Skip to main content

Update: Golden thread, gateways, safety case & KBI on every plan — User manual

Trust Centre

Built on Trust

Transparency is core to how we operate. Find all our legal documents, compliance information, and company details in one place.

Company Information

Registered Company

Company Name
Threadsovereign Ltd
Status
Active
Company No.
17178521
ICO Registration
ZC132889
Registered in
England & Wales

Tax & Insurance

VAT Number
GB 522 6434 10
Professional Indemnity
Held — details available on request

Registered Address

Threadsovereign Ltd
1 St. Peters Mews, Poole, England, BH14 0DN

Procurement & assurance pack

Documentation to support due diligence and information governance. Independent penetration testing, DPIA, and external legal review of terms are in our assurance programme and not yet complete — see Security for current status.

Assurance programme

Threadsovereign publishes policies and technical controls in place today. The items below are part of our go-live assurance programme and are not yet complete — ask security@threadsovereign.co.uk for current status before procurement sign-off.

Independent penetration test

Not yet completed. OWASP Top 10 minimum scope with an external tester is planned.

Data Protection Impact Assessment (DPIA)

Not yet completed. Required for resident and PEEP special-category data processing. An internal draft exists; DPO/counsel sign-off is outstanding.

Legal review — Terms & DPA

Not yet completed. External counsel review for BSA-regulated building contexts is required.

Formal security review

Not yet scheduled. Covers environment variables, secrets handling, and auth configuration.

Compliance & Certifications

In place today

ICO Registration

ZC132889

VAT Registration

GB 522 6434 10

UK GDPR

Aligned operations

Certification roadmap

We are preparing Cyber Essentials (basic) for IASME submission and building an ISMS foundation toward ISO 27001. None of the items below are certified today — ask security@threadsovereign.co.uk for current status before procurement sign-off.

Cyber Essentials (basic)

Internal readiness pack prepared for IASME self-assessment submission — not yet certified. Do not treat as Cyber Essentials certified until a certificate is issued.

Cyber Essentials Plus

Planned after Cyber Essentials (basic). Certification has not commenced.

ISO 27001

ISMS foundation documentation in progress. Formal certification audit has not commenced.

SOC 2 Type II

Planned for enterprise buyers. Certification has not commenced.

Need More Information?

Our legal and compliance team is happy to answer questions or provide additional documentation.