Trust Center

Everything a procurement team, security reviewer or insurer normally has to ask for, published in one place with a way to verify each claim independently.

Solusec Ltd · Company No. 13352754 · ICO Ref ZC103067 · Last reviewed: 26 September 2026

If you are filling in a supplier questionnaire about us: the company details are in section 1, accreditations with public verification links in section 2, insurance in section 3, our own security controls in section 4, data handling and UK GDPR in sections 5 and 6, and our policies in section 10. If your form asks something not covered here, email info@solusec.co.uk and you will get an answer the same working day rather than a brochure.

1  Company details

Registered details, as they should be entered on a supplier form
Registered nameSolusec Ltd
Company number13352754 (England and Wales)
VAT number457904462
Registered officeThe Red House, Albrighton, Wolverhampton, WV7 3LU
ICO registrationZC103067
Data controllerSolusec Ltd
General contactinfo@solusec.co.uk
Security contactsecurity@solusec.co.uk
Business typeCyber security consultancy, and an appointed Certification Body

2  Accreditations and certifications

These are held by Solusec Ltd as a business and independently audited. Every one is on a public register, so you do not have to take our word for any of it. If a claim on this page cannot be verified against a register, treat that as a problem with the claim.

Company accreditations, with public verification
AccreditationAwarded byVerify
CREST Accredited Penetration Testing ProviderCRESTCREST marketplace
CREST AI-Enabled Penetration TestingCRESTCREST marketplace
Cyber Essentials Certification BodyIASME, the NCSC’s sole delivery partnerIASME register
Cyber Essentials Plus Certification BodyIASMEIASME register
IASME Cyber Assurance Certification Body, Levels 1 and 2IASMEIASME register
Defence Cyber Certification Body, Level 0IASME, for the Ministry of DefenceWhat DCC covers

We are also among the first ten organisations worldwide to hold CREST accreditation for AI-Enabled Penetration Testing, recognised on 2 September 2026. That accreditation covers the responsible use of AI within a testing service. It is not the same thing as accreditation to test AI systems, which is a separate scheme CREST has yet to launch, and we would rather explain the distinction than trade on the confusion.

Separately, and more usefully for a supplier review, Solusec is itself certified to the standards it assesses others against: Cyber Essentials Plus, IASME Cyber Assurance and IASME Quality Principles, all verifiable on the IASME register. A certification body that has not been through the assessment itself is worth asking questions about.

Company accreditation over an unqualified team means very little, so the certifications held by the people who carry out the work are published too. This is the list procurement questionnaires usually ask about by name.

OSCP: OffSec Certified Professional OSWE: OffSec Web Expert CREST Registered Penetration Tester CRTO: Certified Red Team Operator CISSP: Certified Information Systems Security Professional PraCSP: Practitioner, UK Cyber Security Council BTL2: Certified Blue Team Level 2 CSOM: Certified Security Operations Manager CompTIA SecurityX
Individual certifications held across the people who do the work
CertificationWhat it isAwarded byVerify
OSCPOffSec Certified Professional. A 24-hour practical examination in compromising live systems, not a multiple-choice paper.OffSec–
OSWEOffSec Web Expert. Advanced web application exploitation, including source code review and bypassing authentication logic.OffSec–
CRTCREST Registered Penetration Tester. An individual CREST examination, and a contractual requirement for many UK government engagements.CRESTCREST marketplace
CRTOCertified Red Team Operator. Adversary simulation, command and control tradecraft and operating against endpoint detection.Zero-Point Security–
CISSPCertified Information Systems Security Professional. Security architecture, risk management, governance and compliance at senior level.ISC2–
PraCSPPractitioner in Security Testing, on the national professional register for the cyber security sector.UK Cyber Security CouncilPublic register
BTL2Blue Team Level 2. Advanced defensive certification assessed through hands-on threat hunting and incident response.Security Blue Team–
CSOMCertified Security Operations Manager. Planning and leading detection, incident response and SOC functions.Centri–
CompTIA SecurityXAdvanced practitioner certification covering security architecture, engineering and risk.CompTIA–
IASME AssessorCertified to assess Cyber Essentials and IASME Cyber Assurance submissions.IASME–
DCC Level 0 AssessorCertified to assess Defence Cyber Certification at Level 0.IASME, for the MOD–

