Skip to content
iCHEX platform/Trust Centre
Explore the Trust Centre 15 topics

Trust Centre

Trust, built into every layer of iCHEX.

iCHEX is the screening and workforce compliance platform your organisation runs on: independently certified, sector accredited, and governed to match the sensitivity of the data it processes.

Who this is for HR, procurement, IT and security teams evaluating or using iCHEX, covering everything from identity verification through to ongoing compliance monitoring.

Our commitment to security Mat Armstrong, CEO
“
Security and data protection are non-negotiable in our industry. We work with organisations who have a duty of care to their own employees and candidates, and we take that responsibility seriously. This Trust Centre reflects our commitment to transparency and to earning the trust of every client we work with.
Mat Armstrong, CEO
S01

Certifications & accreditations

Independently certified, sector accredited, and reassessed on a recurring cycle. Certificate copies are available by contacting Customer Success.

ISO 27001:2022 logo
ISO 27001:2022
Information security management
Certified
ISO 9001:2015 logo
ISO 9001:2015
Quality management
Certified
ISO 14001:2015 logo
ISO 14001:2015
Environmental management
Certified
Cyber Essentials Plus logo
Cyber Essentials Plus
UK government-backed scheme
Certified
PBSA Accreditation logo
PBSA Accreditation
Professional Background Screening Association
Certified
JOSCAR logo
JOSCAR
Defence & aerospace supply-chain accreditation
Certified
FSQS Registered logo
FSQS Registered
Financial services supply-chain accreditation
Certified
ICO Registration logo
ICO Registration
Ref. ZA242124
Registered
DBS logo
DBS
England, Wales, Channel Islands & Isle of Man
Umbrella Body
Disclosure Scotland logo
Disclosure Scotland
Criminal record checks: Scotland
Registered Body
AccessNI logo
AccessNI
Criminal record checks: Northern Ireland
Registered Body
G-Cloud Supplier logo
G-Cloud Supplier
HM Government digital marketplace
Listed
APSCo Trusted Partner logo
APSCo Trusted Partner
Association of Professional Staffing Companies
Trusted Partner
Microsoft Certified Partner logo
Microsoft Certified Partner
Microsoft Partner Network
Certified Partner
EcoVadis Bronze sustainability rating badge
EcoVadis
Sustainability rating
Bronze · Top 35%
Every certification above is independently audited on an ongoing basis: ISO 27001, ISO 9001 and ISO 14001 undergo annual external surveillance audits and periodic recertification by an accredited, UKAS-recognised certification body, and Cyber Essentials Plus requires annual independent technical re-assessment. No certification, accreditation or registration listed here has been suspended, withdrawn, or subject to a formal notice of non-conformance in the last 12 months.
S02

Data protection & governance

How we're structured to handle some of the most sensitive personal data in the UK employment market.

Role under UK GDPR
Giant Screening Limited acts as a data processor in respect of the candidate data it screens on behalf of clients, and as a data controller for its own employee and business data. Registered with the ICO under the Data Protection Act 2018 / UK GDPR (registration reference ZA242124).
Data we process
Identity and contact information, employment and education history, financial and directorship data, and government-issued identity documents. Depending on the check requested, this can extend to sanctions, PEP and adverse media data and right-to-work documentation. Criminal record information is processed under Article 10 UK GDPR and the relevant conditions in Schedule 1 of the Data Protection Act 2018; health data, where applicable, is processed as special category data under Article 9. Each check is processed under an appropriate lawful basis.
Criminal record data
For UK checks, processed under our DBS Umbrella Body status and as a Registered Body with Disclosure Scotland and AccessNI. Where a role requires it, we also conduct international criminal record checks through accredited in-country providers.
Automated decisions
iCHEX does not make automated hiring or suitability decisions. Where required, the case is quality-checked by a trained analyst before the report is compiled, and the decision on suitability always rests with the client.
Retention
12 months from completion by default, with automated purge at the end of the period. Clients can request a shorter window.
Resilience
A documented Business Continuity Plan, maintained within our ISO 27001-certified Information Security Management System, reviewed and tested annually, with recovery infrastructure held at a separate UK site.
S03

Data security

iCHEX is the screening and workforce compliance platform this Trust Centre covers: the system we use to deliver every Managed Service engagement. It encrypts, backs up and segregates client data by design.

