Trust & policies

Security & Confidentiality

Responsible handling of customer information.

Effective date: 16 September 2026 · Version 1.0
01

Our approach to customer information

PTS treats customer information as an asset that requires appropriate access, use and handling. We discuss confidentiality and security requirements during scoping and agree suitable arrangements before sensitive material is shared.

This statement describes our commitments. Specific controls, evidence and contractual obligations must be confirmed for the proposed engagement.

02

Access and sharing

Access to project information must be limited to authorised people who need it for their responsibilities. Sharing channels and permissions must reflect the sensitivity of the material and customer instructions. Accounts and access must be reviewed when responsibilities change or an engagement ends.

03

Business systems and devices

PTS uses Microsoft 365 for business communication and collaboration. The presence of a service or licence does not establish that every available protection is enabled. Device, authentication and sharing requirements are assessed for the engagement, and claims about implemented controls must be supported by evidence.

04

Confidentiality and permitted use

Customer information must be used for the agreed purpose and handled under the applicable contract or confidentiality agreement. Contractors must receive appropriate obligations before access is granted. Project material must not be placed in unapproved public tools or shared outside the authorised group.

05

Storage retention and return

The project arrangements should define approved storage, retention and return or deletion requirements. We will explain any legal preservation requirements or technical limits that affect deletion. We do not promise a storage country, backup frequency or recovery time unless it has been verified and agreed.

06

Security concerns

Report a suspected security issue to [email protected] with the subject “Security concern”. Provide the affected page or service, the time observed and a concise description. Do not include passwords, unnecessary personal data or confidential files in the initial report.

We will assess the issue, coordinate appropriate containment and remediation, and make notifications required by the applicable circumstances, law or contract. Please avoid accessing other people’s information, disrupting services or conducting intrusive testing without written authorisation.

07

Customer assessments

If your procurement process requires a security questionnaire or specific controls, contact us before sharing sensitive information. We will distinguish implemented measures from proposed improvements and identify requirements that need additional work.

No system can be guaranteed free of risk. This statement does not claim ISO/IEC 27001 certification, independent security testing or a formal vulnerability reward programme.

Questions about this policy?

Contact [email protected].