires
- subprocessor information
The availability of specific documentation may depend on the nature of the customer relationship and applicable confidentiality obligations.
11. Reporting Security Concerns
If you believe you have identified a security issue relating to FirstProof, please contact us as soon as possible.
Email:
support@firstproof.co.uk
Please include sufficient information to help us understand and investigate the issue.
We appreciate responsible disclosure and will review all genuine security reports.
12. Continuous Improvement
Security is an ongoing process.
We regularly review our governance framework, policies, operational procedures, and technical controls to improve our security posture as our products, services, and customer requirements evolve.
13. Contact
If you have questions regarding this Security Overview or our approach to information security, please contact:
First Proof UK Ltd
Suite A 82 James Carter Road Mildenhall IP28 7DE United Kingdom
Company Number: 16961002
Email:
Document Control
| Item | Value |
|---|---|
| Document Name | Security Overview |
| Version | 1.0 |
| Classification | Public |
| Owner | Chief Legal Officer |
| Approved By | First Proof UK Ltd |
| Effective Date | 5 August 2026 |
| Review Frequency | Annual |
| Next Review | 5 August 2027 |