Trust Centre

What we can evidence, and what we cannot, said plainly

Enterprise telecom procurement asks hard questions, and it deserves specific answers. Where something is aligned to a standard rather than certified against it, or documented rather than independently audited, we say so.

This page sets out our security practices, data-protection position, resilience design, support model and delivery method. If you need the full assurance pack for an RFP or a security questionnaire, ask us — much of it exists in a form we can share under NDA.

Information security management

We are certified to ISO/IEC 27001:2022. Our access control and cryptography procedure is written directly to the standard's requirements, formally approved, version-controlled and owned by our Cybersecurity and IT function.

  • Deny-by-default access control, with formal user registration and de-registration.
  • Privileged-access management held separately from standard user access.
  • Controlled handling of secret authentication information.
  • Password policy enforcing a minimum length and scheduled rotation.
  • Access reviews every six months, and every three months for privileged rights.
  • Source-code access control.
  • A defined cryptographic key-management lifecycle.

The controls above are the operating detail behind the certification, not a substitute for it. If you need the certificate itself, its scope statement, or completed responses to a security questionnaire, ask us — we can share those directly, most of it under NDA.

Independent security testing

We commission external network penetration testing and vulnerability assessment from a third-party assessor, aligned to CIS Controls and NIST 800-30. Findings are handled internally under remediation, and we do not publish assessment detail — for the obvious reason that a public findings list is a roadmap. Under NDA, we can discuss scope, cadence and remediation posture with your security team directly.

Data protection

  • The platform is not designed to store personally identifiable information, and does not store PII as part of normal operation. It works with network configuration, topology, inventory, asset and performance data.
  • Encryption in transit for all integration paths — HTTPS APIs and SFTP.
  • Key management governed by our documented cryptographic procedure.
  • Identity and access managed through enterprise single sign-on.

Cookies and personal data collected through this website are covered by our Cookie and Privacy Policy. Ask as part of your due diligence and we will answer specifically.

Deployment & resilience

Deployments are dedicated per customer rather than shared multi-tenant, and can run on-premises, in private cloud or in public cloud. The architecture is designed around clustering and replication rather than single points of failure.

  • Clustered application and database tiers with native replication.
  • Replicated shared storage across cluster nodes.
  • Object storage mirrored to an off-site target.
  • Container orchestration with managed ingress and centralised identity.
  • Administrative access over an encrypted private tunnel.
  • Multi-zone deployment available where the hosting environment supports it.

We describe patterns rather than publishing a component-and-location inventory, as a matter of security hygiene. Specifics are shared per engagement under NDA.

Business continuity & disaster recovery

We maintain documented disaster-recovery procedures for production deployments, covering recovery objectives, backup policy, restore ordering, disaster-declaration criteria and communication cadence.

  • Defined recovery time and recovery point objectives per deployment.
  • Backup policy with defined retention and periodic integrity checks.
  • Primary and off-site backup targets, with restore testing.
  • A designated business continuity owner, and a fixed update cadence during an incident.
  • Quarterly disaster-recovery exercises — tabletop, restore rehearsal and readiness evaluation.
  • Annual review of the plan.

These are documented procedures. Recovery objectives are agreed per deployment rather than offered as a single public number, and we do not publish completed test evidence — ask for the current DR documentation set for your deployment model.

Support model

Support is contractually structured across three tiers. Partners may carry first and second line; Digitata Networks always anchors third line, because that is where source-code fixes happen.

TierScopeTypically carried by
First lineDay-to-day operation, basic configuration and integration triage, user accounts, connectivity to integration points, infrastructure checks, data integrity. May include proactive maintenance.Digitata Networks or partner
Second lineDeeper troubleshooting, corrective action and root-cause analysis for problems needing specialist product knowledge.Digitata Networks or partner
Third lineDefect resolution — bug fixes and software patches requiring source-code modification.Digitata Networks
AdvancedAll three tiers plus platform and application upgrades, including vendor-upgrade-driven changes.Digitata Networks

Response and resolution targets, severity definitions and any service credits are set in the engagement contract rather than published here. If you need to see our standard severity matrix before contracting, ask.

Delivery method

Delivery is phased deliberately, to get value early and reduce cutover risk rather than running one long integration and hoping.

  1. Design

    Establish scope, interfaces, data sources and the target data model.

  2. Configure & build an MVP

    Stand the platform up with pilot-migrated data across the priority domains, so there is something real to react to early.

  3. Harden & test

    Iterative system integration testing into user acceptance testing, with migration-trial evidence at each pass.

  4. Deploy & cut over

    Controlled promotion to production with a reconciled production migration.

  5. Hypercare

    Intensive post-go-live support before transition to standard support tiers.

Deployment includes setting up the extract, transform and load processes against your network elements and third-party systems, plus user and administrator training.

Integration & interoperability

We integrate with what you already run. Production integrations span vendor network management systems, third-party inventory platforms and service-assurance systems, using open data-flow tooling with HTTPS APIs and SFTP transport, and centralised identity. Our configuration platform exposes inventory via TM Forum Open APIs in production deployments, and our data models align to the TM Forum resource and service inventory specifications.

Need the full assurance pack?

Security questionnaires, architecture detail, DR documentation and support terms can be shared under NDA. Tell us what your procurement process requires.