Procurement, InfoSec, and legal don't need to file a request. This page is live. If something changes, it changes here first — not in a PDF six weeks later.
Jump to the section you need. Nothing gated, nothing behind an NDA.
ICO, FCA, UK GDPR, and the regulator posture we operate under.
View →Access, data handling, transport, storage, availability, and governance.
View →Every third party that touches your data, with purpose and region.
View →Every production incident in the last 12 months. Resolution times included.
View →DPA template, security questionnaire, pen-test summary, retention policy.
View →How to report a security issue and what to expect in response.
View →We operate under UK GDPR. Registered with the ICO. Aligned with FCA Consumer Duty. What you see is what we file.
Nothing you'll read here is aspirational. Every control listed is live in production.
Complete list. Purpose, region, and when they started processing. We email DPO contacts 30 days before adding a new sub-processor.
We publish every incident, not just the breaches. If the API was degraded for 4 minutes, it's here.
No sales gate. Procurement can grab everything they need without creating an account.
We take security reports seriously. Email security@tdsrisk.com with details. We acknowledge within one UK business day and keep you informed through triage, remediation, and disclosure.