How we protect your data.
The certifications, controls and commitments behind the platform, in the detail a security or procurement team needs. Current as at August 2026.
Certified, encrypted, and independently tested.
Cyber Essentials, hosted in the EU/EEA.
digitalRG holds Cyber Essentials certification across the whole organisation, valid to 31 July 2027. The platform is hosted on ISO 27001-certified cloud infrastructure within the EU/EEA, with enterprise-grade DNS, DDoS mitigation and web application firewall.
Encrypted, and independently assessed.
Data is encrypted in transit and at rest. Every account uses individual multi-factor authentication with role-based permissions, and the platform is penetration tested every year by an independent, CREST-accredited specialist.
Run by Silverfish CSR Limited.
digitalRG is operated by Silverfish CSR Limited, a UK company. Certificates and policies are issued in that name, and our documentation is available to your security and procurement teams.
The proof behind the platform.




Security questions, answered.
Where is our data hosted?
Hosted on ISO 27001-certified cloud infrastructure within the EU/EEA, with enterprise-grade DNS, DDoS mitigation and web application firewall.
Is our data encrypted?
Yes. All data is encrypted in transit over HTTPS/TLS and at rest using industry-standard algorithms.
How is access controlled?
Individual named logins with multi-factor authentication, and shared or generic credentials are prohibited, so every action is individually attributable and logged. Access follows least privilege, and administrative access is time-bound, monitored and reviewed at least quarterly. You manage your own users and roles.
How is our data kept separate from other customers?
Every customer holds a separate account. Data is segregated by account, and visibility inside an account is controlled by role.
Are you penetration tested?
Yes. Independent web application penetration testing is carried out every 12 months by a CREST-accredited company, followed by a formal retest to confirm findings have been remediated. Security patches are applied on a risk-based timeframe, supported by regular vulnerability scanning.
Who is the data controller and processor?
You are the data controller and keep control of everything your team uploads. Silverfish CSR Limited acts as data processor and processes personal data only on your documented instructions, under UK GDPR and the Data Protection Act 2018, and the EU GDPR where it applies.
How are sub-processors handled?
Additions or replacements are notified through an update to the Privacy and Cookies Policy, giving you the opportunity to object before the change takes effect.
What happens to our data if we leave?
On expiry or termination, your data is deleted or returned to you at your written direction.
How quickly can you recover from an outage?
A target recovery time of under four hours for all critical systems, with less critical services on a stepped restoration timeline. Disaster recovery drills run twice a year, and the most recent data-centre outage simulation restored core services in 3.5 hours.
How do you handle a security incident or breach?
A documented incident response process covers detection, containment, investigation, regulatory notification and customer communication. We notify you without undue delay on becoming aware of a personal data breach involving your data.
What data should we not upload?
The platform is not designed for consumer, financial, payment, health or criminal-justice data, and customers are asked not to upload it. Payment card details are never handled by digitalRG; payment is taken by a third-party provider on its own secure pages.
Can we see your security documentation?
Yes. Our Cyber Essentials certificate, information security policy, disaster recovery and business continuity policy, data processing terms and the latest penetration test summary are available on request. Completed security questionnaires and a signed DPA can be provided during procurement.
Need more detail?
Our security documentation is available to your security and procurement teams on request.
