Explore the Trust Centre 15 topics
Trust Centre
Trust, built into every layer of iCHEX.
iCHEX is the screening and workforce compliance platform your organisation runs on: independently certified, sector accredited, and governed to match the sensitivity of the data it processes.
Who this is for HR, procurement, IT and security teams evaluating or using iCHEX, covering everything from identity verification through to ongoing compliance monitoring.
Our commitment to security Mat Armstrong, CEO
Security and data protection are non-negotiable in our industry. We work with organisations who have a duty of care to their own employees and candidates, and we take that responsibility seriously. This Trust Centre reflects our commitment to transparency and to earning the trust of every client we work with.Mat Armstrong, CEO
Certifications & accreditations
Independently certified, sector accredited, and reassessed on a recurring cycle. Certificate copies are available by contacting Customer Success.















Data protection & governance
How we're structured to handle some of the most sensitive personal data in the UK employment market.
- Role under UK GDPR
- Giant Screening Limited acts as a data processor in respect of the candidate data it screens on behalf of clients, and as a data controller for its own employee and business data. Registered with the ICO under the Data Protection Act 2018 / UK GDPR (registration reference ZA242124).
- Data we process
- Identity and contact information, employment and education history, financial and directorship data, and government-issued identity documents. Depending on the check requested, this can extend to sanctions, PEP and adverse media data and right-to-work documentation. Criminal record information is processed under Article 10 UK GDPR and the relevant conditions in Schedule 1 of the Data Protection Act 2018; health data, where applicable, is processed as special category data under Article 9. Each check is processed under an appropriate lawful basis.
- Criminal record data
- For UK checks, processed under our DBS Umbrella Body status and as a Registered Body with Disclosure Scotland and AccessNI. Where a role requires it, we also conduct international criminal record checks through accredited in-country providers.
- Automated decisions
- iCHEX does not make automated hiring or suitability decisions. Where required, the case is quality-checked by a trained analyst before the report is compiled, and the decision on suitability always rests with the client.
- Retention
- 12 months from completion by default, with automated purge at the end of the period. Clients can request a shorter window.
- Resilience
- A documented Business Continuity Plan, maintained within our ISO 27001-certified Information Security Management System, reviewed and tested annually, with recovery infrastructure held at a separate UK site.
Data security
iCHEX is the screening and workforce compliance platform this Trust Centre covers: the system we use to deliver every Managed Service engagement. It encrypts, backs up and segregates client data by design.
Encryption
Data is encrypted at rest using AES-256, and in transit using TLS 1.3. SSL 3.0, TLS 1.0 and TLS 1.1 are disabled across all systems. Unencrypted connections are not accepted.
Backup & recovery
Full backups run twice daily, with database transaction logs backed up every 15 minutes. Backup copies are encrypted and geo-redundantly replicated across separate UK facilities, and recovery is tested annually plus after significant changes.
Data retention
Where a client hasn't specified otherwise, candidate data is retained for 12 months from case completion, then automatically purged. Where a client has documented different instructions, those apply instead. On request, data can be exported in a portable format or erased ahead of the standard window.
Tenant segregation
Client data is logically segregated at application and database level. No cross-tenant access is possible.
Automated decisions
iCHEX does not make automated decisions about candidates. Where required, the case is quality-checked by a trained analyst before the report is compiled, and the suitability decision always rests with the client.
Data residency
Candidate data is stored exclusively in UK data centres. Where a check requires processing overseas, for example an international criminal record check, data is transferred under appropriate safeguards (an IDTA or SCCs) and is not stored or retained outside the UK.
Data classification
All data assets are classified under a documented Asset Classification and Control Policy, with handling, encryption and access controls applied according to sensitivity.
Secure destruction
Electronic data is permanently and verifiably deleted at the end of its retention period, including from backups. Physical media and paper records are destroyed by a certified provider, with destruction certificates retained as evidence.
Infrastructure & network security
UK-based, carrier-neutral, resilient by design. iCHEX runs on dedicated, single-tenant infrastructure at Equinix LD3 co-location: private hosting, not shared public cloud.
Hosting & resilience
- Primary: Equinix LD3, London
- DR: a second, geographically separate UK facility, with replicated data
- Multiple independent internet feeds at the primary site
Threat detection
- 24/7 Security Operations Centre (SOC): full event logging and monitoring via a centralised SIEM, with automated alerting and escalation at any hour
- Managed endpoint protection across all devices
- Email filtering: anti-phishing, anti-malware, DLP
Physical security
- Biometric and card-based access control for our own secure areas
- Equinix LD3 operates 24/7 CCTV, on-site security guarding and mantrap entry as part of a five-layer physical security model
- Secure areas physically separated, access on a least-privilege basis
- Server racks and cabinets individually secured
- Equinix LD3 itself holds ISO 27001, ISO 22301, SOC 2 Type II and PCI DSS certification
Application security
Tested independently, patched continuously, secure by design.
Penetration testing
iCHEX is independently assessed annually, and after significant change, by a CREST-accredited specialist. Findings are remediated to the risk-based timelines set out below, and a redacted summary of the current test is available on request.
