Changing LanesLimited

Legal

Information security policy (summary)

How we protect the platform and the information in it.

Draft for legal review

This document has been prepared from the platform as it is built today and must be reviewed by a UK solicitor before it is relied on. Details marked [to be confirmed: …] are company details we are still confirming (4 in this document).
Version
1.0 (draft)
Effective date
Applies to
Everyone
Owner and next review
Security lead · by
All legal documents

Our approach

We protect the confidentiality, integrity and availability of the platform and the information in it. This summary describes controls that are built into the platform today; some organisational measures are still being put in place and are marked "[to be confirmed]".

Access control

  • Every person has their own account; shared accounts are not allowed.
  • Staff accounts are created by an administrator (no self sign-up) and must use multi-factor authentication in production.
  • Access is by role and enforced by row-level security in the database, not only by the screens.
  • Employers and learners can see only their own records; employers see only consent-filtered candidate details.
  • Staff access is reviewed when roles change and when people leave — [to be confirmed: access review cycle].

Protecting data

  • Data is encrypted in transit (HTTPS) and at rest by our hosting providers.
  • Restricted data (health, benefit, safeguarding, staff identity) is stored separately with tighter rules.
  • Uploaded files are checked for type and size, stored in a private area, and served with settings that stop them running in a browser.
  • Card payments are taken on our payment provider's hosted page; card numbers never reach our systems.
  • Personal details are removed from error reports and logs before they leave our systems.

Secure development

  • Changes are reviewed, tested (including automated security, accessibility and access-control tests) and deployed through a controlled pipeline; production secrets are never stored in the code.
  • Security headers, a content security policy, rate limits, and checks on redirects and inputs protect against common web attacks.
  • Payment provider notifications are verified by signature.

Monitoring and resilience

  • Errors and uptime are monitored; an audit trail records staff actions.
  • The database is backed up by our hosting provider — [to be confirmed: backup frequency, retention and restore testing].
  • An independent penetration test is planned before launch — [to be confirmed: Q-020].

Suppliers

Our processors are listed in Processors we use and are bound by contract to protect the data they handle.

Incidents

Security incidents are reported to [to be confirmed: security contact email address], handled under our incident procedure, and personal data breaches are assessed for notification to the ICO within 72 hours. Researchers can report weaknesses under our Vulnerability disclosure policy.

People

Staff are trained on security and data protection at induction and every year and must follow the Acceptable use policy.

Change history

Change history for Information security policy (summary)
VersionDateChangeAcceptance needed again
1.0First draft for legal review, written from the platform as built.Yes — material change