Trust and due diligence.
We ask compliance leads and operations directors to let us near regulated data, so the least we can do is publish what we hold, what we don't, and who else touches it. Everything below is either verifiable from a public register or a commitment we will put in a contract. Where something is not yet true, it says so.
Where we are, stated plainly.
We would rather tell you this here than have you find it out three weeks into a procurement process.
We hold no formal security certification today. Not Cyber Essentials, not ISO 27001. If a certification is a hard requirement for your procurement process, tell us at the first conversation rather than the last, because that is a scheduling question and we would rather answer it early.
What we can point at is how the work is actually done. Client builds run inside your tenant, under your access controls and your logging, so our security posture is not the thing standing between a regulator and your data. On this site specifically, the technical controls are verifiable from any browser: HTTPS enforced with HSTS, a strict referrer policy, framing denied, MIME sniffing disabled, and camera, microphone and geolocation switched off at the header.
Where your data sits, and who else can see it.
Client work happens inside your environment. This site collects only what you type into a form.
Residency
Client data stays in your tenant. We build in your environment, on the systems you already run, so your data does not have to move to us for the work to happen. Nothing about an engagement requires you to export a dataset to a third party.
Sub-processors
Third parties that process data on our behalf for this website. Engagement sub-processors are named in the data processing agreement for that engagement, because the list depends on which of your systems the build touches.
| Processor | Purpose | Region |
|---|---|---|
| Cloudflare | Hosting, edge delivery and bot protection (Turnstile) | Global edge network, UK/EU points of presence |
| Three Impact | Processes contact and enquiry form submissions | On request |
We keep enquiries for 24 months from our last contact with you, then delete them. What this site collects, and how long for, is set out in our privacy notice.
A person signs off. Every time.
Governance before automation, every time. These controls are in the build from the first sprint, not added once something goes wrong.
Human-in-the-loop controls
- A person signs off every disclosure before it leaves the system.
- Field-level confidence scores, so a reviewer sees which values to check.
- Role-based access, so people see only what their role permits.
- A complete exportable audit trail, from source record to final statement.
- Your data stays in your tenant. We build inside your environment, not ours.
Permanent red lines
- No automated payments, and no automated changes to bank details. Ever.
- A hard human gate before any submission to a regulator. No exceptions.
These are not configurable. They stay in place whatever the workflow is worth.
Who you would be contracting with.
- Registered name
- North Stack Limited
- Company number
- 16928771
- Registered office
- Suite Ra01, 195-197 Wood Street, London, England, E17 3NU
- ICO data-protection register
- ZC186532
- Professional indemnity insurance
- In place. Certificate available on request.
We are a UK studio, remote-first across the UK and Europe, and engagements are delivered remotely.
Ask us for the paperwork.
Send one email and you will get a named person, not a ticket. We would rather answer a hundred questions before a contract than one after an incident.
We hold a data processing agreement ready to sign, and we will complete your security questionnaire in your own format rather than sending ours back.
Anything on this page you want evidence for, ask and we will send it. If we cannot evidence it, we will say so.