Secure development
Security is built in from design: threat modelling and secure architecture review before coding starts, code developed to OWASP Top 10 and Microsoft SDL standards, and mandatory peer review with static code analysis before release. Internet-facing and internal systems are vulnerability-scanned at least quarterly, backed by independent, CREST-accredited penetration testing annually and after significant change.
Vulnerability management
Run under our ISO 27001-certified ISMS, external systems are scanned quarterly and internal systems monthly, in addition to annual penetration testing. Fixes follow risk-based timelines: critical within 24–48 hours, high within 7 days, medium within 30 days, low within 90 days.
Multi-factor authentication
Every user, staff and client alike, authenticates with multi-factor authentication as standard practice when accessing iCHEX.
Session management
Sessions time out automatically after 30 minutes of inactivity, and accounts lock after five unsuccessful login attempts.
API security
All iCHEX APIs are authenticated, rate-limited and monitored. Access requires valid credentials and is logged for audit.
Access control & identity
The right people, the right access, nothing more.
- Role-based access
- Access to iCHEX is governed by RBAC. Access rights are reviewed at least annually for general users and at least quarterly for privileged and administrator accounts, and immediately on any change of role. The principle of least privilege is applied across all systems.
- Password policy
- Passwords require a minimum of 12 characters, with upper- and lower-case letters, a number and a special character. Passwords expire every 30 days and cannot be reused, and are stored as salted cryptographic hashes, never in plaintext. Accounts lock after five unsuccessful attempts.
- Privileged access
- Access to production systems is strictly controlled, logged and subject to enhanced authentication. Server access uses key-based authentication; password-based server access is disabled.
- Audit & deprovisioning
- All access events and administrative actions are written to immutable audit logs. Under a formal Joiners, Movers and Leavers (JML) process, access is revoked within 24 hours of a leaver or client deprovisioning request, adjusted immediately on role change, and dormant accounts are removed on quarterly review.
Platform & accessibility
How tenants, candidates and your own systems connect to iCHEX.
Platform
iCHEX is a browser-based SaaS platform, accessed over HTTPS only. No client-side software or plug-ins are required for tenant users, candidates or referees.
API access
iCHEX exposes a JSON/REST API, authenticated by token-based credentials passed in the request header. API access carries the same tenant- and role-based permissions as the standard interface, and every call is logged for audit.
Tenant integrations
iCHEX integrates with ATS and HRIS platforms via the API, so screening cases can be initiated and tracked without leaving your existing recruitment or HR systems.
Candidate & referee access
Candidates and referees receive a secure, tokenised link to their own portal within iCHEX. No account creation or password is required, and access is time-limited and single-purpose.
Accessibility
Adjustable text size, colour contrast options, keyboard navigation and screen reader support are available throughout iCHEX. We're working towards full WCAG 2.1 AA compliance and are actively reviewing the platform to close any remaining gaps.
Reporting an issue
Candidates, referees and tenant users can report an accessibility barrier at any time through Customer Success, who will log and track it to resolution.
Service levels, support & incident response
What to expect day-to-day, and what happens when something goes wrong.
Platform availability
iCHEX targets 99.9% system availability. Planned maintenance is scheduled outside core business hours and communicated to clients in advance.
Incident response plan
A documented Information Security Incident Response Plan, maintained under our ISO 27001-certified ISMS, is reviewed annually and tested through tabletop and simulation exercises.
Client notification
Clients are notified within 24 hours of us becoming aware of a security incident or data breach affecting their data, by email and phone to the designated contact.
Full incident report
A comprehensive written report, covering root cause, impact, mitigation and corrective action, follows within 72 hours of the initial notification.
Regulatory notification
Where required under UK GDPR, the ICO is notified within 72 hours of a reportable personal data breach; affected individuals are notified without undue delay where there is high risk to their rights.
Global operations & international transfers
A UK-headquartered business with a global delivery team, and transfers governed to the letter of the law.
Where our people are
United Kingdom: primary delivery and client-facing team; all candidate data is stored and processed here.
Additional international support functions handle operational and document processing administration, delivered by dedicated teams working under contract to Giant Screening. Full detail, including location, is set out in our sub-processor register below.
All international connections to UK systems are encrypted and authenticated. No candidate data is stored locally at any international site, and none is replicated outside the UK.
Transfer governance
International transfers are governed by UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs), as appropriate to the destination.
Transfer Impact Assessments have been completed for all international transfers, and a Global Processing DPIA covering our international operations has been completed and approved at Board level.
Staff security & vetting
Our people are screened to the same standard we apply to your candidates.
Pre-employment screening
Conducted in line with BS 7858: identity verification, employment history, financial checks, media and sanctions screening, and criminal record checks where applicable. Staff with access to sensitive data are vetted to at least BS 7858, with re-screening on a recurring cycle.
Ongoing assurance
Mandatory security awareness training at induction, refreshed at least every six months (with some modules quarterly) and reinforced by an annual refresher. All staff are re-screened annually. Confidentiality agreements are a condition of employment, supported by a documented insider threat programme. Employee turnover runs well below the industry average, reflecting a stable, experienced team.