Daly Whyte is CREST registered as an individual, which is separate from and additional to Solusec’s company-level CREST accreditation. For any engagement we tell you who is doing the testing and what they hold before you commit, so if your contract requires a named certification on the person rather than on the company, ask at scoping and you will get a straight answer. The same detail, with the individual awarding bodies, is on our credentials page.

3  Insurance

Cover held. Certificates are issued on request.
Professional indemnity£1,000,000
Public liability£6,000,000
Employers liability£10,000,000

If your contract requires a higher limit of indemnity for a specific engagement, raise it at scoping. It is usually arrangeable, and it is much easier to deal with before a contract is drafted than after.

4  Our own security controls

A firm that tests other people’s security should be able to answer for its own. Ours are independently assessed rather than self-declared: Cyber Essentials Plus involves an assessor verifying the five technical controls on live systems, IASME Cyber Assurance is an audited information security standard aligned to the Government’s Ten Steps, and the CREST accreditation audit covers our methodology, reporting, data handling and staff competence.

The controls we apply to your data are encryption at rest and in transit, access control on a least-privilege basis, audit logging, and regular vulnerability assessment of our own systems. Our productivity and storage platform is Microsoft 365, in a tenant provisioned in the UK and EU region.

We are a small consultancy and our environment is correspondingly small, which is a genuine advantage in this one respect: there is very little of it, all of it is known, and nothing is inherited from a previous IT regime that nobody understands any more.

5  How we handle your data

For a penetration test or an assessment, the sensitive material is not usually personal data. It is the findings: a current, specific description of how to get into your systems. We treat that as the most dangerous document we hold about you, and handle it accordingly.

  • Reports are delivered to named recipients you nominate, not to a shared inbox or a generic address, unless you ask us to.
  • Findings are not reused. We do not publish client names, we do not write up your environment as a case study, and we do not quote your findings in marketing. If you want to be named as a reference, that is your decision to offer.
  • Critical findings are reported as soon as they are confirmed, by phone or email, rather than held back for the report.
  • Testing artefacts, meaning scan output, screenshots, captured credentials and proof of concept material, are held only as long as they are needed to support the report and the retest, then securely deleted.
  • Engagement records are retained for six years from the end of the engagement, in line with statutory limitation periods. If your contract requires a shorter retention period for report material, say so at scoping and we will agree it in writing.
  • We will sign your NDA. We do not require you to sign ours first.

6  Data protection and UK GDPR

Solusec Ltd is the data controller for the personal data we hold about enquirers and clients, registered with the ICO under ZC103067. Where we process personal data on your behalf during an engagement, we do so as a processor under your instructions and under a written agreement. Our full privacy policy sets out lawful bases, your rights and how to exercise them. In summary:

The answers most commonly needed on a data protection questionnaire
SubprocessorsMicrosoft, for email and document storage, under the Microsoft Online Services DPA. Senior consultants engaged on specific engagements, under contractual confidentiality and data processing obligations. Nobody else without a clear lawful basis and your knowledge.
Data locationMicrosoft 365 tenant provisioned in the UK and EU region, so data at rest is held within the EEA.
International transfersWhere any Microsoft processing occurs outside the EEA it is governed by their DPA, incorporating Standard Contractual Clauses and the UK Addendum. No other transfer route is used without an appropriate safeguard.
RetentionEnquiries that do not proceed: up to 12 months. Client engagement data: 6 years. Financial and contractual records: 6 years. Email correspondence: up to 3 years unless part of an engagement record.
Breach notificationWhere a personal data breach meets the reporting threshold, the ICO within 72 hours and affected individuals without undue delay. Where a breach affects data we hold for you, we tell you first and immediately.
DPAWe will sign yours, or provide ours. Either way, before any data changes hands.

