Trust
The security questionnaire, answered in advance
Everything a buyer normally has to ask for, in one place — with what is in place, what is partial, and what is not yet, said plainly.
Every claim here is either evidenced or marked outstanding. Nothing on its way is written as though it had arrived. Once a bid is submitted these become contractual representations, so a page that says “partial, and here is what is missing” is worth more than one that claims a clean sweep — an unqualified conformance claim from a practice this size mostly signals that nobody tested it.
Where the authority is external, it is named: a standard with its version, a circular with its section, or a tool whose rules were not written here. Those can be checked without taking anyone’s word for it.
Security
Where is data stored?
In placeAmazon Web Services, EU (Ireland) region — eu-west-1. The database is not publicly accessible and sits in a private subnet; it cannot be reached from the internet. CloudFront serves the front end from edge locations worldwide.
Verified against the live AWS account, 16 August 2026.
Is data encrypted at rest?
In placeYes. The database is encrypted at rest with a KMS-managed key. Object storage is encrypted by default and blocked from public access at the bucket level.
RDS StorageEncrypted; S3 default encryption and public-access block.
Is data encrypted in transit?
In placeYes. TLS is terminated at CloudFront; HSTS is set. Database connections verify the server certificate — there is deliberately no unverified-TLS option in the code, because a connection string that encrypts without verifying looks identical to a secure one while stopping only a passive attacker.
How is access controlled?
In placeAccounts are invite-only; there is no self-registration path. Sessions use httpOnly, Secure, SameSite cookies with refresh-token rotation, and TOTP two-factor authentication is available. Authorisation is checked twice — once at the route by role, and again in the handler against the specific record.
Regression-tested; see the security page for the model.
How are backups handled, and has a restore been tested?
PartialAutomated daily backups with a seven-day retention window and point-in-time recovery, plus deletion protection on the database instance. A restore drill runs monthly in CI against a fresh database built from the real migrations, so a schema change that broke the restore path would fail the build rather than surface during an incident.
Backups, PITR and the monthly CI drill are all in place. What is outstanding is the drill against the PRODUCTION instance — restoring a real snapshot to a scratch instance and comparing row counts. That is the half CI cannot reach, because the database is private by design. It was first booked for 31 August 2026 and has been rescheduled to 1 November 2026; the runbook is written and the date is recorded rather than quietly dropped. A date rather than "scheduled": an undated commitment is the same as none, and a date that has passed without comment is worse.
Is the application penetration tested?
Not yetNot yet by an independent third party. Security is enforced in the build instead: every deploy is gated on a dependency audit at high severity and on an automated accessibility and security test suite, and past findings are tracked by identifier with their remediation status.
An annual independent test is on the roadmap. Until it exists, this page will not imply one.
What monitoring and alerting is in place?
In placeApplication logs stream to CloudWatch. Alarms cover unhandled server errors and environment health, publishing to a monitored address, and an external uptime check runs on a five-minute interval. A documented incident procedure covers the GDPR Article 33 seventy-two-hour notification window.
How are secrets managed?
In placeNo long-lived cloud credentials exist in the repository or in CI. Deployment authenticates to AWS by assuming a role over OIDC, so there is no stored key to leak or rotate. A secret scanner runs on every commit before it can be pushed.
gitleaks pre-commit hook; GitHub OIDC role assumption in the deploy workflow.
Data protection
Controller or processor?
In placeBoth, in different roles. For this practice’s own site and enquiries, Verity Digital is the controller. For work delivered on a client’s systems and data, Verity Digital acts as a processor on the client’s documented instructions.
Are Article 28 processor terms available?
PartialYes — a data-processing agreement covering documented instructions, confidentiality, security measures, sub-processor authorisation, assistance with data-subject rights, breach notification and deletion or return on termination is available for review on request.
Drafted and in legal review. Provided on request rather than published, because contract terms should be settled before they are offered.
Is there a record of processing activities?
In placeYes. A record under Article 30 is maintained, along with a data-protection impact assessment and a documented retention position. The Data Protection Commission’s guidance is that the under-250-employee derogation does not extend to processing that is not occasional, which routine client work is not.
