Information Security at Glaxtons
Glaxtons is trusted with pricing, bid strategy and the details of key people before a tender is submitted. We treat the protection of that information as a condition of doing business. This page sets out our Information Security Policy in full, with a summary for supplier questionnaires and a PDF for portals that need an upload.
For supplier questionnaires: the facts at a glance
Each entry cites the clause of the policy it comes from. If a questionnaire needs something this page does not answer, call 020 3668 5488 or email info@glaxtons.co.uk for the attention of the Information Security Lead.
- Legal entity
- Glaxtons Consulting Limited, registered in England and Wales, company number 12065176, D-U-N-S 225164801
- Policy reference: 1.1
- Registered office
- 3 More London Place, London SE1 2RE
- Policy reference: Document control
- Information Security Lead
- Jean-Pascal Olivier, Director
- Policy reference: 3.2
- Policy status
- Version 1.0, approved by the Directors, effective 6 October 2026
- Policy reference: Document control
- Primary systems
- Microsoft 365 for email and files, data held at rest in the United Kingdom
- Policy reference: 6.2
- Encryption
- In transit and at rest on every Approved System; full disk encryption on every Device
- Policy reference: 6.4, Schedule 1
- Authentication
- Multi factor authentication on every account on every Approved System; passwords of at least twelve characters, unique per system, held in an approved password manager
- Policy reference: 5.2, 5.3
- Least privilege
- Individual accounts only, no shared credentials; day to day work from non-administrator accounts; access granted on written Director approval and removed on or before the leaving date
- Policy reference: 5.1, 5.4, 5.5
- Device standard
- Supported software, automatic updates, security patches within 14 days, OS firewall, malware protection, ten minute screen lock, secure erasure before disposal
- Policy reference: Schedule 1
- Client data use
- Used only for the engagement it was provided for, never for another client; exchanged only through Approved Systems or client-approved channels
- Policy reference: 4.2, 4.4
- Client portal access
- Named Personnel with individually issued credentials only; no submission or declaration on a client's behalf without written authority
- Policy reference: 5.6
- AI tools
- Only Approved Systems whose terms prevent the supplier training on our data, and never where a Client Contract restricts it
- Policy reference: 9.1 to 9.3
- Subcontractors and associates
- Written confidentiality obligations no less protective than ours to the client; client consent obtained first where the contract requires it
- Policy reference: 10.2, 10.3
- Personnel
- Proportionate pre-access screening, written confidentiality, security and data protection training on joining and at least annually
- Policy reference: 11.1 to 11.3
- Incident notification
- Client notified in writing within the contract period or, where none is set, within 24 hours of awareness; ICO within 72 hours where the law requires
- Policy reference: 14.3, 14.4
- Backup and recovery
- Client work held in Approved Systems with version history and deleted-item recovery; recovery tested quarterly
- Policy reference: 13.1, 13.2
- Return and deletion
- Client Information returned or securely deleted at the end of the engagement, with written confirmation on request
- Policy reference: 15.2
- Assurance
- Quarterly checks of devices, access, MFA and recovery, recorded with owners for any failure; annual policy review; evidence of compliance available to clients on request
- Policy reference: 17.1 to 17.5
How the policy works in practice
Access
One person, one account, MFA everywhere. Administrator rights are separate from daily work and access is removed the day it is no longer needed.
Systems
Information lives only in Approved Systems on a register that records where data is held. Microsoft 365 holds our email and files at rest in the UK. Personal accounts are never used.
Devices
Every device meets a nine-point standard: supported software, patches within 14 days, full disk encryption, firewall, malware protection and a ten minute lock.
People
Screening before access, written confidentiality before anything is shared, training on joining and every year, and the same obligations flowed to associates.
Incidents
Reported immediately, contained by the Information Security Lead, clients told in writing within 24 hours where no contract period applies, the ICO within 72 hours where required.
Assurance
Quarterly checks of devices, access, MFA and file recovery, every failure recorded with an owner and a date, and a Director review of the policy every twelve months.
Where a client contract sets a stricter requirement than this policy, the contract prevails for that client's information (clause 16.1). The periods for which we keep personal data are in our privacy policy. The companion policies of the Information Security Policy Suite (access control, data security, data protection and compliance, HR security, incident management, business continuity, change management, risk and vulnerability management, third party and supplier security) are published in full at glaxtons.co.uk/policies.
