Why this page exists
Procurement and compliance functions at banks, insurers, and health platforms verify vendor claims as routine process, not as an exception. Most supplier websites make that work harder than it needs to be: certifications and regulatory frameworks are presented in the same format, experience claims are stated without a basis, and outcome figures appear with no explanation of where they came from.
This page is our attempt to do the opposite. Where we hold something, we say so and will produce the evidence. Where we do not, we say that too. If anything here does not hold up under your own checks, we would rather hear it on the first call than lose the work quietly on the third.
Company details
BritonOne Technology Ltd is a private limited company incorporated in England and Wales. Our registration can be checked on the public register at find-and-update.company-information.service.gov.uk.
- Registered name: BritonOne Technology Ltd.
- Jurisdiction of incorporation: England and Wales.
- Registered office: 134 Westbourne Terrace, London W2 6QB, United Kingdom.
- Registered with the Information Commissioner's Office as a data controller, and as a data processor when operating inside client cloud accounts. Registration reference available on request.
Regulatory frameworks we deliver within
The following are regulatory regimes our clients operate under, and which our delivery practices, evidence trails, and handover packs are built to satisfy. They are not certifications, we are not accredited in them, and we do not present them as such. What we offer is delivery experience building systems that clear scrutiny under each.
- FCA: UK financial conduct regime.
- PRA: UK prudential regulation, including SS1/23 model risk and SS2/21 outsourcing and third-party risk.
- DORA: EU digital operational resilience, including testing and third-party registers.
- HIPAA: US healthcare data protection.
- GxP and 21 CFR Part 11: life-sciences quality practice and electronic records.
- UK GDPR and EU GDPR: data protection, in both controller and processor roles.
- NHS DSPT: Data Security and Protection Toolkit.
- WCAG 2.2 AA: accessibility, independently audited on public-sector engagements.
Certifications we formally hold
We do not currently hold ISO 27001, ISO 9001, SOC 2 Type II, or Cyber Essentials Plus certification, and we do not claim to. Any page on this site that appears to suggest otherwise is an error, and we would be grateful if you reported it to us.
Certification is a defined thing: an accredited body audits you and issues a certificate with a number and an expiry date. When we hold one, this section will carry the certificate number and expiry, not just a logo. Until then, what we can evidence is the following.
- ISO 27001-aligned internal controls: our information-security controls are mapped to Annex A. The mapping and our current gap position are shareable under NDA.
- SOC 2 evidence practice: we build and operate the control narratives, evidence pipelines, and sampling that clients rely on for their own Trust Services Criteria audits.
- Client-estate-first working: on most engagements we work inside your tenancy, under your controls and within your certification scope, rather than moving your data into ours.
- Cloud platform delivery: we architect and run regulated workloads on AWS, Azure, and Google Cloud. We do not currently claim a partner tier with any of them.
Where the numbers on this site come from
Case-study metrics are the easiest part of a vendor website to invent and the hardest for a buyer to check. Rather than ask you to assume ours are sound, here is the process behind them, so you can decide how much weight they deserve.
- Defined against a baseline agreed at scoping, recorded before work begins. A figure without a baseline is an opinion, so we do not publish one.
- Confirmed in writing by the client at engagement close. Where a client will not confirm a figure, it does not appear on this site in any form.
- Anonymised under mutual NDA to sector, region, and scale only. We do not sharpen a description to the point where a client becomes identifiable.
- Available for reference: for a live opportunity we will arrange a call with a client who has agreed to speak, subject to their consent and their own compliance sign-off.
Contractual commitments
The following are standing terms in our engagement contracts rather than marketing positions. You can hold us to each of them in writing.
- Code and IP transfer to you from day one. All source, infrastructure-as-code, runbooks, and documentation are handed over as we ship, not withheld until final payment.
- 48-hour replacement window. If a specialist is not the right fit on engineering style, communication, or skills, we replace them within 48 hours, with no transition invoicing and no contract addendum.
- Change orders are documents. Any change to agreed scope is a one-page document you approve before work proceeds, never an invoice you discover afterwards.
- Named team, no substitution. The engineers named at scoping are the engineers who deliver. Substitutions require your agreement in advance.
- Senior-only delivery. We do not staff engagements with juniors shadowing a senior name on the contract.
Published policies
The governance documents behind these commitments are published in full, with no gate and no form. Each is linked from the footer of every page on this site.
- Privacy policy: what we collect, why, and your rights under UK GDPR.
- GDPR policy: controller and processor duties, international transfers, and breach handling.
- Security: our technical and organisational controls, and incident response.
- Vulnerability disclosure: how to report a security issue to us, and what happens next.
- Terms of service: the standing commercial terms behind every engagement.
- Modern slavery statement: our position and supply-chain due diligence.
- Tax strategy: our UK tax position and approach to compliance.
- Accessibility statement: the standard we hold this site and our deliverables to.
Diligence and questionnaires
Procurement, compliance, and security questionnaires all come to the same address, and a senior person answers rather than a sales desk. We aim to return completed questionnaires within three working days.
If you want something on this site evidenced, ask. That includes the control mapping, our anonymisation process, insurance certificates, and reference introductions.
Email: hello@britonone.co.uk
BritonOne Technology Ltd134 Westbourne TerraceLondon W2 6QBUnited Kingdom