Encryption

Data is encrypted at rest using AES-256, and in transit using TLS 1.3. SSL 3.0, TLS 1.0 and TLS 1.1 are disabled across all systems. Unencrypted connections are not accepted.

Backup & recovery

Full backups run twice daily, with database transaction logs backed up every 15 minutes. Backup copies are encrypted and geo-redundantly replicated across separate UK facilities, and recovery is tested annually plus after significant changes.

Data retention

Where a client hasn't specified otherwise, candidate data is retained for 12 months from case completion, then automatically purged. Where a client has documented different instructions, those apply instead. On request, data can be exported in a portable format or erased ahead of the standard window.

Tenant segregation

Client data is logically segregated at application and database level. No cross-tenant access is possible.

Automated decisions

iCHEX does not make automated decisions about candidates. Where required, the case is quality-checked by a trained analyst before the report is compiled, and the suitability decision always rests with the client.

Data residency

Candidate data is stored exclusively in UK data centres. Where a check requires processing overseas, for example an international criminal record check, data is transferred under appropriate safeguards (an IDTA or SCCs) and is not stored or retained outside the UK.

Data classification

All data assets are classified under a documented Asset Classification and Control Policy, with handling, encryption and access controls applied according to sensitivity.

Secure destruction

Electronic data is permanently and verifiably deleted at the end of its retention period, including from backups. Physical media and paper records are destroyed by a certified provider, with destruction certificates retained as evidence.

S04

Infrastructure & network security

UK-based, carrier-neutral, resilient by design. iCHEX runs on dedicated, single-tenant infrastructure at Equinix LD3 co-location: private hosting, not shared public cloud.

Hosting & resilience

  • Primary: Equinix LD3, London
  • DR: a second, geographically separate UK facility, with replicated data
  • Multiple independent internet feeds at the primary site

Threat detection

  • 24/7 Security Operations Centre (SOC): full event logging and monitoring via a centralised SIEM, with automated alerting and escalation at any hour
  • Managed endpoint protection across all devices
  • Email filtering: anti-phishing, anti-malware, DLP

Physical security

  • Biometric and card-based access control for our own secure areas
  • Equinix LD3 operates 24/7 CCTV, on-site security guarding and mantrap entry as part of a five-layer physical security model
  • Secure areas physically separated, access on a least-privilege basis
  • Server racks and cabinets individually secured
  • Equinix LD3 itself holds ISO 27001, ISO 22301, SOC 2 Type II and PCI DSS certification
S05

Application security

Tested independently, patched continuously, secure by design.

Penetration testing

iCHEX is independently assessed annually, and after significant change, by a CREST-accredited specialist. Findings are remediated to the risk-based timelines set out below, and a redacted summary of the current test is available on request.

Secure development

Security is built in from design: threat modelling and secure architecture review before coding starts, code developed to OWASP Top 10 and Microsoft SDL standards, and mandatory peer review with static code analysis before release. Internet-facing and internal systems are vulnerability-scanned at least quarterly, backed by independent, CREST-accredited penetration testing annually and after significant change.

Vulnerability management

Run under our ISO 27001-certified ISMS, external systems are scanned quarterly and internal systems monthly, in addition to annual penetration testing. Fixes follow risk-based timelines: critical within 24–48 hours, high within 7 days, medium within 30 days, low within 90 days.

Multi-factor authentication

Every user, staff and client alike, authenticates with multi-factor authentication as standard practice when accessing iCHEX.

Session management

Sessions time out automatically after 30 minutes of inactivity, and accounts lock after five unsuccessful login attempts.

API security

All iCHEX APIs are authenticated, rate-limited and monitored. Access requires valid credentials and is logged for audit.

S06

Access control & identity

The right people, the right access, nothing more.

Role-based access
Access to iCHEX is governed by RBAC. Access rights are reviewed at least annually for general users and at least quarterly for privileged and administrator accounts, and immediately on any change of role. The principle of least privilege is applied across all systems.
Password policy
Passwords require a minimum of 12 characters, with upper- and lower-case letters, a number and a special character. Passwords expire every 30 days and cannot be reused, and are stored as salted cryptographic hashes, never in plaintext. Accounts lock after five unsuccessful attempts.
Privileged access
Access to production systems is strictly controlled, logged and subject to enhanced authentication. Server access uses key-based authentication; password-based server access is disabled.
Audit & deprovisioning
All access events and administrative actions are written to immutable audit logs. Under a formal Joiners, Movers and Leavers (JML) process, access is revoked within 24 hours of a leaver or client deprovisioning request, adjusted immediately on role change, and dormant accounts are removed on quarterly review.
S07

Platform & accessibility

How tenants, candidates and your own systems connect to iCHEX.

