How we protect your data, your people and your project
As an independent consultancy supporting regulated and enterprise-scale organisations, we operate under a transparent security and compliance framework covering personnel vetting, data handling, retention and business continuity.
Last Updated: 03/08/2026
Our Commitment to Security and Compliance
At LicenceSync, data security is the foundation of our forensic assurance process. This page sets out the operational detail behind the commitments made in our Privacy Policy and Terms of Business, and how we protect client intellectual property and sensitive metadata at every stage of an engagement.
1. Personnel Vetting & Standards
-
BPSS Cleared: All consultancy engagements are led by a specialist holding current Baseline Personnel Security Standard (BPSS) clearance. This is the required security vetting for individuals handling sensitive UK government and financial sector data.
-
ICO Registered: LicenceSync is registered with the Information Commissioner’s Office (ZC076819) and operates in strict accordance with the Data Protection Act 2018.
-
NDA-Ready: We operate a confidentiality-first approach. We are accustomed to executing specific Non-Disclosure Agreements (NDAs) to formalise data protection before any technical discovery begins.
2. Data Processing Model
We operate a least-privilege model, keeping access and data handling tightly controlled throughout an engagement.
-
Read-Only Ingestion: Tenant metadata is collected using limited-scope, read-only access (for example Global Reader or a temporary limited account), with no write access to your environment.
-
Bespoke Reconciliation (Local Controls): Where manual reconciliation is required (for example, matching HR leaver lists to active IDs), data is handled by a BPSS-vetted consultant on BitLocker-encrypted hardware.
-
Secure Ingestion: We avoid unsecured email attachments for sensitive datasets, using MFA-protected encrypted transfer portals (for example SharePoint or OneDrive) for all document exchanges.
-
Partner Standards: Where we engage a third-party platform or partner to support delivery, we require ISO 27001 certification as a minimum
3. Data Minimisation & Retention (UK GDPR)
We act as a Data Processor under UK GDPR, focusing on the principle of data minimisation.
-
Forensic Purge Policy: By default, all PII (names, emails, UPNs) and client-sensitive datasets are forensically deleted within 30 days of final report delivery, unless a longer "Aftercare" period is contractually agreed.
-
Zero-Sharing Policy: We never share data with third parties—including Microsoft—without explicit written consent.
-
Proactive Management: We continually review our security posture to stay ahead of evolving threats and ensure alignment with the latest UK data protection regulations.
4. Operational Resilience (Business Continuity)
To mitigate "Key Person Risk," we maintain a robust Business Continuity Plan (BCP) to ensure project delivery is never compromised:
-
Peer Substitution: LicenceSync maintains a network of independent BPSS-vetted partner consultants who can be onboarded as substitutes under our standard Terms of Service. This ensures that in the event of primary consultant unavailability, project momentum is maintained by a specialist of equal vetting and expertise.
-
Daily Handover Logs: We maintain internal "Project Status Checklists" updated at the close of each business day. These logs document current progress, pending data reconciliations, and next steps, allowing for a seamless transition to a partner consultant if required.
-
Hardware Redundancy: We maintain a secondary encrypted device ready for immediate deployment in the event of primary hardware failure.
-
Cloud Persistence: All project work-papers are synced in real-time to an encrypted, MFA-protected cloud repository. This ensures that the "Intellectual Property" of the audit remains accessible to the client even in the event of consultant unavailability.
Compliance FAQs
Do you require Global Admin credentials?
No. To maintain the principle of Least Privilege, we typically use limited-scope, "Global Reader" permissions to ingest metadata, ensuring we have no write-access to your environment.
How do you ensure my data is kept confidential?
All client information is handled strictly on a need-to-know basis. Beyond our BPSS vetting, we enforce Role-Based Access Control (RBAC) and advanced encryption to ensure data remains siloed and protected.
What insurance coverage do you hold?
LicenceSync Consulting Ltd is fully indemnified by Hiscox Insurance Company Limited with the following limits:
-
Professional Indemnity: £2,000,000
-
Public Liability: £2,000,000
-
Employers’ Liability: £5,000,000
-
Cyber and Data Insurance: £500,000
These limits can be increased for specific engagements where a client requires higher cover.
