Protected to the standard the work is held to.
How Innative protects an organisation’s data, controls who and what can reach it, and preserves the boundaries between organisations.
How data is held.
- In transit
- Encrypted end to end. Nothing moves between systems in the clear.
- At rest
- Encrypted with modern ciphers, with keys managed separately from the data they protect.
- Credentials
- Access an organisation grants is encrypted, never rendered into an interface, an export or a log, and revocable by you at any moment.
- Isolation
- Each organisation's data is separated from every other organisation's, enforced below the application rather than by it.
- Least privilege
- Every part of Innative reaches only what its work requires, and no person or process holds standing access to a customer's data.
- Residency
- United Kingdom and European Union. Named in the agreement, not left to default.
- Retention
- Set by you, applied automatically, and evidenced. We do not keep what you have not asked us to keep.
- Return and deletion
- Full export on request at any time, and verified deletion at the end of the engagement.
Policy is written before capability, not after it.
Most of this field builds the capability and then works out what should have constrained it. That order is the reason so little of it can be used where it matters.
The rules come first
What Innative may do, for whom, and under whose authority is agreed and written before anything goes live. Capability is added inside that, never around it.
Your policy, expressed as constraint
Your obligations are not guidance Innative is asked to respect. They are limits it operates inside.
Ethical by construction
A person stays in the decisions that carry consequence, provenance is kept for everything asserted, and the organisation can always show what was done and why. None of that depends on intent.
Answerable to your assessor
Everything here is designed to be handed to whoever assesses you, in the form they read, without translation.

On request
Subprocessor list, data processing agreement, retention schedule, penetration test summary, insurance position and our current certification status are provided in writing at the briefing.
Request an Innative briefing.
A working session on your operation, what Innative would understand and take on inside it, and what an implementation would involve. Held by the people who build it.