Trust
Security, privacy, and responsible AI at EfficientEther.
We run the company to three ISO standards and Cyber Essentials. This page is the public summary for buyers, procurement, and risk reviewers.
Procurement stalls on evidence, not intent. A questionnaire arrives, a risk team asks which standard covers which part of the business, and the answer has to be checkable rather than asserted. This page sets out what EfficientEther is certified to, what each standard governs, and how a reviewer can confirm it.
Certifications and accreditations
- ISO 27001Information Security Management
Our information security management system is certified to ISO/IEC 27001, covering risk management, access controls, vulnerability management, and operational security across product and service delivery.
ISO/IEC 27001 is the international standard for an information security management system. It governs how risk is identified and treated, how access to customer data is controlled, and how those controls are kept working between audits.
Certification was announced in October 2023 and covered independently by UK Tech News. The certificate is issued to EfficientEther Ltd and is shared on request through the security enquiry route below.
Questionnaire answers come from a documented management system rather than from individual recollection. It is also the control framework our data processing agreement and sub-processor oversight are written against.
- ISO 9001Quality Management System
Our quality management practices are certified to ISO 9001, supporting consistent service delivery, customer satisfaction, and continuous improvement across our operations.
ISO 9001 is the international standard for a quality management system. It documents how customer commitments are set and met, how change is managed, and how delivery is measured and improved.
Announced alongside ISO/IEC 27001 in October 2023, with independent coverage by UK Tech News. The practices behind it have been in place since the company was founded in June 2023.
Delivery runs to a defined process rather than to whoever is available. That matters most where the contract covers onboarding, support response, and change control.
- ISO 42001AI Management Systems
We hold ISO 42001 certification for AI management systems, covering responsible AI governance, risk assessment, and transparency in how AI is developed and deployed within our products.
ISO/IEC 42001 is the international standard for an AI management system. It requires defined accountability for AI development and deployment, systematic risk assessment, operational oversight of every AI-enabled capability, and improvement tied to measurable outcomes.
Certification was announced in March 2026 and covered independently by UK Tech News. It applies to the AI capabilities across our products, not to a single feature.
Buyers no longer ask whether AI is used, they ask how it is governed. For a reviewer working under UK GDPR or sector data governance rules, this is the certified answer.
- Cyber EssentialsUK Government Cyber Accreditation
EfficientEther holds Cyber Essentials accreditation, the UK Government-backed scheme that verifies our defences against common cyber threats including malware, phishing, and unauthorised access.
Cyber Essentials is the UK government-backed scheme that benchmarks defences against common cyber threats. It assesses five control areas: boundary firewalls, secure configuration, user access control, malware protection, and patch management.
EfficientEther was certified in April 2024, with independent coverage by UK Tech News. Each control area is independently assessed against the scheme's requirements before certification is granted.
It is a baseline expectation in many UK and public sector procurements. Where ISO/IEC 27001 describes how security is managed as a system, Cyber Essentials confirms the technical controls are in place.
- WCAG 2.2 AAWeb Content Accessibility Guidelines
The EfficientEther public website conforms to the Web Content Accessibility Guidelines (WCAG) 2.2 at Level AA. Every page is tested against the WCAG 2.0, 2.1, and 2.2 Level A and AA success criteria via axe-core before release. Conformance claim reference: https://www.w3.org/WAI/WCAG2AA-Conformance.
WCAG 2.2 Level AA is the accessibility conformance target used in public sector and enterprise web procurement, covering the perceivable, operable, understandable, and robust criteria.
An accessibility question on a tender is answered with a stated conformance level and a repeatable test rather than with an assurance.
How we protect your data
- Least-privilege access
- System and data access are scoped by role and reviewed regularly to support operational accountability and auditability.
- Monitoring and incident response
- Logging and alerting support early detection, structured triage, and documented response handling across our environments.
- Backup and recovery
- Backup coverage and recovery planning are maintained to support service continuity commitments and recovery time objectives.
- Customer trust reviews
- Approved assurance summaries and questionnaire responses are shared with customers during active procurement and security evaluations.
Policies and statements
We limit personal data processing to what is needed for service delivery, apply controlled access and retention boundaries, and manage processor oversight in line with our ISO 27001 controls.
Procurement questions
- Where is our data held?
Hosting region is recorded per sub-processor, alongside the purpose and the data categories each one handles, and the data processing agreement sets the contractual terms. EtherApps Forge is deployed differently: it runs inside the customer's own infrastructure or approved cloud estate, so packaging data stays in your tenant.
- How current are the certifications?
ISO 9001 and ISO/IEC 27001 were announced in October 2023, Cyber Essentials in April 2024, and ISO/IEC 42001 in March 2026, each with independent trade coverage at the time. Certificates and completed questionnaire responses are shared during an active procurement or security evaluation.
- Which sub-processors do you use?
The sub-processors page carries the current list with the purpose, data categories, and hosting region for each entry, and records the date it was last revised. It sits with the data processing agreement and the privacy policy in the list above.
- What happens during a security incident?
Logging and alerting support early detection, structured triage, and documented response handling across our environments, under the ISO/IEC 27001 management system. Incident and privacy questions go to the security enquiry route, with a UK business-day response.
Trust and procurement contact
Security reviews, privacy requests, and procurement questionnaires: open a security enquiry or email privacy@efficientether.co.uk for privacy matters. UK business-day response.
