Least privilege
Administrative and service access is limited to defined operational purposes. Role-based controls separate platform, tenant, device, support and privileged responsibilities.
SECURITY & PLATFORM ASSURANCE
Understand what DC Core protects, where managed tenancy data resides, how the platform recovers, and which controls remain with your application team. This public summary is based on our Supplier and Platform Assurance Pack v1.2, dated .
SECURITY PRINCIPLES
The platform combines technical and operational controls across identity, connectivity, infrastructure and monitoring. The exact assurance boundary depends on which systems DC Core directly operates.
Administrative and service access is limited to defined operational purposes. Role-based controls separate platform, tenant, device, support and privileged responsibilities.
WebAuthn/passkeys support high-trust access flows. Multi-factor authentication is used where applicable to protect administrative and sensitive functions.
Customer-side agents normally connect outwards through encrypted paths, avoiding inbound management ports and direct publication of private systems.
External access uses TLS, with TLS 1.3 where supported. AES-256-GCM protects applicable platform-managed data and protected services.
Operational and security-relevant events are logged where appropriate. Hash-chain and immutable storage controls protect audit-log integrity.
Network restrictions, segmentation, encrypted communication, monitoring, service isolation and operational review reduce reliance on any single safeguard.
Critical security updates with active known-exploited-vulnerability risk are prioritised. Routine operating-system, dependency and platform updates use planned maintenance or controlled deployment windows.
Infrastructure and network providers vary by deployment. Applicable locations are confirmed during onboarding, and material providers or processing changes are assessed before use and communicated where required.
DATA PROCESSING
Customers determine the purpose and lawful basis for personal data in their applications. DC Core acts as a processor for agreed platform or infrastructure services, or as a sub-processor where the customer serves its own client.
Organisation details, names, email addresses, roles and permissions support customer administration, authentication and authorised platform use.
Hostnames, IP addresses, operating-system information, service state and performance telemetry support monitoring and management of in-scope systems.
Access, audit, security and operational logs—and information supplied in support requests—support troubleshooting, incident response and service assurance.
Workload data is processed where it is hosted, transmitted, backed up or otherwise managed through DC Core. Customers remain responsible for content, classification and lawful use.
DATA PROTECTION & RESIDENCY
DC Core distinguishes primary tenancy storage from the global relay and edge services used to improve secure connectivity, performance and availability.
ENCRYPTION & KEYS
DC Core protects platform-managed communication, infrastructure and key access. Encryption inside customer-developed applications remains a workload-level responsibility unless separately managed.
| Layer | DC Core control | Boundary |
|---|---|---|
| Transport | TLS protects external access and applicable internal communication; TLS 1.3 is used where supported. | Customer integrations outside DC Core control must also use appropriate secure transport. |
| Platform data | AES-256-GCM is used where applicable for sensitive platform-managed and protected service data. | The implementation depends on the service and data layer being operated. |
| Owner keys | A customer-owned key and virtual keychain model protects device and workload access, with WebAuthn-backed unlocking. | Key-controlled operations do not rely on ordinary account passwords alone. |
| Customer workload | DC Core provides managed transport, infrastructure and platform protections within scope. | Application databases, files, scripts and custom data handling remain with the customer or application owner unless agreed otherwise. |
AVAILABILITY & RECOVERY
Controls for high availability, backup and disaster recovery apply to services directly operated by DC Core. Customer-hosted and transitional environments can have different arrangements.
Core application, relay and supporting services are separated to reduce single-instance dependency. Relay pools provide alternative capacity where the deployment supports it.
Monitoring, process supervision, restart policies and traffic routing support automatic recovery where technically appropriate, with operator intervention for complex incidents.
Platform-managed systems are backed up daily. Backups are encrypted in transit and at rest, with retention defined by service and customer agreement.
Backup and restore processes are tested periodically, including availability verification and operational review after significant platform changes.
Telemetry covers service health, relay availability, agent connectivity and infrastructure indicators. Anomaly detection compares workload behaviour with prior operational baselines.
Recovery objectives depend on the service, incident and contracted recovery design. Specific commitments or dedicated standby arrangements must be agreed contractually.
COMPLIANCE ROADMAP
These frameworks are a work programme, not completed certifications. Certificates, attestations and third-party reports will be shared when available, subject to confidentiality and commercial terms.
| Framework | Current status | Programme focus |
|---|---|---|
| ISO 27001 | In progress | Information security governance, risk management, supplier management, incident response, access control and operational security. |
| SOC 2 | In progress | Readiness activity focused on security, availability, confidentiality and operational control evidence. |
| Cyber Essentials | Planned | Baseline assurance around endpoint security, access control, patching, malware protection and secure configuration. |
SHARED RESPONSIBILITY
DC Core secures the platform and managed infrastructure. Customers retain responsibility for their users, applications, business data and systems outside the agreed operational scope.
| Area | DC Core | Customer |
|---|---|---|
| Infrastructure | Hardening, network controls, monitoring and patching for infrastructure managed by DC Core. | Servers, services and networks not hosted or managed by DC Core. |
| Identity | Platform authentication, role-based access and privileged administrative controls. | Customer user lifecycle, appropriate permissions, MFA adoption and removal of leavers. |
| Applications | Secure configuration of DC Core platform services and supporting components. | Application code, databases, roles, business logic, integrations and workload-level encryption. |
| Backup & recovery | Processes for DC Core-managed platform services and infrastructure. | Requirements and recovery validation for customer-managed application data or out-of-scope workloads. |
| Data | Secure processing of data handled to deliver the agreed managed service. | Ownership, accuracy, classification, lawful basis and lifecycle of customer data. |
SUPPORT & DISCLOSURE
Standard support is Monday–Friday, 08:00–17:00 UK time, excluding UK public holidays. Critical incident handling outside these hours is available where covered by a managed support arrangement.
[email protected] →Report suspected vulnerabilities with the affected component, a clear description, reproduction steps and relevant evidence. Reports are reviewed and prioritised by potential impact.
[email protected] →| Severity | Example | Target initial response |
|---|---|---|
| Critical | Platform outage or customer production unavailable | Immediate emergency handling |
| High | Major degradation or security concern | Same business day |
| Medium | Non-urgent fault or configuration issue | 1–2 business days |
| Low | General query or request | Best effort / planned queue |
CUSTOMER DUE DILIGENCE
Tell us which service or deployment you are assessing. We can provide the appropriate assurance material and clarify the controls that apply to your environment, subject to confidentiality requirements.