Glaxtons Consulting Limited
Information Security Policy
relating to the protection of client and company information. Version 1.0.
1. Definitions and interpretation
In this Policy the following expressions have the following meanings:
- "Approved System" means a system, application or cloud service that the Information Security Lead has approved for holding or processing Information and has entered in the Systems Register;
- "Client" means any person for whom the Company provides, or proposes to provide, services;
- "Client Contract" means any contract, engagement letter or confidentiality agreement between the Company and a Client;
- "Client Information" means all information in any form that a Client, or a person acting for a Client, makes available to the Company, together with all material that the Company prepares for that Client;
- "Company" means Glaxtons Consulting Limited, registered in England and Wales with company number 12065176;
- "Company Information" means all information in any form that the Company holds for the purposes of its own business, including its financial, commercial and personnel records;
- "Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003;
- "Device" means any computer, tablet or phone that is used to hold or to reach Information, whoever owns it;
- "Directors" means the directors of the Company from time to time, and "Director" means any one of them;
- "Information" means Client Information and Company Information;
- "Information Security Lead" means the Director appointed by the Directors to own this Policy and to oversee its operation;
- "Personal Data" has the meaning given to it in the Data Protection Legislation;
- "Personnel" means the Directors, the employees of the Company and every associate, contractor or other individual who works for the Company and has access to Information;
- "Policy" means this information security policy;
- "Schedule" means the schedule to this Policy;
- "Security Incident" means any actual or reasonably suspected unauthorised access to, or accidental or unlawful loss, disclosure, alteration or destruction of, Information, and any loss or theft of a Device or of removable storage media that holds Information; and
- "Systems Register" means the register of Approved Systems kept under clause 6.1.
In this Policy, unless the context otherwise requires:
- (a) the Schedule forms part of this Policy;
- (b) headings do not affect its interpretation;
- (c) the words “including” and “in particular” do not limit the words that come before them; and
- (d) a reference to legislation is a reference to it as amended or replaced from time to time.
2. Purpose and scope
This Policy sets out how the Company protects the confidentiality, integrity and availability of Information.
The Company provides bid writing, bid management and related consultancy services. In doing so it is trusted with commercially sensitive Client Information, including pricing, bid strategy and details of key people. The Company treats the protection of that information as a condition of doing business.
This Policy applies to all Personnel, to all Information, and to every Device and Approved System, wherever the work is carried out.
Compliance with this Policy is a condition of working for the Company.
3. Responsibilities
The Directors are accountable for information security. They approve this Policy and provide the resources needed to operate it.
The Information Security Lead shall:
- (a) keep this Policy and the Systems Register up to date;
- (b) decide requests for access to Approved Systems;
- (c) keep the record of Security Incidents required by clause 14.6;
- (d) carry out the checks required by clause 17.1; and
- (e) report the results of those checks to the Directors.
All Personnel shall:
- (a) comply with this Policy;
- (b) complete the training required by clause 11.3; and
- (c) report every Security Incident in accordance with clause 14.1.
4. Handling of information
All Client Information is confidential, whether or not it is marked as such.
Personnel shall use Client Information only for the engagement for which it was provided. Information received from one Client shall not be used for the benefit of another Client or of any other person.
Access to Client Information shall be limited to the Personnel who need it for the engagement.
Client Information shall be exchanged only through an Approved System or through a channel that the Client has provided or approved.
Printed copies of Client Information shall be kept to the minimum needed, kept out of sight when not in use and shredded when no longer needed.
5. Access control
Each member of Personnel shall have an individual account for each Approved System. Accounts and credentials shall not be shared.
Multi factor authentication shall be switched on for every account on every Approved System. A system that cannot support multi factor authentication shall not be used to hold Client Information.
Passwords shall be at least twelve characters long, shall be unique to each system and shall be kept only in a password manager approved by the Information Security Lead.
Administrator rights shall be given only to Personnel who need them and shall be used only for administration. Day to day work shall be carried out from an account without administrator rights.
Access to an Approved System shall be granted only on the written approval of a Director. It shall be removed on or before the day on which the individual stops working for the Company or no longer needs it.
