digitalRG
Log in
Security

How we protect your data.

The certifications, controls and commitments behind the platform, in the detail a security or procurement team needs.

Current as at August 2026.

At a glance

Certified, encrypted, and independently tested.

Certified & EU/EEA-hosted

Cyber Essentials, hosted in the EU/EEA.

digitalRG holds Cyber Essentials certification across the whole organisation, valid to 31 July 2027. The platform runs on AWS in the EU/EEA, behind Cloudflare for DNS, DDoS protection and edge security.

Encrypted & access-controlled

Encrypted, and independently assessed.

Data is encrypted in transit and at rest. Every account uses individual multi-factor authentication with role-based permissions, and the platform is penetration tested by an independent specialist every year.

Operated in the UK

Run by Silverfish CSR Limited.

digitalRG is operated by Silverfish CSR Limited, a UK company. Certificates and policies are issued in that name, and our documentation is available to your security and procurement teams.

Resilience

Built to stay up, and to recover fast.

< 4 hrs
Recovery time target for critical systems
3.5 hrs
Last outage simulation, core services restored
2× a year
Full disaster-recovery drills
12 months
Independent penetration-test cycle
Recovery time targetUnder 4 hours
Most recent restore3.5 hours
Certification & assurance

The proof behind the platform.

Cyber Essentials
Certified across the whole organisation by Delta Cyber Security under the IASME Consortium. Issued 31 July 2026 and valid to 31 July 2027. The certificate carries a QR code so you can verify it independently.
Information security policy
Our information security management is aligned to ISO/IEC 27001:2022, including the Annex A controls covering supplier relationships and supply chain security. Policies are reviewed annually and on any material change.
Independent penetration testing
Web application penetration testing and formal retesting is carried out every 12 months by an independent specialist. The most recent retest report is dated September 2025 and is available under NDA.
Published documentation
Terms and conditions, privacy and cookies policy, and data processing terms are published at digitalrg.com.
Registered with the Information Commissioner's OfficeCyber Essentials CertifiedCPD Member, The CPD Certification ServiceISO/IEC 27001
FAQ

Security questions, answered.

Where is our data hosted?

Amazon Web Services, with platform data held in the EU/EEA. Cloudflare sits in front of the platform providing DNS, DDoS mitigation and edge security.

Is our data encrypted?

Yes. All data is encrypted in transit over HTTPS/TLS and at rest on AWS using industry-standard algorithms.

How is access controlled?

Individual named logins with multi-factor authentication, and shared or generic credentials are prohibited, so every action is individually attributable and logged. Access follows least privilege, and administrative access is time-bound, monitored and reviewed at least quarterly. You manage your own users and roles.

How is our data kept separate from other customers?

Every customer holds a separate account. Data is segregated by account, and visibility inside an account is controlled by role.

Are you penetration tested?

Yes. Independent web application penetration testing every 12 months, followed by a formal retest to confirm findings have been remediated. Security patches are applied on a risk-based timeframe, supported by regular vulnerability scanning.

Who is the data controller and processor?

You are the data controller and keep control of everything your team uploads. Silverfish CSR Limited acts as data processor and processes personal data only on your documented instructions, under UK GDPR and the Data Protection Act 2018, and the EU GDPR where it applies.

How are sub-processors handled?

Additions or replacements are notified through an update to the Privacy and Cookies Policy, giving you the opportunity to object before the change takes effect.

What happens to our data if we leave?

On expiry or termination, your data is deleted or returned to you at your written direction.

How quickly can you recover from an outage?

A target recovery time of under four hours for all critical systems, with less critical services on a stepped restoration timeline. Disaster recovery drills run twice a year, and the most recent data-centre outage simulation restored core services in 3.5 hours.

How do you handle a security incident or breach?

A documented incident response process covers detection, containment, investigation, regulatory notification and customer communication. We notify you without undue delay on becoming aware of a personal data breach involving your data.

What data should we not upload?

The platform is not designed for consumer, financial, payment, health or criminal-justice data, and customers are asked not to upload it. Payment card details are never handled by digitalRG; payment is taken by a third-party provider on its own secure pages.

Can we see your security documentation?

Yes. Our Cyber Essentials certificate, information security policy, disaster recovery and business continuity policy, data processing terms and the latest penetration test summary are available on request. Completed security questionnaires and a signed DPA can be provided during procurement.

Our Cyber Essentials certificate, information security policy, disaster recovery and business continuity policy, data processing terms and latest penetration test summary are all available on request. Completed security questionnaires and a signed DPA can be provided during procurement.