7  How an engagement is controlled

Testing somebody’s systems without proper authority is a criminal offence under the Computer Misuse Act 1990, and the paperwork that prevents that is not a formality. Before any testing starts:

  1. Written authorisation from someone with the authority to grant it, confirming the targets in scope and that you own them or are permitted to have them tested.
  2. An agreed scope naming the systems, addresses and applications in scope, and anything explicitly out of scope.
  3. Rules of engagement covering testing windows, techniques excluded, escalation contacts and what happens if something breaks or if we find evidence of a live compromise.
  4. Third party notification where a hosting provider or SaaS platform requires it. We will tell you which of your suppliers need to be told, and what they usually want to see.

After testing, the report arrives within five working days of testing completing, and a retest is included once the issues are fixed. Standard lead time from agreed scope to testing is two to three weeks, often within a week at short notice, and occasionally two to three days for a contained scope. There is no rush premium.

8  The people who do the work

Work is carried out by the founder, Daly Whyte, or by one of a small number of senior consultants engaged directly, and you are told which before you commit. Daly oversees every engagement personally whoever carries it out. There is no sales layer taking the brief and no junior analyst delivering it.

Consultants are engaged directly on written terms that include confidentiality and data protection obligations. We do not use labour agencies or offshore delivery centres, and we do not subcontract delivery to organisations whose own practices we cannot see. Staff competence is one of the things the CREST accreditation audit examines.

If your engagement carries a specific vetting or security clearance requirement, raise it at scoping. We will tell you plainly whether we meet it rather than discovering the problem halfway through a procurement.

9  Reporting a vulnerability in our systems

If you have found a security issue in anything we run, we want to hear about it. Email security@solusec.co.uk. Our machine readable policy is at /.well-known/security.txt, published to RFC 9116.

We operate a coordinated disclosure process, we acknowledge reports within one business day, and we do not pursue legal action against researchers acting in good faith under that policy. Given that we have contributed over 500 findings to other organisations’ disclosure programmes, it would be poor form to treat somebody badly for doing the same to us.

10  Policies and statements

Published policies, most often requested in tenders
Privacy policyWhat personal data we collect, why, on what lawful basis, and how long we keep it.
Modern slavery statementVoluntary, as we are below the section 54 threshold. Our structure, our supply chain, and where the risk actually sits.
Equality, diversity and inclusionWhat a consultancy of our size can honestly commit to, and what we do not yet report.
Vulnerability disclosureHow to report a security issue in our systems, to RFC 9116.

Signed copies on letterhead, and any of these in a format your procurement portal insists on, are available the same working day on request.

11  What we do not hold

Trust pages are more useful when they are candid about the gaps, because the gaps are what a good evaluator is looking for anyway.

  • We do not hold CHECK status. That is the NCSC scheme required for some central government work. If your contract specifies CHECK, we will tell you so and point you elsewhere rather than argue the equivalence.
  • We do not hold ISO 27001. We hold IASME Cyber Assurance, which is aligned to ISO 27001 and independently audited, and we consider it the proportionate standard for a specialist practice of our size. If your contract requires ISO 27001 specifically, that is a real gap and we will say so.
  • We do not implement security controls for clients. That is deliberate, because it means we are never assessing our own work. It also means we are not the supplier to ask to fix what we find.
  • We do not publish a gender pay gap or workforce demographics. The pay gap reporting duty applies from 250 employees and does not apply to a business of our size, and at our scale a demographic breakdown would identify individuals rather than inform anybody. The EDI statement sets out what we commit to instead.

12  Asking us something else

Supplier questionnaires ask things no generic page anticipates. Email info@solusec.co.uk with the form attached, or the questions in the body, and you will get answers the same working day. Where the honest answer is that we do not do something, that is the answer you will get, because a supplier who never says no is a supplier whose yes means nothing.

This page is reviewed at least every six months, and next by 31 March 2027.