Where a Client gives the Company access to a tender portal or to a Client system, that access shall be used only by named Personnel, using credentials issued to them individually. No terms shall be accepted, and no declaration or submission shall be made, on a Client’s behalf without the Client’s written authority.
6. Systems and storage
Information shall be held only in Approved Systems. The Information Security Lead shall keep the Systems Register, which shall record for each Approved System its purpose, its owner within the Company, the country in which its data is held and whether multi factor authentication is switched on.
The Company’s primary systems for email and files are Microsoft 365 services. The Company’s data in those services is held at rest in the United Kingdom.
Client Information shall not be stored in, or sent through, any personal email account, personal cloud storage account or messaging account that is not an Approved System.
Information shall be encrypted in transit and at rest.
Client Information shall not be copied to removable storage media unless the Information Security Lead has approved the copy and the media is encrypted.
Where a Client Contract requires Client Information to be held in a particular country, it shall be held only in an Approved System that meets that requirement.
7. Devices
Every Device shall meet the standard set out in the Schedule. A Device that does not meet that standard shall not be used to hold or to reach Client Information.
The Information Security Lead shall keep a record of the Devices used for the Company’s work.
Personnel may use a Device that they own only if it meets the standard set out in the Schedule and is included in that record.
Devices shall not be left unattended in a public place or in a vehicle.
The storage of a Device shall be securely erased before the Device is sold, returned, recycled or passed to another user.
8. Updates and malware protection
Devices and Approved Systems shall run only software that its supplier still supports with security updates.
Security updates shall be installed within 14 days of release.
Malware protection shall be switched on and kept up to date on every Device.
Software shall be installed only from its supplier or from the official application store for the Device.
Any request received by email or message to change bank details, to make a payment or to disclose credentials shall be verified by a telephone call to a known number before it is acted on.
9. Artificial intelligence tools
A generative artificial intelligence tool may be used with Information only if it is an Approved System.
The Information Security Lead shall approve such a tool only where the terms on which it is supplied prevent the supplier from using Information to train or improve any model.
Client Information shall not be entered into any such tool where the Client Contract prohibits or restricts that use, unless the Client has approved the tool in writing.
Personnel remain responsible for the accuracy of any work produced with the help of such a tool.
10. Suppliers and associates
Before a system is approved, or a supplier is given access to Information, the Information Security Lead shall review the security and data protection terms on which the system or service is supplied.
An associate or contractor shall be given access to Client Information only after agreeing in writing to confidentiality obligations no less protective than those that the Company owes to the Client.
Where a Client Contract requires the Client’s consent to subcontracting, or to the disclosure of Client Information to an associate or other third party, the Company shall obtain that consent first.
The Company shall engage a sub processor of Personal Data only as the Data Protection Legislation and the relevant Client Contract allow.
11. Personnel
Before an individual is given access to Client Information, the Company shall carry out screening that is proportionate to the role and that complies with employment law and the Data Protection Legislation.
All Personnel shall be bound by written confidentiality obligations before they are given access to Information.
All Personnel shall complete information security and data protection training when they join and at least once in every twelve months after that. The Company shall keep a record of the training completed.
On leaving the Company, an individual shall return all Information and every Device belonging to the Company, and shall delete Information from any Device that the individual owns.
A breach of this Policy may be dealt with under the Company’s disciplinary procedure. In the case of an associate or contractor it may lead to the end of the engagement.
12. Working securely
Screens shall be locked whenever a Device is left unattended.
Client Information shall not be worked on, or discussed, where it can be seen or overheard by people who are not entitled to it.
Devices and papers shall be stored securely when they are not in use.
13. Backup and recovery
Information that is needed to deliver Client work shall be held in an Approved System that keeps previous versions and allows deleted items to be recovered. It shall not be held only on a Device.
The ability to recover a file from each such Approved System shall be tested as part of the checks required by clause 17.1.
14. Security incidents
Personnel shall report every Security Incident to the Information Security Lead as soon as they become aware of it.
On receiving a report the Information Security Lead shall take immediate steps to contain the Security Incident, establish what Information is affected and decide what further action is needed.