Platform

iCHEX is a browser-based SaaS platform, accessed over HTTPS only. No client-side software or plug-ins are required for tenant users, candidates or referees.

API access

iCHEX exposes a JSON/REST API, authenticated by token-based credentials passed in the request header. API access carries the same tenant- and role-based permissions as the standard interface, and every call is logged for audit.

Tenant integrations

iCHEX integrates with ATS and HRIS platforms via the API, so screening cases can be initiated and tracked without leaving your existing recruitment or HR systems.

Candidate & referee access

Candidates and referees receive a secure, tokenised link to their own portal within iCHEX. No account creation or password is required, and access is time-limited and single-purpose.

Accessibility

Adjustable text size, colour contrast options, keyboard navigation and screen reader support are available throughout iCHEX. We're working towards full WCAG 2.1 AA compliance and are actively reviewing the platform to close any remaining gaps.

Reporting an issue

Candidates, referees and tenant users can report an accessibility barrier at any time through Customer Success, who will log and track it to resolution.

S08

Service levels, support & incident response

What to expect day-to-day, and what happens when something goes wrong.

Platform availability

iCHEX targets 99.9% system availability. Planned maintenance is scheduled outside core business hours and communicated to clients in advance.

Incident response plan

A documented Information Security Incident Response Plan, maintained under our ISO 27001-certified ISMS, is reviewed annually and tested through tabletop and simulation exercises.

Client notification

Clients are notified within 24 hours of us becoming aware of a security incident or data breach affecting their data, by email and phone to the designated contact.

Full incident report

A comprehensive written report, covering root cause, impact, mitigation and corrective action, follows within 72 hours of the initial notification.

Regulatory notification

Where required under UK GDPR, the ICO is notified within 72 hours of a reportable personal data breach; affected individuals are notified without undue delay where there is high risk to their rights.

S09

Global operations & international transfers

A UK-headquartered business with a global delivery team, and transfers governed to the letter of the law.

Where our people are

United Kingdom: primary delivery and client-facing team; all candidate data is stored and processed here.

Additional international support functions handle operational and document processing administration, delivered by dedicated teams working under contract to Giant Screening. Full detail, including location, is set out in our sub-processor register below.

All international connections to UK systems are encrypted and authenticated. No candidate data is stored locally at any international site, and none is replicated outside the UK.

Transfer governance

International transfers are governed by UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs), as appropriate to the destination.

Transfer Impact Assessments have been completed for all international transfers, and a Global Processing DPIA covering our international operations has been completed and approved at Board level.

S10

Staff security & vetting

Our people are screened to the same standard we apply to your candidates.

Pre-employment screening

Conducted in line with BS 7858: identity verification, employment history, financial checks, media and sanctions screening, and criminal record checks where applicable. Staff with access to sensitive data are vetted to at least BS 7858, with re-screening on a recurring cycle.

Ongoing assurance

Mandatory security awareness training at induction, refreshed at least every six months (with some modules quarterly) and reinforced by an annual refresher. All staff are re-screened annually. Confidentiality agreements are a condition of employment, supported by a documented insider threat programme. Employee turnover runs well below the industry average, reflecting a stable, experienced team.

S11

Insurance & financial standing

Adequately insured, financially stable, and with a clean track record.

Insurance cover held

Employers' Liability: £10,000,000
Public / Products Liability: £10,000,000
Professional Indemnity: £10,000,000
Cyber Liability: £5,000,000

All policies are current and renew annually with our insurer. Certificates of insurance are available by contacting Customer Success.

Financial position

Giant Screening Limited (company no. 10656083) is a financially stable, independently operating limited company. Statutory accounts are filed at Companies House and publicly available; turnover figures are available by contacting Customer Success. Giant Screening Limited is not part of a private equity portfolio or leveraged buy-out structure.

