Trust

What a security, privacy or procurement team needs to assess VCode, including what is not published and why.

This page exists so that a security, privacy or procurement team can assess VCode without a call. It states what is confirmed and says plainly where something is not published, rather than filling the gaps with reassurance.

Scope. This page covers two separate things and keeps them apart. Most of it describes this website, vcode.co.uk, which is a content site holding no customer data. The section on VPlatform service architecture describes the identification service itself, at the level a security review needs. Full architecture, hosting and processing documentation is provided to prospective customers and partners under NDA. Where something is not published, this page says so instead of guessing.

Certifications

No certifications are currently published. We do not display ISO, SOC, regulatory or security badges that are not held and current, and we would rather tell you that here than have you discover it during due diligence.

If a certification is achieved it will appear on this page with the certification body, certificate number, scope and expiry, so that you can verify it independently on the issuing body’s register. A badge without those four things is not evidence.

Security architecture of this site

  • The site is served exclusively over HTTPS, with a publicly verifiable certificate.
  • It is a content website. There is no customer account system, no authenticated user area and no customer data store.
  • Nothing is loaded from third-party hosts. Fonts and scripts are served from this domain, so visiting a page does not disclose your IP address to a font service, CDN, tag manager or analytics provider.
  • Administrative access is restricted, and the hosting platform provides security monitoring including failed-login recording.
  • The enquiry form applies a nonce, a honeypot, allow-listed input and a short per-address rate limit.

VPlatform service architecture

The identification service is separate from this website. It is summarised here so that a reviewer can assess it without a call. Detailed network and processing documentation is shared under NDA rather than published, because topology detail assists an attacker and does not assist an assessment.

  • Hosted on Amazon Web Services, in dedicated isolated environments rather than a shared default network. Each deployment carries its own network boundary and its own address range.
  • Three availability zones, all active. The service runs live in three physically separate data centres simultaneously rather than failing over to a standby, so the loss of one does not interrupt it and there is no failover delay to absorb.
  • The application and data tiers are not reachable from the internet. Only the load balancing layer faces the public network. The data tier is isolated further again, and outbound access from the application tier is controlled rather than open.
  • Encrypted in transit and at rest. TLS terminates at the load balancer, and connections onward to the application servers are encrypted too, so traffic is not in clear text inside the network. Stored data and backups are encrypted using AES-256.
  • Automated encrypted backups, with restoration tested rather than assumed.
  • A microservice architecture, so components scale independently and no single component takes the whole service down.
  • Infrastructure defined as code, so environments are reproducible and a recovery environment is rebuilt from the same definitions rather than from memory.

This is an architecture description, not an audited assertion. Nothing above has been certified by a third party, and it should be read that way until a certificate appears in the section above.

Privacy and GDPR

The Privacy Policy describes what this site actually processes, which is deliberately very little: enquiry details sent to us by email and not stored in the site database, ordinary web server logs, and a one-way hash of the requesting address held for forty seconds to stop automated form abuse.

The site is built to the data protection by design principle in Article 25: no advertising or analytics cookies, no tracking, no profiling and no automated decision making. Lawful bases, retention periods and your rights are set out in full in the policy.

Hosting, infrastructure and data residency

This website is hosted on managed infrastructure in the United Kingdom. Enquiries are delivered to a mailbox provided by a third-party email provider. Where a supplier processes personal data outside the UK, the safeguards described in the Privacy Policy apply.

Encryption

Traffic to and from this site is encrypted in transit using TLS. Encryption at rest is provided by the hosting platform. Encryption for the VPlatform service is summarised under VPlatform service architecture above, with full detail provided under NDA.

Data retention

Enquiry correspondence is kept while we are in contact and for up to twenty-four months after the last exchange. Server and security logs are kept for the limited period operated by the host. The form rate-limit hash lasts forty seconds. Full detail is in the Privacy Policy.

Availability and business continuity

This is a marketing website and carries no service level commitment. Backup and restoration are provided at platform level by the host.

The VPlatform service is architected for high availability as described above. That is a design property, not a contractual one: availability commitments are set out in the relevant commercial agreement rather than claimed here.

Incident management and disclosure

If we become aware of a personal data breach affecting this site we will assess it against the UK GDPR reporting thresholds and notify the Information Commissioner’s Office and affected individuals where those thresholds are met.

Security researchers are welcome. The Acceptable Use Policy sets out how to report a vulnerability, what we ask of you, and our undertaking not to pursue action against researchers acting in good faith. There is no paid bug bounty, and we say so rather than implying one.

Sub-processors

Two categories of supplier handle data on our behalf for this website: the hosting provider, which stores the site and generates server logs, and the email provider, which delivers and holds enquiries sent to us. Named sub-processor detail is provided to customers and prospective customers on request.

Accessibility

The site is built to be operable without a mouse, to respect the prefers-reduced-motion setting, and to keep content readable in both light and dark themes. Content is never hidden behind JavaScript without a mechanism to reveal it.

We have not published a formal accessibility conformance report, so we do not claim a WCAG conformance level here. If you hit a barrier, tell us through the contact form and we will fix it.

Platform status

There is no public status page at present. Service incidents affecting integrated customers are communicated through the commercial contact for that engagement.

Need assurance material for procurement?

Tell us what your security team needs to see and who is asking. Platform-level detail is shared directly rather than published.