Skip to content

For procurement and vendor onboarding

How we handle your systems and your data

This page exists so your security review does not have to start with an email. If your questionnaire asks something not covered here, send it over and we will complete it properly.

Engagements
Under NDA as standard
People
Background-checked engineers
Data
GDPR and DPA ready
Infrastructure
World-renowned cloud providers

Practices

What we commit to

Confidentiality
We work under NDA as standard and will sign yours rather than insisting on ours. We do not publish client names, and we do not reference an engagement in a proposal without written permission.
People
Engineers are background-checked before they are placed on an engagement. Everyone who touches client systems is a named individual known to you, not an anonymous resource from a pool.
Access control
Named accounts, least privilege, multi-factor authentication, and access scoped to the engagement. Offboarding is documented and revocation is verified rather than assumed.
Client data
We work on your infrastructure wherever possible. Where data must move, it is minimised, encrypted in transit and at rest, and kept in the region your obligations require. We do not copy production player data into development environments.
Secure development
Review before merge, dependency and container scanning in the pipeline, secrets held in a managed store rather than in configuration, and security review on any change touching authentication, payments or personal data.
Incident response
A named contact, an agreed escalation path and a defined response target on engagements where we carry operational responsibility. Post-incident, you get a written account of cause and remediation.
Data protection
We act as processor on your behalf and will sign a data processing agreement. Sub-processors are disclosed, and we will complete your vendor security questionnaire rather than sending a brochure back.
Insurance and entity detail
Argon Technology Group is a registered company, number C 104964. Professional indemnity and public liability certificates are provided on request during procurement, along with any further entity documentation your onboarding requires.

Certifications

What we do not claim

We do not hold ISO 27001 or SOC 2 certification and we will not imply otherwise on a procurement form. What we do provide is the underlying evidence: documented access control, secure development practice, a data processing agreement, and engineers who have worked inside certified and audited environments under licence conditions.

Where your own certification scope requires a certified supplier, tell us early and we will say plainly whether we can meet it rather than discovering it at contract stage.

Security questions and questionnaires: sales@argontechnologygroup.com

Next step

Tell us what you are building, or what you are about to buy.

One working day to a reply, from an engineer rather than an account manager. Under NDA as standard, before anything is shared.