Track record

No material litigation, disputes or arbitration proceedings in the last three years. No notice of termination for service failure in the last three years. No regulatory enforcement or investigation in the last five years. No personal data breaches reported to the ICO in the last five years.

Audit

An internal audit function reviews compliance with information security policies and the ISMS on a scheduled and unscheduled basis, with findings tracked to resolution and reported to senior management.

S12

Corporate responsibility & ethics

Governance that extends beyond data protection to how we run the business.

Anti-bribery & corruption

A zero-tolerance Anti-Bribery Policy applies across the business, reinforced by mandatory staff training. No confirmed corruption incidents in the most recent reporting year.

Modern Slavery

A Modern Slavery Policy is maintained and applied throughout the business and supply chain. Giant Screening Limited sits below the £36m turnover threshold that would require a statutory Section 54 statement, but holds itself to the same standard regardless.

Environment

ISO 14001 certified. A Carbon Reduction Plan is published in line with PPN 06/21, targeting UK carbon neutrality by 2050.

Diversity & inclusion

Diversity & Inclusion, Equal Opportunities and Anti-Harassment policies are in place. No findings of unlawful discrimination in the last three years.

Whistleblowing

A formal Whistleblowing Policy gives staff and third parties a confidential route to raise concerns, including on information security and ethics matters.

Independent assessment

We hold a current EcoVadis sustainability rating of Bronze, placing us in the top 35% of companies assessed, covering environmental, labour, ethics and procurement practices. Full scorecard available by contacting Customer Success.

S13

Sub-processor register

Full transparency on who processes data on our behalf. Every sub-processor goes through a security review before onboarding, an annual review while engaged, and a formal offboarding process, including data deletion and access revocation, when the relationship ends. The register is reviewed quarterly, or immediately on any change. Clients are notified of material changes to this register and may object.

Sub-processorLocationNature of processingTransfer mechanism
Statutory / government bodies
Disclosure and Barring Service (DBS)UKCriminal record checks: England, Wales, Channel Islands, Isle of ManStatutory · UK
Disclosure ScotlandUKCriminal record checks: ScotlandStatutory · UK
AccessNIUKCriminal record checks: Northern IrelandStatutory · UK
Commercial sub-processors: UK
CIFASUKFraud screening and informationUK domestic
EquifaxUKCredit report & scoring; employment verification (HMRC)UK domestic
GBG ID ScanUKIdentity investigation & validationUK domestic
Trust IDUKIdentity document verification (operational provider)UK domestic
YotiUKIdentity document verification (integrated; not the operational provider)UK domestic
HEDDUKDegree verificationUK domestic
KonfirUKEmployment verification: HMRC, payroll, Open BankingUK domestic
MisthoUKEmployment verification: HMRCUK domestic
NeotasUKOnline due diligence & social media screeningUK domestic
DocuSignUKElectronic signatureUK domestic
EsendexUKSMS / WhatsApp messagingUK domestic
Postcoder.comUKPostcode lookupUK domestic
Commercial sub-processors: international
FamaUnited StatesOnline due diligence & social media screeningSCC / IDTA
OwensUnited StatesGlobal credit, criminal & directorship checksSCC / IDTA
Net Force GlobalUnited StatesGlobal credit, criminal & directorship checksSCC / IDTA
I-CoverFranceGlobal credit, criminal & directorship checksSCC / IDTA
One Source Technology, LLCUnited StatesUS background check deliverySCC / IDTA
Kombo Technologies GmbHGermanyUnified API: verification data aggregationEU · adequacy decision
Group operational entities
Giant Precision (Private) LtdPakistanScreening operations support: no local data storageIDTA / UK Addendum · intragroup
Quality Assured Services Inc.PhilippinesDocument processing support: no local data storageIDTA / UK Addendum · intragroup
S14

Candidate & data subject rights

Your rights under UK GDPR, and how to exercise them.

01
Right of access: request a copy of the personal data we hold about you.
02
Right to rectification: ask us to correct inaccurate or incomplete data.
03
Right to erasure: request deletion where there's no lawful basis to keep it.
04
Right to restriction: ask us to restrict processing in certain circumstances.
05
Right to portability: request your data in a structured, machine-readable format.
06
Right to object: object to processing based on legitimate interests.
07
Automated decisions: not applicable: we do not use automated decision-making.
08
Right to withdraw consent: where processing relies on consent, you may withdraw it at any time.
How to submit a requestEmail [email protected], our Data Protection team. Requests are acknowledged within 72 hours and responded to within one calendar month. You can also complain to the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
S15

Document library

Every document below is available from Customer Success on request, so get in touch and we'll share what's needed.

