Security, privacy and assurance information in one place.
This page brings together the main documents and supporting information that clients, procurement teams and security reviewers may need when assessing CommsPliant.
Some resources are public. Others are provided on request or during client onboarding where the material contains controlled or internal detail.
Public Resources
Available on Request
| Resource | Availability | Action |
|---|---|---|
| CommsPliant Security & Trust Summary |
|
Request access |
| Data Processing Agreement |
|
Request access |
| Client-facing Subprocessor List |
|
Request access |
| Security and Privacy Supporting Information |
|
Request access |
Controlled Evidence
Detailed internal evidence is not published openly where it could expose unnecessary operational or security information.
Where appropriate, CommsPliant can provide controlled evidence or summaries supporting areas such as:
| Resource | Availability | Action |
|---|---|---|
| Backup and restore testing evidence |
|
Request access |
| Incident-response exercise evidence |
|
Request access |
| Business-continuity testing evidence |
|
Request access |
| Governance audit trail evidence |
|
Request access |
| Access-control review evidence |
|
Request access |
| Security testing evidence |
|
Request access |
| Change and deployment evidence |
|
Request access |
A request does not automatically mean the full internal record or raw evidence will be provided. Depending on the purpose of the review, CommsPliant may provide a client-facing version, extract, summary or other controlled evidence instead.
Key Supporting Documents
The following documents form part of the CommsPliant trust and assurance framework:
| Resource | Availability | Action |
|---|---|---|
| Information Security Policy |
|
Request access |
| Access Control and Privileged Access Policy |
|
Request access |
| Logging and Security Monitoring Standard |
|
Request access |
| Change Management and Secure Development Procedure |
|
Request access |
| Supplier Management Policy |
|
Request access |
| Backup and Restore Procedure |
|
Request access |
| Incident Response and Personal Data Breach Procedure |
|
Request access |
| Business Continuity and Disaster Recovery Plan |
|
Request access |
| Data Subject Rights Procedure |
|
Request access |
| Retention and Deletion Schedule |
|
Request access |
| Data Processing Agreement |
|
Request access |
| Client-facing Subprocessor List |
|
Request access |
| Security & Trust Summary |
|
Request access |
| Security and Privacy Risk Register |
|
Request access |
| ISO 27001 Evidence Register |
|
Request access |
Not every internal document is intended for public distribution. A request for access does not automatically mean the full internal document will be shared. Appropriate client-facing versions, extracts, summaries or controlled evidence can be provided where that is more suitable.
FAQ
CommsPliant publishes its main Trust Center information covering security, privacy, data flow, subprocessors and resilience. The Privacy Notice and relevant public Trust Center pages are also available without a separate request.
Yes. Appropriate client-facing information can be provided during procurement, due diligence or onboarding, including the CommsPliant Security & Trust Summary and relevant supporting information.
Yes. An approved Data Processing Agreement baseline is available for client onboarding. Client-specific processing details are completed before live client processing begins.
It is a concise client-facing overview of CommsPliant's current security, privacy, access-control, monitoring, resilience and assurance framework. It is available on request for due-diligence and procurement reviews.
Some detailed internal evidence is controlled because publishing it openly could expose unnecessary operational or security information. Where appropriate, CommsPliant can provide client-facing summaries, extracts or controlled evidence during procurement or security review.
Still have questions?
If you're not sure which document, summary or evidence you need, contact us and we'll help you find the right information.
Request more informationRequest Information
If you are reviewing CommsPliant for procurement, security, privacy or compliance purposes, request the information you need and we will provide the appropriate public, client-facing or controlled material.
Request trust informationThis page is the Trust Center library. It shows what is public, what is available on request, and what is shared during client onboarding or due diligence.