Security

Security Overview

Version
1.0
Effective
5 August 2026
Last updated
5 August 2026

1. Purpose

Security is fundamental to how FirstProof designs, develops and operates its services.

This Security Overview provides a high-level summary of our approach to protecting customer information, supporting enterprise procurement, and maintaining trust.

It is intended for prospective customers, procurement teams, information security reviewers, and other stakeholders seeking an overview of our security posture.

This document is an overview only and does not replace contractual security documentation or technical due diligence where required.

2. Security Principles

Our security programme is built around the following principles:

  • Protect customer information.
  • Minimise unnecessary collection of personal data.
  • Apply security throughout the product lifecycle.
  • Restrict access using the principle of least privilege.
  • Monitor and continually improve our security controls.
  • Support customers in meeting their own security and compliance obligations.

Security is considered throughout product development and operational decision-making.

3. Infrastructure Security

The FirstProof marketing website is hosted using modern cloud infrastructure designed to provide availability, resilience, and secure delivery.

Security measures include:

  • HTTPS encryption
  • Secure hosting
  • Transport Layer Security (TLS)
  • HTTP Strict Transport Security (HSTS)
  • Continuous platform updates through our hosting provider

Infrastructure components are maintained using recognised cloud security practices.

4. Encryption

We use encryption to help protect information during transmission.

This includes:

  • encrypted communications using HTTPS/TLS
  • encrypted connections between users and our website where supported

Where personal information is processed by our services, appropriate encryption measures are applied consistent with the nature of the information being processed.

5. Access Control

Access to systems and information is restricted to authorised individuals with a legitimate business need.

Our approach includes:

  • role-based access where appropriate
  • least privilege principles
  • controlled administrative access
  • authentication mechanisms designed to protect administrative functions

Administrative access is reviewed as part of our operational governance processes.

6. Data Protection

We are committed to protecting personal information throughout its lifecycle.

Our approach includes:

  • data minimisation
  • appropriate retention periods
  • secure deletion where appropriate
  • privacy by design principles
  • documented governance policies

Personal information is processed in accordance with applicable data protection legislation and our published privacy documentation.

7. Incident Management

We maintain documented processes for responding to security incidents.

Our objectives are to:

  • identify security incidents promptly
  • investigate potential impacts
  • contain and remediate issues
  • communicate with affected parties where appropriate
  • continually improve our security practices

Where a personal data breach occurs, we aim to respond in accordance with applicable legal and contractual obligations.

8. Responsible AI

FirstProof incorporates artificial intelligence to support structured assessment workflows.

Our approach to AI includes:

  • human oversight
  • configurable AI-assisted functionality
  • documented governance controls
  • transparency regarding AI use
  • ongoing review of AI-related risks

FirstProof does not position AI as replacing human decision-making in recruitment or employment decisions.

9. Compliance

Our governance framework is designed to support compliance with applicable legal and regulatory requirements, including:

  • UK GDPR
  • Data Protection Act 2018
  • applicable contractual obligations
  • relevant principles of the EU AI Act for high-risk AI systems

Compliance is supported through documented policies, governance procedures, and regular review.

10. Enterprise Security Documentation

Where appropriate and subject to confidentiality requirements, additional documentation may be made available during customer procurement or due diligence processes.

This may include:

  • Data Processing Agreement (DPA)
  • Technical and Organisational Measures (TOMs)
  • AI governance documentation
  • privacy documentation
  • security questionnaires
  • subprocessor information

The availability of specific documentation may depend on the nature of the customer relationship and applicable confidentiality obligations.

11. Reporting Security Concerns

If you believe you have identified a security issue relating to FirstProof, please contact us as soon as possible.

Email:

support@firstproof.co.uk

Please include sufficient information to help us understand and investigate the issue.

We appreciate responsible disclosure and will review all genuine security reports.

12. Continuous Improvement

Security is an ongoing process.

We regularly review our governance framework, policies, operational procedures, and technical controls to improve our security posture as our products, services, and customer requirements evolve.

13. Contact

If you have questions regarding this Security Overview or our approach to information security, please contact:

First Proof UK Ltd

Suite A 82 James Carter Road Mildenhall IP28 7DE United Kingdom

Company Number: 16961002

Email:

support@firstproof.co.uk

Document Control

ItemValue
Document NameSecurity Overview
Version1.0
ClassificationPublic
OwnerChief Legal Officer
Approved ByFirst Proof UK Ltd
Effective Date5 August 2026
Review FrequencyAnnual
Next Review5 August 2027

Cookie Preferences

Essential cookies operate the website and remember your choice. Optional analytics help us improve the site, while optional functional storage enables the feedback and support feature.

Read our Cookie Policy and Website Privacy Policy.