FOR SECURITY, COMPLIANCE & PROCUREMENT

Make infrastructure assurance specific enough to verify.

Review where data lives, how access is controlled, what is monitored, how recovery is designed and which team owns each layer. Where a claim depends on the deployment or contract, DC Core says so.

ISO 27001 and SOC 2 readiness are roadmap positions—not completed certifications.

ASSURANCE WITHOUT THEATRE

Answer the control question—and its boundary.

A technically true statement can still mislead when its scope is hidden. DC Core pairs security and resilience claims with the service, environment and customer responsibility to which they apply.

02 / CONTROL

Describe access from identity to workload

Review authentication, roles, tenant and device ownership, command authorisation, logging and the distinction between platform access and permissions inside customer applications.

  • WebAuthn and MFA where applicable
  • Least-privilege operating model
03 / RESILIENCE

Keep design features separate from commitments

Backup, replication and recovery mechanisms support resilience, while customer-specific RPO, RTO, standby capacity and support commitments must be agreed contractually.

  • Service-specific objectives
  • Explicit contractual boundary

THE ASSURANCE ROUTE

Public answers first. Deployment evidence second.

The public Trust Centre should answer common questions without an NDA. Customer-specific material is then matched to the service and confidentiality required.

Browse public resources
  1. 01

    Review the public control position

    Start with data processing, residency, encryption, access, logging, suppliers, recovery, support and current compliance progress.

  2. 02

    State the proposed service and deployment

    Identify the workload, data types, locations, recovery needs, integrations and infrastructure that would be inside or outside DC Core control.

  3. 03

    Map responsibility and exceptions

    Document customer duties, third-party dependencies, transitional controls and any requirement that differs from the standard managed design.

  4. 04

    Agree evidence and commitments

    Provide appropriate supporting material and ensure service levels, recovery objectives or dedicated arrangements that matter are contractual.

CURRENT POSITION

Treat roadmap items as roadmap items.

DC Core publishes the controls it can describe today and avoids presenting planned certifications as completed assurance.

AreaWhat can be reviewed nowWhat still depends on scope or progress
Platform controlsAccess principles, encrypted connectivity, logging, monitoring, segmentation and operating boundaries.Deployment-specific implementation and customer-side controls.
Data handlingStandard UK/EU managed design, processing categories and global relay distinction.Customer-selected providers, exceptional locations and workload-specific flows.
RecoveryManaged backup approach, recovery locations and periodic restore-process checks.Contractual RPO/RTO, retention, dedicated capacity and application-level testing.
CertificationCurrent readiness roadmap and assurance materials available for the proposed service.ISO 27001, SOC 2 and Cyber Essentials are not represented as completed certifications.
BUYER CHECKIf a completed certification is mandatory at procurement stage, confirm that requirement before investing time in technical scoping.

LIKELY STARTING POINTS

Review assurance, recovery and external exposure together.

CUSTOMER DUE DILIGENCE

Send the service and control questions that matter.

We will route public answers first, identify deployment-specific questions and provide appropriate assurance material where available and justified.

Request assurance