Policies & public statements

▤
Privacy Policy
How we collect, use and protect personal data, as a processor for client screening and a controller for our own staff
▤
Data Protection Policy
Our internal data protection standards and controls, aligned to UK GDPR and the Data Protection Act 2018
▤
Data Retention Policy
Sets retention periods for candidate and client data, and the secure deletion process once they expire
▤
Information Security Policy Statement
One-page public summary of our ISO 27001-aligned information security programme
▤
Subject Access Request Policy
How we handle Subject Access Requests and other UK GDPR data subject rights within statutory timeframes
▤
Complaints Handling Policy
Our process for logging, investigating and resolving client and candidate complaints
▤
Policy on the Recruitment of Ex-Offenders
Candidate-facing policy on the fair treatment of applicants with convictions, aligned to DBS guidance
▤
Modern Slavery Policy
Our approach to preventing modern slavery and human trafficking across our business and supply chain
▤
Anti-Bribery Policy
Our zero-tolerance approach to bribery and corruption, aligned to the Bribery Act 2010
▤
Diversity & Inclusion Policy
Our commitment to equal opportunity and an inclusive workplace, free from unlawful discrimination
▤
Whistleblowing Policy
A protected route for staff to raise concerns about illegal activity or breaches of policy
▤
Carbon Reduction Plan (PPN 06/21)
Our published carbon reduction commitments under the UK government's PPN 06/21 procurement policy note
▤
Accessibility Statement for iCHEX
Current WCAG 2.1 AA compliance status and how to report an accessibility issue

Assurance & compliance documents

▤
Certificates of insurance
Confirms current cover: £10m each for Employers', Public & Professional Indemnity Liability, plus £5m Cyber Liability
▤
Penetration test summary
Independent CREST-accredited findings for the current annual test cycle, redacted to remove exploit detail
▤
DPIA: global processing
Assesses privacy risk across our global processing footprint and international support operations
▤
Business Continuity Plan summary
Client-facing overview of our resilience model, recovery targets and 24/7 monitoring arrangements
▤
Data Transfer Impact Assessment
Assesses safeguards for any personal data transferred outside the UK, including SCCs/IDTA basis
▤
Data Breach Policy
Our incident detection, containment and notification process, including statutory ICO and client timescales
▤
DPA / MSA templates
Standard data processing and master service agreement templates, ready for contract execution

Certificates & registrations

▤
ISO 27001 Certificate
Confirms our certified Information Security Management System, covering all systems and processes behind screening delivery
▤
ISO 9001 Certificate
Confirms our certified Quality Management System covering all service delivery processes
▤
ISO 14001 Certificate
Confirms our certified Environmental Management System
▤
Cyber Essentials Plus Certificate
UK government-backed certification with independently tested technical controls
▤
PBSA Membership Certificate
Confirms accreditation by the Professional Background Screening Association
▤
JOSCAR Certificate
Confirms our accreditation on the aerospace, defence and security sector's shared supplier assurance register
▤
ICO Registration Certificate
Confirms our registration with the Information Commissioner's Office, reference ZA242124
▤
Certificate of Incorporation
Confirms registration at Companies House, company no. 10656083
▤
VAT Registration Certificate
Confirms our VAT registration for invoicing and procurement purposes
▤
EcoVadis Scorecard
Full sustainability assessment behind our Bronze rating, covering environmental, labour, ethics and procurement practices
Need a copy of any of the above?Contact Customer Success and we'll get it to you.

Further technical & operational policies

These policies describe control mechanics in more technical detail and are shared under NDA or as part of a contracted due diligence review, rather than by open request.

Access Control Policy Encryption Policy Password Policy Vulnerability & Threat Management Policy Secure Development Lifecycle (SDLC) Policy Backup Policy Physical Security Policy Change Management Policy Business Continuity Plan (full) Supplier Information Security Policy

Available under NDA or contract. Contact Customer Success to arrange a formal review.