Trust

    What we do with your data, where it sits, and what we can evidence today — including the things we cannot yet.

    Start with the uncomfortable one

    We are not ISO/IEC 27001 certified as an organisation. GSNA Solutions was founded in April 2024, and since then we have put our effort into building the practice rather than our own management system. That is a choice, and it is one we would question if a client made it — so we will not dress it up as a timing problem.

    We are implementing ours now, to the same standard we implement for other people. When the certification audit is booked, this page will name the body and the date. Until then the position is stated plainly, because a consultancy that oversells its own compliance posture is not a promising supplier of compliance advice. What follows is what we can evidence today, and what we commit to contractually.

    What follows is what we can evidence today, and what we commit to contractually.

    Where your data sits

    • Engagement material stays in named locations. Where you require data residency in a specific jurisdiction, we agree it in writing before the engagement starts and we design to it rather than retrofitting.
    • Client data is segregated per engagement, with access limited to the consultants assigned to it. Access is removed at closure rather than at some later review.
    • We do not move client material into AI tools by default. Where using one would help, we ask first, we tell you which and under what terms, and where the answer is that nothing may leave your boundary, we work inside that constraint.
    • Subprocessors are named. If a third party will touch your material, you know who and why before it happens.

    How we work

    • Multi-factor authentication across company systems, with access reviewed when people join, change role and leave.
    • Endpoint protection and monitoring across company devices.
    • Encrypted storage and transit for client material.
    • Backups taken and restores tested — tested, because a backup nobody has restored is a hope.
    • Documented incident process, with the same clocks we advise clients to work to.
    • Confidentiality obligations in every consultant and associate contract, including associates engaged for a single engagement.
    • Vulnerability disclosure route published at /.well-known/security.txt.

    What we ask of you

    Security in an engagement is a shared arrangement, and these are the things we ask for rather than assume.

    • Least-privilege access rather than blanket administrative rights. We would rather ask twice than hold more than we need.
    • A named contact for access decisions, so that granting and revoking are not improvised.
    • Notice when someone on your side leaves the engagement, so we can close their route in as fast as you close ours.

    Answering your security questionnaire

    Client due diligence questionnaires are part of how this market works and we treat them as a normal cost of doing business rather than an imposition. Send yours and we will complete it — accurately, including the questions where the honest answer is 'not yet'. If a question is one we cannot answer positively, you will see that in the response rather than in a footnote.

    Questions procurement teams ask

    Should we be worried that you are not certified?

    You should ask what we can evidence, which is the right question for any supplier including certified ones — a certificate proves a management system existed at audit, not that your data is handled well today. What we can show is on this page, and we will complete your questionnaire without embellishment.

    When will you be certified?

    We will publish the date when the audit is booked rather than announce an intention. We are unwilling to put a target on a public page that depends on work we have not finished, for the same reason we push back when a client asks us to put one in a board pack.

    Where is our data stored during an engagement?

    Agreed with you in writing before we start. Where residency in a specific jurisdiction is a requirement, it shapes the tooling we use for your engagement — see sovereign hosting for the same question applied to production workloads.

    Do you use AI on our material?

    Not by default, and never without telling you which tool and under what terms. Where your position is that nothing leaves your boundary, we work inside it, and that is a common enough requirement that it is designed for rather than negotiated.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.