Insurance & financial standing
Adequately insured, financially stable, and with a clean track record.
Insurance cover held
Employers' Liability: £10,000,000
Public / Products Liability: £10,000,000
Professional Indemnity: £10,000,000
Cyber Liability: £5,000,000
All policies are current and renew annually with our insurer. Certificates of insurance are available by contacting Customer Success.
Financial position
Giant Screening Limited (company no. 10656083) is a financially stable, independently operating limited company. Statutory accounts are filed at Companies House and publicly available; turnover figures are available by contacting Customer Success. Giant Screening Limited is not part of a private equity portfolio or leveraged buy-out structure.
Track record
No material litigation, disputes or arbitration proceedings in the last three years. No notice of termination for service failure in the last three years. No regulatory enforcement or investigation in the last five years. No personal data breaches reported to the ICO in the last five years.
Audit
An internal audit function reviews compliance with information security policies and the ISMS on a scheduled and unscheduled basis, with findings tracked to resolution and reported to senior management.
Corporate responsibility & ethics
Governance that extends beyond data protection to how we run the business.
Anti-bribery & corruption
A zero-tolerance Anti-Bribery Policy applies across the business, reinforced by mandatory staff training. No confirmed corruption incidents in the most recent reporting year.
Modern Slavery
A Modern Slavery Policy is maintained and applied throughout the business and supply chain. Giant Screening Limited sits below the £36m turnover threshold that would require a statutory Section 54 statement, but holds itself to the same standard regardless.
Environment
ISO 14001 certified. A Carbon Reduction Plan is published in line with PPN 06/21, targeting UK carbon neutrality by 2050.
Diversity & inclusion
Diversity & Inclusion, Equal Opportunities and Anti-Harassment policies are in place. No findings of unlawful discrimination in the last three years.
Whistleblowing
A formal Whistleblowing Policy gives staff and third parties a confidential route to raise concerns, including on information security and ethics matters.
Independent assessment
We hold a current EcoVadis sustainability rating of Bronze, placing us in the top 35% of companies assessed, covering environmental, labour, ethics and procurement practices. Full scorecard available by contacting Customer Success.
Sub-processor register
Full transparency on who processes data on our behalf. Every sub-processor goes through a security review before onboarding, an annual review while engaged, and a formal offboarding process, including data deletion and access revocation, when the relationship ends. The register is reviewed quarterly, or immediately on any change. Clients are notified of material changes to this register and may object.
| Sub-processor | Location | Nature of processing | Transfer mechanism |
|---|---|---|---|
| Statutory / government bodies | |||
| Disclosure and Barring Service (DBS) | UK | Criminal record checks: England, Wales, Channel Islands, Isle of Man | Statutory · UK |
| Disclosure Scotland | UK | Criminal record checks: Scotland | Statutory · UK |
| AccessNI | UK | Criminal record checks: Northern Ireland | Statutory · UK |
| Commercial sub-processors: UK | |||
| CIFAS | UK | Fraud screening and information | UK domestic |
| Equifax | UK | Credit report & scoring; employment verification (HMRC) | UK domestic |
| GBG ID Scan | UK | Identity investigation & validation | UK domestic |
| Trust ID | UK | Identity document verification (operational provider) | UK domestic |
| Yoti | UK | Identity document verification (integrated; not the operational provider) | UK domestic |
| HEDD | UK | Degree verification | UK domestic |
| Konfir | UK | Employment verification: HMRC, payroll, Open Banking | UK domestic |
| Mistho | UK | Employment verification: HMRC | UK domestic |
| Neotas | UK | Online due diligence & social media screening | UK domestic |
| DocuSign | UK | Electronic signature | UK domestic |
| Esendex | UK | SMS / WhatsApp messaging | UK domestic |
| Postcoder.com | UK | Postcode lookup | UK domestic |
| Commercial sub-processors: international | |||
| Fama | United States | Online due diligence & social media screening | SCC / IDTA |
| Owens | United States | Global credit, criminal & directorship checks | SCC / IDTA |
| Net Force Global | United States | Global credit, criminal & directorship checks | SCC / IDTA |
| I-Cover | France | Global credit, criminal & directorship checks | SCC / IDTA |
| One Source Technology, LLC | United States | US background check delivery | SCC / IDTA |
| Kombo Technologies GmbH | Germany | Unified API: verification data aggregation | EU · adequacy decision |
| Group operational entities | |||
| Giant Precision (Private) Ltd | Pakistan | Screening operations support: no local data storage | IDTA / UK Addendum · intragroup |
| Quality Assured Services Inc. | Philippines | Document processing support: no local data storage | IDTA / UK Addendum · intragroup |
Candidate & data subject rights
Your rights under UK GDPR, and how to exercise them.
Document library
Every document below is available from Customer Success on request, so get in touch and we'll share what's needed.
Policies & public statements
Assurance & compliance documents
Certificates & registrations
Further technical & operational policies
These policies describe control mechanics in more technical detail and are shared under NDA or as part of a contracted due diligence review, rather than by open request.
Available under NDA or contract. Contact Customer Success to arrange a formal review.