Where Client Information is or may be affected, the Company shall notify the Client in writing without undue delay and within any period that the Client Contract requires. Where the Client Contract sets no period, the Company shall notify the Client within 24 hours of becoming aware of the Security Incident.
Where Personal Data is or may be affected, the Company shall assess the Security Incident under the Data Protection Legislation and, where notification is required, shall notify the Information Commissioner’s Office within 72 hours of becoming aware of it.
The Company shall not disclose a Security Incident affecting Client Information to any third party without the Client’s consent, unless the law requires it to do so.
The Information Security Lead shall keep a record of every Security Incident, whether or not it is notified to anyone. The record shall state what happened, what Information was affected and what action was taken.
15. Retention, return and disposal
Information shall be kept only for as long as it is needed for the purpose for which it is held, or for as long as the law or a Client Contract requires.
At the end of an engagement, or earlier at the Client’s written request, the Company shall return or securely delete Client Information as the Client Contract requires, and shall confirm in writing that it has done so where the Client asks.
Deletion shall extend to Approved Systems and to Devices. Information held in automatic backups that cannot be deleted selectively shall not be accessed or used and shall be left to expire.
The periods for which the Company keeps Personal Data are set out in its published privacy policy.
16. Client requirements
Where a Client Contract sets a requirement that is stricter than this Policy, that requirement shall apply to that Client’s information and shall prevail over this Policy.
The Director responsible for an engagement shall record any such requirement at the start of the engagement and shall brief the Personnel assigned to it before they are given access to the Client Information.
Where a Client Contract requires it, the Company shall keep an up to date list of the Personnel who have access to that Client’s information and shall provide the list to the Client on request.
17. Compliance and review
At least once in every three months the Information Security Lead shall check, and shall record:
- (a) that every Device in use meets the standard set out in the Schedule;
- (b) who has access to each Approved System, and that each of them still needs it;
- (c) that multi factor authentication is switched on for every account; and
- (d) that a file can be recovered from each Approved System used to hold Client Information.
Any failure found by those checks shall be recorded with an owner and a date for putting it right.
An exception to this Policy may be made only with the written approval of the Information Security Lead. An exception shall be limited in time and shall be recorded.
The Company shall give a Client reasonable evidence of its compliance with this Policy on request, subject to the confidentiality that it owes to others.
The Directors shall review this Policy at least once in every twelve months, and after any significant Security Incident or any significant change to the Company’s systems or legal obligations.
Schedule 1
Device security standard
Every Device shall meet each requirement in this Schedule that its operating system is capable of meeting.
| No. | Control | Requirement |
|---|---|---|
| 1 | Supported software | The operating system and every application is a version that its supplier still supports with security updates. |
| 2 | Security updates | Automatic updates are switched on. Security updates are installed within 14 days of release. |
| 3 | Disk encryption | Full disk encryption is switched on. |
| 4 | Firewall | The firewall built into the operating system is switched on. |
| 5 | Malware protection | The protection built into the operating system, or a product approved by the Information Security Lead, is switched on and up to date. |
| 6 | Screen lock | A password, passcode or biometric check is needed to unlock the Device. The Device locks itself after no more than ten minutes without use. |
| 7 | User accounts | Each user has a separate account. Day to day work is carried out from an account without administrator rights. Guest accounts are switched off. |
| 8 | Software sources | Software is installed only from its supplier or from the official application store for the Device. |
| 9 | Disposal | The storage is securely erased before the Device is sold, returned, recycled or passed to another user. |
Document control
- Policy owner
- Information Security Lead: Jean-Pascal Olivier, Director
- Approved by
- Jean-Pascal Olivier, Director
- Version
- 1.0
- Status
- Approved
- Effective date
- 6 October 2026
- Next review due
- 6 October 2027
- Applies to
- All Personnel, Devices and Approved Systems
Glaxtons Consulting Limited. Registered in England and Wales, company number 12065176. Registered office: 3 More London Place, London SE1 2RE. D-U-N-S 225164801.
Security questions from a buyer or a client
Evidence of compliance with this policy is available to clients on request (clause 17.4). Direct security questions to the Information Security Lead, Jean-Pascal Olivier, at info@glaxtons.co.uk or on 020 3668 5488.
Glaxtons, 3 More London Place, London SE1 2RE