Logo

Trust, privacy & delivery

Confidence built into every product relationship.

See how we approach company accountability, privacy, product security, deployment, and support from first evaluation through ongoing use.

Company

Who you are contracting with.

One registered UK entity stands behind every ScotiTech product. The details below are public and independently verifiable at Companies House.

Legal entity
ScotiTech Solutions Limited
Registered in
Scotland, United Kingdom
Company number
SC829021
Registered office
11 Caldervale Drive, Motherwell ML1 2GB, UK
ICO registration
ZB925464
Data Protection Officer
Pardeep Kumar

Certifications & assurance

Stated honestly, including what we do not hold.

We publish certification status rather than badges. Nothing below is claimed before it is granted.

In progress

Cyber Essentials

Application in progress as of August 2026. When granted, the certificate number and badge will be published here — not before.

Not held

SOC 2 / ISO 27001

Neither certification is held today. Both are a 2027 roadmap item, once Enterprise volume justifies the cost of a formal audit.

Operated

Product controls

Each product operates the technical controls a SOC 2 or ISO 27001 auditor would inspect. The detail is product-specific and published in each product's Trust Centre below.

Responsible disclosure

Report a vulnerability.

Send security reports to security@scotitech.com. Include a clear description, steps to reproduce, the affected URL, and your assessment of impact. Mark the subject URGENT if the issue is being actively exploited. A PGP key is available on request.

Our commitments

  • We acknowledge security reports within two business days.
  • We provide a first triage update within five business days.
  • We treat reports as confidential until a coordinated disclosure is agreed.
  • We offer credit, with the reporter's consent, once a fix is deployed.

Safe harbour

Research in line with these rules is treated as authorised and we will not pursue legal action.

  • Avoid privacy violations, data destruction, and service disruption.
  • Use only test accounts or your own data — never another organisation's.
  • Do not access, modify, or retain data belonging to others.
  • Give us a reasonable opportunity to remediate before public disclosure.

Out of scope

For product endpoints and tenants, see the relevant product Trust Centre.

  • Social engineering of ScotiTech staff or customers.
  • Denial-of-service or volumetric testing.
  • Findings on third-party services this site depends on — please report upstream.
  • Missing security headers, SPF/DMARC, or version disclosure without demonstrated impact.

Privacy law coverage

Which laws we operate under.

Summarised here, set out in full in the privacy policy.

UK & EU GDPR

ScotiTech Solutions Limited (SC829021) is the data controller for personal data collected through this website, registered with the Information Commissioner's Office under reference ZB925464. Our Data Protection Officer is Pardeep Kumar. You can exercise your rights, or complain to the ICO, at any time.

India — DPDP Act 2023

Our Grievance Officer is Pardeep Kumar, Data Protection Officer. Grievances are acknowledged within 72 hours and we aim to resolve them within 30 days. Withdrawing consent is as simple as giving it.

United States — state privacy laws

We do not sell or share personal information as defined by the CCPA/CPRA, and have not done so in the preceding 12 months. We use no third-party advertising cookies; optional analytics runs only after opt-in.

Product trust centres

Control detail lives with each product.

This page covers the company. Technical controls, service status, and contractual terms are specific to each product and published there.

Private enterprise workspace

AXOS

Trust, privacy, and data processing terms are published. Operational evidence and control review are provided during enterprise evaluation.

What you can review

Information for confident decisions.

During product evaluation, we can walk your commercial, technical, security, and operations teams through the areas that matter to your organisation.

Assurance topics

Available during product evaluation

  • Company, privacy, cookie, and legal information
  • Product architecture and deployment options
  • Data handling, identity, access, and administration
  • Implementation and onboarding approach
  • Customer control and supplier responsibilities
  • Support contacts and escalation routes
Talk to the team

Have security, privacy, or deployment questions?

Share your product interest and key requirements. We will connect you with the right commercial or technical contact.

Discuss your requirements