Placeholder. This article was scaffolded when the Trust Centre launched. The substance below is accurate, but the wording is awaiting final review through the documentation review flow.
Certified information security management
DOS & Co. Ltd operates an information security management system certified to ISO/IEC 27001 (certificate number 00510). Certification means our security controls, risk management and governance are independently assessed against the international standard.
Our security posture
We describe our controls at posture level. We deliberately do not publish implementation detail:
- Access to systems and data follows the principle of least privilege, with role-based access control and audit trails on sensitive activity.
- Data is encrypted in transit and at rest.
- Sensitive account information is stored separately from general records and revealed only under step-up authentication, with every reveal audited.
- Our systems and infrastructure undergo regular penetration testing by independent external security specialists.
- We maintain insurance cover appropriate to the nature and scale of the services we provide.
Reporting a vulnerability
If you believe you have found a security vulnerability in any of our services, please see our responsible disclosure policy.