Who are the sub-processors?
In placeAmazon Web Services (hosting, EU-Ireland), Stripe (payments), Resend (transactional email) and Anthropic (AI-assisted drafting, where enabled). The current list, with data categories and safeguards, is in the processing record and is provided with the data-processing agreement.
Is there a breach procedure?
In placeYes. A written incident-response procedure covers containment, assessment, the Article 33 notification to the Data Protection Commission within seventy-two hours of awareness, and Article 34 communication to data subjects where the risk threshold is met.
Accessibility
Accessibility is a procurement specification a public-sector buyer has to satisfy under the Web Accessibility Directive — which makes conformant delivery a capability they are buying, not a courtesy.
What standard is the work built to?
In placeEN 301 549, the European standard referenced by the Web Accessibility Directive. Its current version maps to WCAG 2.1 AA; work here is tested against WCAG 2.2 AA, ahead of the revision expected to raise the standard.
Is that tested, or asserted?
In placeTested, automatically, on every change. The build runs axe-core across the public pages, the client portal and the admin area, and fails on any serious or critical violation. Automated testing cannot catch everything — it is a floor, not a certificate.
axe-core via Playwright, blocking in CI on serious/critical.
Does the European Accessibility Act apply to this practice?
In placeNo. The Competition and Consumer Protection Commission’s guidance is that the Act’s obligations do not apply to microenterprises providing services. It is named here because the honest answer is more useful than a claim of compliance with something that does not apply.
CCPC guidance for microenterprises.
Certifications
Listed with their real status. Where a certificate is held, the number is published rather than a badge — a number can be checked against the registrar, an image cannot.
Tax clearance
HeldRequired for public contracts over €10,000 including VAT in any twelve-month period. Verifiable by the contracting authority through Revenue’s online system.
Cyber Essentials
PlannedSelf-assessed certification against the five technical controls. The certificate number will be published here once held — not a badge.
Cyber Fundamentals (CyFun)
Self-assessingIreland’s emerging national cyber baseline, adopted by the NCSC. Self-assessment is free and open now; a national certification scheme is expected to follow.
ISO/IEC 27001
Not heldNot currently proportionate for a practice this size. If pursued, it would be through an INAB or UKAS-accredited body — an unaccredited certificate is routinely rejected in procurement.
Buying from a practice this size
Four points from the national procurement guidance that are easy to miss and frequently over-applied. Cited so they can be checked rather than taken on trust.
Below €50,000, there is no tender
Circular 05/2023 provides that contracts between €5,000 and €50,000 (ex VAT) may be awarded on written specifications issued to at least three suppliers. Most engagements of this size are decided by who a buyer chooses to email — not by a scored competition.
DPER Circular 05/2023
Personnel experience counts where a company track record does not
Circular 05/2023 §3.5 directs contracting authorities to consider the previous experience of a supplier’s personnel where the business has yet to establish a corporate track record. That is the basis on which this practice asks to be assessed, and why the principal’s background is documented in detail rather than summarised.
DPER Circular 05/2023 §3.5
Insurance is required on award, not at tender
Circular 05/2023 §3.11 provides that tenderers should be asked to declare they can obtain cover, and should not be required to hold it at the time of tendering — evidence is required once identified as successful. Employer’s Liability is expressly noted as unnecessary for a self-employed supplier.
DPER Circular 05/2023 §3.11, Appendix 1
Turnover requirements are capped
Minimum yearly turnover required of a supplier shall not exceed twice the estimated contract value, except in duly justified cases. Worth knowing when a request for proposals asks for more.
DPER Circular 05/2023 §3.6
Anything not answered here
The governance pack — information security policy, data protection policy, secure development policy, business continuity and disaster recovery — is published in full on the procurement page. The engineering detail behind the security answers is on the security page, and how this platform is built and deployed is on how it’s built.
If a questionnaire asks something this page does not cover, send it over — an answer that is “not in place” will be given as one.