Governance & policy centre
Data & security

Public Information Security Policy

A public summary of Intelex Systems' information-security governance, secure engineering and incident-management commitments.

Intelex Systems protects the confidentiality, integrity and availability of information entrusted to us. Our information-security management approach is aligned with ISO/IEC 27001 and supported by organisation-wide Cyber Essentials Plus certification. This page intentionally summarises our commitments without disclosing sensitive control configuration.

Security is designed into our people, processes, products and supplier relationships—not added only before release.

Governance and risk

  • Defined security roles, policies and management review
  • Risk assessment and treatment proportionate to business and customer impact
  • Asset, information and supplier ownership
  • Internal assurance, corrective action and continual improvement

People and access

  • Pre-employment checks where lawful and proportionate
  • Confidentiality obligations and security awareness
  • Least-privilege access and role-based authorisation
  • Multi-factor authentication for supported critical services
  • Prompt joiner, mover and leaver access control

Secure engineering

  • Security requirements and threat-aware design
  • Peer review and controlled source management
  • Dependency and vulnerability management
  • Environment separation and change approval
  • Security testing proportionate to risk
  • Logging, monitoring and protected secrets

Operations and resilience

  • Secure configuration and security update management
  • Endpoint, malware and network protection
  • Backup, recovery and continuity arrangements
  • Monitoring, incident triage and escalation
  • Supplier due diligence and contractual security requirements

Incident management

Suspected security events are recorded, assessed, contained and investigated through defined response arrangements. Customers and regulators are notified in accordance with contractual and legal duties. Lessons and corrective actions are tracked after material incidents.

Report a vulnerability

Send a clear, confidential description to uk@intelexsystems.com with the subject ‘Security Vulnerability’. Do not access data that is not yours, disrupt services, use destructive testing or publicly disclose an issue before we have had a reasonable opportunity to investigate.

Official references