Security Commitment
Dealing with confidential information requires strict security practices. We are committed to making sure your data is dealt with appropriately from start to finish.
Dealing with confidential information requires strict security practices. We are committed to making sure your data is dealt with appropriately from start to finish.
Criminal record and pre-employment checks deal with extremely sensitive information, from detailed personal information to Client records and contact details. At DDC, we understand that can be a nervous process and that you might want to be assured that your data is being dealt with in a secure and professional manner and stored on a secure system.
ISO 27001 is one of the most widely recognised information security standards and demonstrates that a certified organisation has an integrated and professional approach to all aspects of information security. DDC has been certified to ISO 27001 since 2012 and for our clients, this means that we are constantly testing and reviewing our security systems. We also ensure that data security is one of the primary considerations in all services provided.
For larger organisations and government bodies, DDC can cooperate and support your existing security practices and you can be sure that information is being transferred and processed in an auditable manner that is aligned with industry best-practice. All of our systems are within our officially stated ISMS scope, which can be verified here Alcumus Group Ltd, by entering our certificate number 10228.
PCI is the credit-card industry’s benchmark security standard. We have undergone rigorous PCI compliance testing, to ensure our systems are secure enough to accept online and telephone card payments. As part of our ongoing compliance testing, our servers are scanned each month by TrustWave, who check our servers against a comprehensive list of known security vulnerabilities. We are required to maintain compliance at all times, and we promptly respond to any newly published security vulnerabilities. You can validate our current PCI compliance status by clicking on the badge below:
We use the latest SHA-256 encryption algorithms to ensure your data cannot be intercepted while in transit. We also use an ‘Enhanced Validation’ SSL certificate, which is the highest level of SSL certificate available. On modern browsers, this means you will see our company name in a green bar next to our website address. Our modern certificates are not compatible with some older, insecure browsers, which means we are less of a target for opportunistic cyber-criminals.
All of our staff have been vetted in accordance with the Cabinet Office Baseline Personnel Security Standard (BPSS). This involves checking staff identity, employment history for a minimum of the past 3 years, Nationality and Immigration Status and Criminal Record for unspent convictions.
In addition to these checks, only staff who are fully authorised ‘Countersignatories’ are permitted to submit applications to the DBS. This position requires extensive in-house training, in addition to an Enhanced-level criminal record check.
The DBS regularly visit our premises and we have passed all assessments and audits. This includes site visits, information security risk assessments and direct connectivity and data delivery testing. We are also fully compliant with the DBS Guidelines and Code of Practice, which have dictated many of our operational processes.
We are subscribed to all relevant DBS mailing lists and legislative lists, to enable us to remain fully informed of upcoming changes at the DBS and any relevant developments in legislation.
We run our own dedicated hardware and software for processing applications. This means that your data is not stored on a shared system, such as the ‘cloud’, yet on secure hardware servers where the data is always under our direct control. We adhere to industry best-practices for secure communications and encryption.
Our in-house IT team are ably assisted by support specialists to ensure business continuity. We regularly penetration-test our own systems and have scheduled system inspections, backup tests and disaster-recovery emulations.
Our Partners: