Governance approach
Our security and privacy approach is risk-based, proportionate and designed around accountable ownership. Practices are informed by UK GDPR and the Data Protection Act 2018, NCSC secure-design guidance, Cyber Essentials controls and ISO/IEC 27001 information-security management principles. References to alignment do not replace the scope stated on any formal certificate or contract.
Core controls
- Data minimisation, purpose limitation, retention and secure disposal.
- Role-based access, least privilege and appropriate authentication.
- Secure configuration, vulnerability management, logging and incident response.
- Encryption and protected transfer where appropriate to risk.
- Supplier assurance, contractual controls and review of material sub-processors.
- Secure development, change control, testing and documented approval.
Quality and continual improvement
Our management approach reflects ISO 9001 quality principles: understanding requirements, assigning responsibility, controlling delivery, maintaining evidence, reviewing performance and acting on lessons learned. Controls and service processes are reviewed as risks, technology and obligations change.
Public-sector delivery
For G-Cloud, Digital Outcomes and other public-sector engagements, security, accessibility, audit evidence, data location, exit planning and service responsibilities are agreed in the applicable service definition, framework and call-off documents. Client-specific requirements take precedence where contractually agreed.
Incidents and enquiries
Suspected security or privacy incidents relating to WR Logic should be reported promptly to contact@wrlogic.com with enough information for triage. Do not include passwords, secret keys or unnecessary sensitive personal data in the first message.
Authoritative guidance
These links provide further context and do not form part of a client contract.