The certifications, controls and commitments behind the platform, in the detail a security or procurement team needs.
Current as at August 2026.
digitalRG holds Cyber Essentials certification across the whole organisation, valid to 31 July 2027. The platform runs on AWS in the EU/EEA, behind Cloudflare for DNS, DDoS protection and edge security.
Data is encrypted in transit and at rest. Every account uses individual multi-factor authentication with role-based permissions, and the platform is penetration tested by an independent specialist every year.
digitalRG is operated by Silverfish CSR Limited, a UK company. Certificates and policies are issued in that name, and our documentation is available to your security and procurement teams.




Amazon Web Services, with platform data held in the EU/EEA. Cloudflare sits in front of the platform providing DNS, DDoS mitigation and edge security.
Yes. All data is encrypted in transit over HTTPS/TLS and at rest on AWS using industry-standard algorithms.
Individual named logins with multi-factor authentication, and shared or generic credentials are prohibited, so every action is individually attributable and logged. Access follows least privilege, and administrative access is time-bound, monitored and reviewed at least quarterly. You manage your own users and roles.
Every customer holds a separate account. Data is segregated by account, and visibility inside an account is controlled by role.
Yes. Independent web application penetration testing every 12 months, followed by a formal retest to confirm findings have been remediated. Security patches are applied on a risk-based timeframe, supported by regular vulnerability scanning.
You are the data controller and keep control of everything your team uploads. Silverfish CSR Limited acts as data processor and processes personal data only on your documented instructions, under UK GDPR and the Data Protection Act 2018, and the EU GDPR where it applies.
Additions or replacements are notified through an update to the Privacy and Cookies Policy, giving you the opportunity to object before the change takes effect.
On expiry or termination, your data is deleted or returned to you at your written direction.
A target recovery time of under four hours for all critical systems, with less critical services on a stepped restoration timeline. Disaster recovery drills run twice a year, and the most recent data-centre outage simulation restored core services in 3.5 hours.
A documented incident response process covers detection, containment, investigation, regulatory notification and customer communication. We notify you without undue delay on becoming aware of a personal data breach involving your data.
The platform is not designed for consumer, financial, payment, health or criminal-justice data, and customers are asked not to upload it. Payment card details are never handled by digitalRG; payment is taken by a third-party provider on its own secure pages.
Yes. Our Cyber Essentials certificate, information security policy, disaster recovery and business continuity policy, data processing terms and the latest penetration test summary are available on request. Completed security questionnaires and a signed DPA can be provided during procurement.
Our Cyber Essentials certificate, information security policy, disaster recovery and business continuity policy, data processing terms and latest penetration test summary are all available on request. Completed security questionnaires and a signed DPA can be provided during procurement.